Security Consideration for SharePoint Extranet Solutions

Security is a complex topic that must be balanced with business requirements and goals. Any system that must be accessed externally will always be more vulnerable than the system within an intranet environment. Security also has its trade-offs, such as usability, supportability, security, and complexity. Each of these affect the others, and has to be weighed by the business and its requirements and goals to establish the proper security model for their specific scenario. The following list should be considered when building extranet solutions in SharePoint:

• Use the “least privilege” accounts and security approach. This approach reduces the security risk when any account is compromised and isolates problems and issues to their specific areas. For example, if search is using specific content access accounts, errors while crawling the content sources will be easily identified by the source and also the account. In SharePoint 2010, managed accounts simplify the process of changing passwords by centralizing the management of the accounts in Central Administration.

• Include a SharePoint-specific antivirus solution such as Microsoft’s Forefront Protection for SharePoint as part of the extranet deployment. This ensures that the antivirus solution can be configured to scan only uploaded files and documents, as opposed to scanning both uploads and downloads. All data contained within the content databases can be considered clean.

• Plan the security model for the SharePoint farm according to the business names while minimizing the complexity. Choose a network topology that protects the intranet and any shared resources adequately. Reduce the access points to the shared resources and establish a common nomenclature that is intuitive and descriptive.

Document decisions, configuration, and modifications made as part of the security model. Establish a governance approach around security changes to ensure all documentation is maintained and recorded appropriately.

• Consider placing application servers on a private, nonroutable subnet for secure SharePoint interfarm communication. Also, consider securing communication between SharePoint servers (interserver communication) through IPsec or SSL.

• Use web applications for isolation, security, and confidentiality.

Note

Security is a complex topic. Make sure to understand the authentication providers and the required access to any shared resources. Always minimize the access any user or application has to only the minimum information that is required.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset