信息权限管理(IRM)和 SharePoint - 系统管理员可以查看受保护文件的内容吗?
我们正在考虑为我们的人力资源部门部署一个 MOSS 站点,但对于系统管理员是否能够访问有关绩效和薪资的高度机密材料存在一些担忧。 看来 IRM 是我们正在寻找的灵丹妙药,让 MOSS 系统管理员无法打开文档来查看内容。
谁能确认 IRM 会保护我们 MOSS 网站中系统管理员的内容吗?
谢谢! -蒂姆
We are considering deploying a MOSS site for our HR department but there is some concern over the system administrators being able to access the highly confidential material regarding performance and salaries. It appears that IRM is the silver bullet we are looking for providing the MOSS System Administrators CAN NOT open the documents to view the content.
Can anyone confirm that IRM will secure the content from our Sys Admins in our MOSS Site?
Thanks!
-Tim
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
将 IRM 与 SharePoint 结合使用的方法有 2 种:
SharePoint 集成模式:在此模式下,当用户下载文档时,IRM 会以正确的权限动态应用于文档。 在这种情况下,文档的存储不受保护,因此可以直接访问 SQL 数据库的管理员可以查看文档的内容。
“标准”:如果在将文档上传到 SharePoint 之前对文档应用 IRM,则该文档将受到保护存储(有 2 种保护:SharePoint 权限和 IRM 权限)。 因此,在这种情况下,即使 SQL 管理员也无法提取该文档。 但是,存在一些副作用:例如,搜索将无法工作,因为搜索引擎将无法提取文档的内容。
就您的情况而言,您需要使用第二种解决方案:在将文档上传到 SharePoint 之前对其进行加密。
There are 2 ways in using IRM with SharePoint:
SharePoint integrated mode: In this mode, IRM is applied on the document on the fly with correct permission when the user download it. In this case the document is stored unprotected, so administrator with direct access to the SQL database can view the content of the document.
"Standard": If IRM is applied on the document before uploading it to SharePoint, the document is stored protected (there are 2 protections: SharePoint permissions AND IRM permissions). So even SQL administrator won't be able to extract the document in this case. However, there are some side effects: for example search won't work as the search engine won't be able to extract the content of the document.
In your case, you will need to use the second solution: encrypt the documents before uploading them to SharePoint.
您是否在 www.adeptol.com 上查看过 Adeptol 的共享点权限管理
Have you looked at Adeptol Rights management for sharepoint at www.adeptol.com