Academy Central
----
Weather

Managing Sensitive Data in SaaS Environments

管理 SaaS 環境中的敏感資料

Overview | 概述

The rise of SaaS and generative AI has amplified the risks of unintentional data exposure. Falcon Shield's Data Inventory helps you detect publicly shared documents, prevent unauthorized data transfers to AI tools, and enforce policies that limit sensitive data movement.

SaaS 和生成式 AI 的興起放大了非故意資料外洩的風險。Falcon Shield 的資料清單協助偵測公開分享的文件、防止未授權的資料傳輸至 AI 工具,並執行限制敏感資料移動的策略。


Public vs. External Sharing | 公開 vs. 外部分享

TypeDescription風險等級說明
PublicAnyone with the sharing link can access the file. URLs can be guessed or shared by mistake.Critical任何有分享連結的人可存取檔案。URL 可能被猜中或誤分享。
ExternalShared with unverified domains not approved by the organization. Corporate IP could be exposed.High與組織未批准的未驗證網域分享。企業智慧財產可能被暴露。

To view unverified domains, go to Settings > Domains in Falcon Shield (owner access required).

要檢視未驗證網域,請前往 Falcon Shield 的 Settings > Domains(需要擁有者權限)。


Data Inventory Fields | 資料清單欄位

Main Columns | 主要欄位

ColumnDescription欄位說明
NameFile or resource name名稱檔案或資源名稱
TypeCalendar, File, Document, PDF, Repository類型日曆、檔案、文件、PDF、儲存庫
IntegrationSource SaaS app整合來源 SaaS 應用程式
OwnerUser who shared the resource擁有者分享資源的使用者
Access LevelPublic or External存取層級公開或外部
Last AccessedMost recent access date最後存取最近存取日期
Password ProtectedWhether file is password-protected密碼保護檔案是否受密碼保護
Owner DepartmentOwner's department擁有者部門擁有者的部門

Data Side Bar | 資料側邊欄

Clicking any row opens a side bar with:

點擊任何一列會開啟側邊欄,顯示:

  • User Enabled — The user who shared the resource

  • Resource ID — Unique identifier

  • Link(s) — Internal and/or external sharing links

  • Times Viewed — Exposure gauge for unauthorized sharing

  • Shared users — Grouped by domain

  • 使用者 — 分享資源的使用者

  • 資源 ID — 唯一識別碼

  • 連結 — 內部和/或外部分享連結

  • 檢視次數 — 未授權分享的暴露指標

  • 已分享使用者 — 按網域分組


Filters | 篩選器

FilterPurpose篩選器用途
IntegrationNarrow to specific SaaS app整合篩選至特定 SaaS 應用程式
OwnerFind files by specific user擁有者按特定使用者尋找檔案
Access LevelSeparate public from external存取層級區分公開與外部
Owner DepartmentIdentify risky departments擁有者部門識別高風險部門
Unmanaged DomainFind external shares to unknown orgs未管理網域發現與未知組織的外部分享

Grouping | 分組

Group results by Owner or Owner Department to detect users or departments with higher numbers of mismanaged files.

擁有者擁有者部門分組結果,以發現有較多管理不當檔案的使用者或部門。


Key Risk Use Cases | 關鍵風險使用情境

Abandoned Files | 遺棄檔案

Problem | 問題: Documents left accessible after their owners' accounts are disabled. Without an active owner, these files remain in circulation with no oversight.

問題: 擁有者帳戶被停用後,文件仍然可存取。沒有活動的擁有者,這些檔案會在無監督的情況下持續流通。

Solution | 解決方案:

  1. Use Data Inventory to identify files owned by disabled users
  2. Reassign ownership or delete the files
  3. Implement policies to audit file ownership when accounts are disabled

解決方案:

  1. 使用資料清單識別由停用使用者擁有的檔案
  2. 重新分配所有權或刪除檔案
  3. 實施帳戶停用時稽核檔案所有權的策略

High-Sharing Users/Departments | 高分享使用者/部門

Problem | 問題: Some users or departments consistently create public links without passwords or expiration dates.

問題: 某些使用者或部門持續建立無密碼或無到期日的公開連結。

Solution | 解決方案: Group by Owner or Department, identify outliers, and provide targeted training on secure file-sharing practices.

解決方案: 按擁有者或部門分組,識別異常者,並針對安全檔案分享實踐提供針對性培訓。


Mitigation Checklist | 緩解清單

  • Review Data Inventory weekly for new public/external shares

  • Verify file sharing policy status via Security Checks page

  • Group by department to identify training gaps

  • Implement expiration dates on external shares

  • Audit abandoned files when employees leave

  • Monitor for sensitive data being shared to AI tools

  • 每週審查資料清單中的新公開/外部分享

  • 透過安全檢查頁面驗證檔案分享策略狀態

  • 按部門分組以識別培訓缺口

  • 對外部分享實施到期日

  • 員工離職時稽核遺棄檔案

  • 監控敏感資料是否被分享至 AI 工具


Related Modules | 相關模組

ModuleDescription關聯模組說明
Applications InventoryTrack apps with data access應用程式清單追蹤有資料存取權的應用程式
User InventoryIdentify users sharing data使用者清單識別分享資料的使用者
Identity GovernanceEnforce data access policies身分治理執行資料存取策略
Permissions GovernanceControl sharing permissions權限治理控制分享權限