New Business Software

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 7 December 2006

Document-level security with Enterprise Search

Posted on 18:08 by Unknown
Posted by Nitin Mangtani, Google Search Appliance Product Manager

We came across another interesting article published in New Idea Engineering in the series - "Enterprise Search: Mapping Security Requirements to Enterprise Search". In this article Mark talks about the importance of document level security and the two methods of implementing it. We completely agree with Mark on the importance of supporting document level security with enterprise search systems. Anything short of fine-grained access control is no security at all. The Google Search Appliance supports document level security across heterogeneous enterprise content stores.

While we agree with Mark on some of the benefits with using early-binding security filtering, there are certain limitations that make it impractical (if not impossible) to use for most deployments today. One of the main issues with early-binding is synchronization with the access control list (ACL) policies stored in content systems. ACL policies change frequently, and caching the ACL policies results in policies being out-of-sync with the source system. This can cause severe breaches in company security and allow sensitive IP to be leaked within the organization.

The second issue is the lack of implemented standards for introspecting the ACL policies. Without a standard way of reading policies from source systems, companies are faced with difficult implementations or are only able to provide secure results inside a homogeneous system. The new MOSS 2007 search system is a prime example of this, where security is only enforced on content that is stored in the Sharepoint system and not across other content systems, web servers, or databases.

At Google, we're working to establish a scalable, standards-driven way of early-binding security filtering. For that to work we need implemented standards within content systems (web servers, file servers, document management systems, portals, etc.) for introspecting and notifying changes in ACL policies. Until then we continue to support late-binding, document-level security filtering and delivering the highest quality, highly secure search results to tens of millions of users in companies worldwide every day.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

Categories

  • admin
  • Android
  • cloud computing
  • developers
  • earth and maps
  • education
  • enterprise
  • events
  • gmail
  • gonegoogle
  • Google Apps
  • Google Apps Blog
  • Google Calendar
  • google commerce search
  • google docs
  • Google Email Security and Archiving
  • Google Enterprise Search
  • Google I/O
  • Google Maps
  • google message security
  • Google Search Appliance
  • Google Site Search
  • google sites
  • Google spreadsheets
  • Google Video
  • Google Wave
  • government
  • guest post
  • hints and tips
  • innovation
  • IT
  • K-12
  • large business
  • mashups
  • medium business
  • migration
  • mobile
  • new features
  • non-profit
  • partners
  • Postini
  • productivity
  • small business
  • spam and security trends
  • success story
  • switch
  • university
  • viewpoint
  • webinar
  • webmaster

Blog Archive

  • ►  2010 (14)
    • ►  January (14)
  • ►  2009 (178)
    • ►  December (11)
    • ►  November (12)
    • ►  October (15)
    • ►  September (19)
    • ►  August (18)
    • ►  July (19)
    • ►  June (13)
    • ►  May (15)
    • ►  April (15)
    • ►  March (14)
    • ►  February (13)
    • ►  January (14)
  • ►  2008 (78)
    • ►  December (9)
    • ►  November (16)
    • ►  October (8)
    • ►  September (8)
    • ►  August (3)
    • ►  July (4)
    • ►  June (4)
    • ►  May (5)
    • ►  April (5)
    • ►  March (7)
    • ►  February (5)
    • ►  January (4)
  • ►  2007 (79)
    • ►  December (6)
    • ►  November (7)
    • ►  October (6)
    • ►  September (8)
    • ►  August (4)
    • ►  July (9)
    • ►  June (6)
    • ►  May (10)
    • ►  April (7)
    • ►  March (7)
    • ►  February (1)
    • ►  January (8)
  • ▼  2006 (76)
    • ▼  December (4)
      • Unified Search across different ECM systems
      • Hey (Username) Your lights are on!
      • Savings Measured in Millions
      • Document-level security with Enterprise Search
    • ►  November (6)
    • ►  October (13)
    • ►  September (10)
    • ►  August (6)
    • ►  July (9)
    • ►  June (6)
    • ►  May (7)
    • ►  April (3)
    • ►  March (3)
    • ►  February (7)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile