When performing IT audits, one of the most mundane, time-consuming tasks is assessing the data access controls in the environment. IT auditors have to use a combination of tools, scripts and manual processes to gain visibility into the audited organization’s sensitive data to understand:
- Who has access to what?
- What is accessible to whom?
- How did access rights to sensitive data change at different points in time?
With Aprigo’s on-demand architecture, IT auditors can perform extensive access control assessments of large data environments in minutes as opposed to days.
How to answer key IT auditing questions with Aprigo NINJA:
Step 1: Gaining visibility into your data environment: Aprigo NINJA lets you aggregate all the data sources containing sensitive files into a single dashboard.

Step 2: Folders permission reporting on sensitive folders: Use Aprigo NINJA to aggregate information from Active Directory with ACLs collected from file systems to provide detailed visibility into the actual users that have access to sensitive folders. Security groups are great, but they mean nothing to the business owner or IT auditor that needs to change access controls on those sensitive folders

File System Audits With Aprigo NINJA
Step 3: Perform user entitlements reviews of users and groups: Use Aprigo NINJA to illustrate all the network folders that a user or group has access to, where they gained this access from, and remediate issues. End-users have ABE (Access Based Enumeration) that provides them with a view of only the resources they have access to. Now, the system administrator can have a similar view for each user and group in the environment.
Step 4: Review data access controls at different point in times: Use Aprigo NINJA to create scheduled scans of areas containing sensitive files to create an audit trail of who had access to what and what was accessible to whom in different points in time. Those snapshots can be loaded into the dashboard at any time.