Allow Shield List of Countries Usable for Access Policies
There may be certain countries a Box customer may be prohibited from sharing with under any circumstance. I suggest making it possible to whitelist or blacklist entire countries by allowing Shield Lists of countries to be included in Access Policies.
Not a priority. Will revisit in 6 months.
-
Anonymous commented
This control is more needed everyday in our current landscape. Automated reporting of Geographic locations is nice, but outright blocking of locations we do not have legitimate business with would be ideal.
-
Anonymous commented
Next example: For the US, medical data generally cannot be shared or accessed outside the US. As of now, BOX will alert on foreign country access, but cannot block it. Auditors (SOC-2, HITRUST, ISO, CMMC) and payors (Blue Cross/Shield, United Health, CIGNA, Humana) are questioning BOX usage due to this vulnerability.
-
Anonymous commented
An example of where this could apply is ITAR-restricted data, where only countries who are not ITAR prohibited are allowed to access the data in a given folder.
-
Anonymous commented
how this is already not built-in is amazing to me....