Security & Governance Risk Caused by Retained Collaborations After Folder Moves
To help prevent unintended external access to internal-only content and strengthen data governance, we would like to request a feature that either controls collaboration inheritance when folders are moved or restricts folder moves within designated folder hierarchies.
In the current Box environment, my understanding is that when a folder is moved, any collaborations directly assigned to that folder are retained.
This behavior may lead to situations where folders with different access policies become mixed within the same hierarchy. For example, a folder collaborated with external users could be moved into a directory intended exclusively for internal use. As a result, external collaborators may continue to have access within an area that is expected to be restricted to internal users only. We believe this introduces a potential security and governance risk.
To help mitigate this risk, we would like to request consideration of one of the following options:
A configurable setting that automatically removes existing collaborations when a folder is moved.
A configurable setting that prevents folders and their entire descendant folder tree from being moved under specified parent folders.
More generally, administrative controls that allow organizations to enforce folder placement and collaboration governance policies when folder moves occur.
We understand that similar requests have previously been discussed on Box Pulse and were not adopted, partly due to concerns regarding the complexity of collaboration changes and the volume of user notifications that could be generated when folders are moved.
However, we have not found any recent discussions addressing this concern. Given the increasing importance of data governance and the prevention of unintended external access, we would appreciate it if Box could reconsider this capability.
Additionally, we are not necessarily requesting these specific approaches. Any solution that achieves an equivalent level of risk mitigation would be equally appreciated.
Thank you for your consideration.
Japanese:
社内専用領域への意図しない外部アクセスを防止するため、フォルダ移動時のコラボレーション継承制御、または指定フォルダ配下への移動抑止機能の提供をご検討いただけないでしょうか。
現在のBoxの仕様では、フォルダを移動した際、そのフォルダに直接付与されているコラボレーション設定は維持されると認識しています。
この挙動により、異なるアクセスルールを持つフォルダが同一のフォルダ階層内に混在する可能性があります。例えば、外部ユーザーがコラボレーションされているフォルダが、社内専用として運用されているディレクトリ配下へ移動された場合でも、その外部ユーザーのアクセス権は継続されます。その結果、本来は内部利用を想定している領域内に外部ユーザーがアクセス可能なフォルダが存在することになり、セキュリティおよびガバナンス上のリスクにつながると考えています。
このリスクを軽減するため、以下のいずれかの機能の実装をご検討いただけないでしょうか。
フォルダ移動時に既存のコラボレーションを自動的に削除する設定
指定した親フォルダ配下への移動を、対象フォルダおよびその配下階層を含めて制限する設定
より広義には、フォルダ移動時に組織のアクセス管理ポリシーやコラボレーション管理方針を強制できる管理者向けの制御機能
過去にBox Pulseにおいて同様の要望が議論され、フォルダ移動に伴うコラボレーション変更処理や、それによって発生するユーザー通知の煩雑さなどを理由に採用されなかった経緯があることは認識しております。
しかしながら、近年ではデータガバナンスの重要性や、意図しない外部アクセスを防止する必要性が一層高まっています。また、直近では同様の要望を見受けなかったため、改めて本機能についてご検討いただければ幸いです。
また、上記の実装方式に限定するものではなく、同等のリスク低減効果を実現できる代替的な機能や制御手段についてもご検討いただけますと幸いです。
ご検討のほどよろしくお願いいたします。