We Want to Hear From You! What Do You Want to See on the Community? Tell us here!
Forum Discussion
Techyguy
2 years agoNew member | Level 2
What are best practices for securing other's Dropbox
As our company's CISO, it's my responsibility to validate the security posture of our company and our third parties. I have unresolved questions about how we can verify Dropbox security controls, specifically for third parties.
We are not a direct Dropbox customer, although we've encountered many third parties who use Dropbox, as their preferred File Sharing & Collaboration platform. What are the Dropbox best practices to ensure a third party's Dropbox setup is secure? I have attempted to do a Q&A with various third parties to ensure they securely setup their Dropbox, although many third parties don't know much about how their company's Dropbox security is configured. Many third parties simply have a lack of knowledge about Dropbox security controls. I notice there are 4 tiers of Dropbox, each with various security controls. I understand how these controls can better secure data residing in a Shared Dropbox.
Examples of questions which our best practice Dropbox procedure should answer:
- How do we, the receiving party, know which Dropbox tier the parent company is subscribed to? (i.e. Must have Business "HIPAA configured" if they want to share medical records)
- How can we, the receiving party, validate that all parties have MFA enabled, among other security controls?
Definitions:
(Parent Company) = the company who provides their shared Dropbox.
(Receiving Company) = the company who is using the parent company's Dropbox.
(Third Party) = any customer or vendor we do business with.
3 Replies
- Jay2 years ago
Dropbox Community Moderator
Hi Techyguy, thanks for messaging the Community.
As DocuSign is a separate company, we wouldn't be able to advise on that matter?
Is it possible you're referring to HelloSign or Dropbox Sign?
This will help me to assist further!
- Techyguy2 years agoNew member | Level 2
Thank you Jay, I mistyped and corrected now. I meant Dropbox, not DocuSign. No eSign.
- Jay2 years ago
Dropbox Community Moderator
Thanks for the update, currently, there isn't a direct method to determine if another user is on a Dropbox Business team, in order to determine if they can share HIPAA data, if they have any two step authentication methods.
About Integrations
Find solutions to issues with third-party integrations from the Dropbox Community. Share advice and help members with their integration questions.
Need More Support
The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.
If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.
For more info on available support options for your Dropbox plan, see this article.
If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!