What is the procedure for setting up a Dropbox File Request team folder for Level 3 data?

Tags Dropbox
  1. Customers should request a Dropbox Team Folder for Level 3 storage.
    • Customers must specify the types of Level 3 data that would be stored and include the justification.
    • Level 3 data will not be stored in a non-Team Folder.
    • Team Folders will not be synced to local computers with Dropbox file sync.
  2. After the form is submitted, OneIT Security Services receives the ticket.
    • Security Services will ensure that the request has a critical legitimate business justification that cannot be filled in any other way.
    • CISO approves or denies.
  3. Security Services will send a risk acceptance document to the customer and supervisor via DocuSign and ask them to agree to the terms and accept the risk.
  4. Security Services will ensure the risk acceptance document is attached to the original ticket.
  5. Security Services will forward the ticket to Endpoint Solutions for creation of the Dropbox Team Folder with the following caveats:
    • Folder restrictions:
      • Folder membership: Team members only
      • Manage Access: Team Admin Only 
      • Link Restrictions: On 
      • Viewer Info: On
      • Dropbox Team Folder File Sync: Online only
      • Disable permanent deletions
    • Department responsibilities:
      • The customer will designate a team admin to provision team members for folder access.
      • Team member access should be restricted to only necessary personnel to complete the process.
      • Files should never be downloaded or processed on personal computers or devices, only use managed University machines. (NO DROPBOX FILE SYNC)
      • Files should be deleted from the Dropbox Team Folder once processed (by team admin)
      • Files will never be shared outside of the University or with universal links.
      • Team members should use the Dropbox File Intake request process to send users file requests. Always ensure that team members request files from the team folder only. https://help.dropbox.com/files-folders/share/create-file-request#filerequest
  6. Security Services will include the Dropbox Team folder information in an internal tracking sheet, conduct annual audits of the Level 3 Team Folders, and contact the customer annually to re-validate.