Dropbox data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Dropbox, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dropbox connector needs.
Checks (5)
severity: high Public Shared Links Allowed by Default fix difficulty: easy #
Change the default shared link policy to restrict links to team members only
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Sharing
- Under Shared links, find the default link visibility setting
- Change the default to team only or no-one (require explicit sharing)
- Save the changes
- Communicate the updated policy to team members
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Shared Folders Open to Anyone fix difficulty: easy #
Restrict shared folder membership to Dropbox team members only
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Sharing
- Under Shared folders, find the membership policy setting
- Change the setting to allow only team members to be added to shared folders
- Save the changes and inform users of the updated policy
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium External Folder Join Unrestricted fix difficulty: easy #
Restrict team members from joining shared folders outside the team
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Sharing
- Under Shared folders, find the join policy for external folders
- Change the setting to restrict members from joining folders owned by non-team accounts
- Save the changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Folder Link Restriction Not Enforced fix difficulty: easy #
Configure the shared folder link restriction policy to prevent unrestricted external access
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Sharing
- Under Shared folder links, find the link restriction policy
- Change the setting to restrict folder links to team members or require a password
- Save the changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Suggest Members Enabled fix difficulty: easy #
Disable the Dropbox suggest members feature to prevent unauthorized team invitation suggestions
- Sign in to the Dropbox Admin Console as an administrator
- Navigate to Admin Console > Settings > Team profile
- Locate the Suggest members setting
- Disable the suggest members feature
- Save the changes
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12