Previous Topic: Prevent Unauthorized Uninstallation of CA DataMinderNext Topic: Preventing Man-in-the-Middle Attacks


Use File Permissions to Protect Event Data and Document Fingerprints

We recommend to limit user access to event data held in the local endpoint agent database, and to email or web page content in blob files held below the CA DataMinder data folder. You also want to prevent unauthorized users from tampering with, for example, the document fingerprints stored in content index files in the "C:\ProgramData\CA\CA DataMinder\data\PRC\IndexCache" folder.

By default, the CA DataMinder software and data are in some of the following folders, depending on your operating system:

C:\Program Files\CA\CA DataMinder\
C:\Program Files (x86)\CA\CA DataMinder\
C:\ProgramData\CA\CA DataMinder\data\
C:\Documents and Settings\All Users\Application Data\CA\CA DataMinder\

Note: On an NTFS volume, the "CA" folders typically inherit attributes and permissions from their parent folders. The default file system privileges provide basic protection because users require administrator privileges to modify files in these folders.

Follow these steps:

  1. Change the folder attributes of all "CA" folders to System Hidden where necessary.

    This attribute prevents users from seeing the CA DataMinder software and data files.

  2. Reduce user permissions to the "C:\ProgramData\CA\CA DataMinder\data" folder.
  3. Reduce user permissions to the "C:\Documents and Settings\All Users\Application Data\CA\CA DataMinder\" folder.

Important: Ensure that the account under which the CA DataMinder infrastructure service runs (typically LocalSystem) retains full access to all CA DataMinder folders!