Compliance

ISO 27001 access reviews for SharePoint external sharing

ISO/IEC 27001 puts access control at the centre of an information-security management system: a policy for who may access what (A.5.15), and a review of those access rights at planned intervals (A.5.18). In a Microsoft 365 tenant, external sharing across SharePoint and OneDrive is a large — and constantly changing — part of exactly that surface, and keeping it reviewed and evidenced is the reader's obligation, not a tool's.

What the standard asks for (the access-control slice)

Two controls sit squarely in this lane. A.5.15 expects an access-control policy — who gets access, on what basis. A.5.18 expects that access rights are provisioned, reviewed, and removed on a defined cadence, with evidence that the review happened. Read together, they are not a one-off exercise: an access-control policy nobody re-checks is a document, not a control. And access state drifts daily — every share, every guest invitation, every new file under an already-shared folder moves it — so a review performed once before an audit describes last year's exposure, not this quarter's.

The external-sharing surface

SharePoint and OneDrive are where a tenant's working documents live, and external access to them takes shapes that are easy to grant and hard to see again: "Anyone" links that outlive their purpose, guest grants left over from finished projects, guests reaching whole sites through Microsoft 365 group membership, and inherited access — where a grant on a parent folder silently covers every file added beneath it. For an A.5.18 review, that surface has to be reviewable on a recurring basis, not archaeologically reconstructed when an auditor asks.

Scheduled reports as audit artefacts

TRACER365 makes the external-access review a working practice, and its output an artefact an auditor can read:

  • Complete inventory, read-only: every external exposure across all SharePoint sites and OneDrives — anonymous links, guest grants, inherited access, pending invitations — from a locally installed app that changes nothing in the tenant.
  • A review a reviewer can finish: cascade de-duplication collapsed roughly 91% of raw findings as duplicates in our testing. An access-rights review is only real if the person doing it can get through the list.
  • A cadence by construction: scheduled scans and email reports to the person responsible — including a non-IT reviewer via the viewer role — so the A.5.18 interval survives busy quarters, and each report is a dated artefact.
  • Point-in-time and change-over-time: scan history shows both the current state and the trend; new or expanded sharing is flagged for review again.
  • No new data flow: the audit runs locally and its data never leaves your environment, so the evidence-gathering itself adds nothing new to account for.
The honest boundary: meeting ISO 27001 is an organisational undertaking — the audit is yours to pass — not a product feature. TRACER365 provides evidence for the access-control side (A.5.15 access control, A.5.18 review of access rights) — it does not read sensitivity labels, it does not classify data, and no tool can hand your organisation the standard. The same access-review evidence also serves GDPR Article 32 and NIS2 access-control obligations, where those apply to you.

Make the access-rights review performable

Complete external-sharing evidence across SharePoint and OneDrive, de-duplicated, on a schedule, without your data leaving your environment. Free 30-day trial at launch.