What is the Most Common Time Interval to Schedule Recurring Scans?
The most common time interval for scheduling recurring scans in Spirion SDP is Weekly, though the "correct" interval depends entirely on the volatility of the data and the operational impact of the scan.
Based on internal best practices and common user configurations, here is how different scheduling time intervals are typically used:
Weekly (The "Standard" Interval)
- Why it’s common: It strikes a balance between maintaining a current security posture and minimizing the load on target systems and agents.
- Typical Use Case: General-purpose file shares, user endpoints, and SharePoint libraries.
- Best Practice: Schedule these for weekend maintenance windows (for example, Sunday at 12:00 AM) to ensure they finish before the Monday morning login rush.
Daily (The "High-Risk" Interval)
- Why it’s used: For environments where data changes rapidly or where the risk of sensitive data exposure is extremely high.
- Typical Use Case: Email (Exchange Online), "Drop" folders where new files are constantly uploaded, or regulated databases.
- Operational Tip: Daily scans rely heavily on Search History. Because Spirion only scans new or modified files (incremental scanning), a daily scan often finishes very quickly after the initial baseline is established.
Monthly or Quarterly (The "Compliance" Interval)
- Why it’s used: For massive, static archives where data rarely changes, or for meeting specific regulatory audit requirements (like PCI-DSS or HIPAA) that only require periodic verification.
- Typical Use Case: Cold storage, legacy backups, or very large "read-only" repositories.
Factors to Consider When Choosing Your Scheduling Time Interval
When deciding on your schedule, Spirion experts recommend evaluating these 4 axes:
- Data Volatility: How fast does the Target (email server, file share, database, workstation, etc.) change? If users add hundreds of files a day, a weekly scan might leave a 6-day "blind spot."
- Scan "Expense": How much load does the scan put on the target? Scanning a production database daily might impact performance, whereas scanning an endpoint is relatively "cheap."
- Remediation Urgency: If you have Automatic Playbooks enabled, the scan interval determines your "Time to Remediate." A weekly scan means a sensitive file could sit exposed for up to a week before being automatically moved or deleted.
- Search History Maturity: For the first scan (the Baseline), the interval doesn't matter because it will scan everything. Once the baseline is done, you can increase the frequency (for example, from Weekly to Daily) because the incremental runs will be much faster.
Summary Recommendation
If you are just starting, the most successful pattern is:
- Baseline: Run a one-time manual scan to clear the "backlog."
- Steady State: Schedule a Weekly scan for most targets.
- High-Value Targets: Schedule Daily scans for Email and active "Inbound" folders.