ISA does not control file access but is responsible for making decisions upon whether traffic requesting passage through its interfaces will be allowed or denied based upon firewall and system policy rules defined through the gui.
If the site is published and SSO is ebanled for the rule then the user credentials can be passed on. Generally speaking, I would normally enable all of the participating components to have Kerberos delegation enabled for all authentication protocols on the ISA and IIS server active directory objects.
If you are talking about drag and drop capabilities as well to these folders then webdav would be the normal approach as you have Sharepoint.