SEARCH RESULTS
 
Showing 1-10 of 62 records
 
Expand article

Best Practices For Endpoint DLP: Part 1

2008-07-01 00:57:52 by rmogull in securosis.com
 
...DLP. Early on I tended to exclude endpoint only solutions because they were more limited in functionality, and couldnt help at all with protecting data loss from unmanaged systems. But even then I always said that, eventually, endpoint DLP would be a critical component of any DLP solution. When were looking at a problem like data loss, no...
 
 
 
 
 
Expand article

So, CAN We Have DLP?

2008-06-20 16:59:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...DLP - data leak prevention Well, can we have IDS? How about IPS? Can we really "prevent intrusions?" Can we really "control access to our networks The answer to "can we have DLP?" is actually pretty simple: if you think "DLP = box that prevents all data leaks" (and you also think that deploying IPS will "prevent intrusions"), then we can't....
 
 
 
 
 
Expand article

Best Practices For DLP Content Discovery: Part 2

2008-04-15 17:20:20 by rmogull in securosis.com
 
...DLP content discovery, defined it a little bit, and listed a few use cases to demonstrate its value. Today were going to delve into the technology and a few major features you should look for First I want to follow up on something from the last post. I reached out to one of the DLP vendors I work with, and they said they are seeing around 60%...
 
 
 
 
 
Expand article

Best Practices For DLP Content Discovery: Use Cases

2008-05-01 17:32:42 by rmogull in securosis.com
 
...DLP content discovery best practices by discussion rolling out and maintaining your deployment. Today were going to focus on a couple of use cases that illustrate how it all works together. Im writing these as fake case studies, which is probably really obvious considering my lack of creativity in the names DLP Content Discovery for Risk...
 
 
 
 
 
Expand article

In Passing on DLP

2008-05-16 19:08:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...DLP analyst , but it doesn't mean that I cannot have an opinion on this "searing -warm" :-) security concept: "data leak 'prevention'" or DLP (notice the double quotes around prevention I admit that in the past I poked jokes at DLP for being "ADLP", with "A" standing for "accidental." Indeed, most of the technology approaches I've seen were...
 
 
 
 
 
Expand article

Best Practices For DLP Content Discovery: Part 4

2008-04-29 18:01:19 by rmogull in securosis.com
 
...DLP deployment content discovery or otherwise is properly setting expectations at the start of the project. DLP tools are powerful, but far from a magic bullet or black box that makes all data completely secure. When setting expectations you need to pull key stakeholders together in a single room and define whats achievable with your...
 
 
 
 
 
Expand article

Best Practices For DLP Content Discovery: Part 3

2008-04-17 22:44:34 by rmogull in securosis.com
 
...DLP discovery tool determines something is out of place, it can (depending on the tool) take enforcement actions that range from alerts to full on protection, including combinations. In cases where files are restricted, moved, or encrypted an unprotected plain text file can be dropped into the same location to notify users who to contact with...
 
 
 
 
 
Expand article

Database Activity Monitoring Is As Big, Or Bigger, Than DLP

2008-05-14 17:12:04 by rmogull in securosis.com
 
...DLP market (thats where we toss out peripheral products that only use DLP as a feature). I assumed this was common knowledge, but their jaws dropped. We ran through some back of the envelope calculations, and placed DLP at about $70M in 2007, with DAM right in the same range. My estimates might be off by up to $20M, but thats basically a...
 
 
 
 
 
Expand article

Best Practices For Reducing Risks With DLP Content Discovery: Part 1

2008-04-14 17:34:32 by rmogull in securosis.com
 
...DLP is a core tool, its no surprise I took a ton of questions on it over the week. Many of these questions were inspired by analysis, including my own, that leaks over email/web really arent a big source of losses. People use that to try and devalue DLP, forgetting that network monitoring/prevention is just one piece of the pie. A small...
 
 
 
 
 
Expand article

Best Practices for DLP Content Discovery: Part 5

2008-04-30 00:20:51 by rmogull in securosis.com
 
...DLP content discovery deployment, including expectation setting, prioritizing information for protection, and defining your workflow. By this point you should know what policies youd like to deploy, where you want to start protecting the content, how youd like to grow that protection after initial deployment, and the workflow for when you...