Data Loss Prevention DLP – Ready or Not, By Robin Basham, CISSP, CISA, CRISC, CGEIT, M.Ed., M.IT
If you are required to comply with (US) HIPPA, State Social Security Laws, COPPA, State Security Breach Laws (California Civil Code § 1798.29, 1798.80 et seq.), GLBA or PCI-DSS, someone will ask you
- How many unauthorized data exfiltration attempts have been detected recently by the organization's Data Loss Prevention (DLP) system?
- What percentage of the organization's business systems are not utilizing host-based Data Loss Prevention (DLP) software applications?
- Whether it was a customer request or a conversation with an examiner, they expected a detailed answer broken out by the business unit. If you manage compliance, you are accountable to these answers.
- Good News: When done right, Data Loss Prevention – DLP benefits
- Protect critical business data and intellectual property
- Improve compliance
- Reduce data breach risk
- Enhance training and awareness
- Improve business processes
- Optimize disk space and network bandwidth
- Detect rogue/malicious software
Source: Data Leak Prevention © 2010 ISACA.
- The DLP Mission – Understand, Control, and Protect Data
- Data loss prevention (DLP) is a comprehensive approach (covering people, processes, and systems) of implementing policies and controls designed specifically to discover, monitor, and protect confidential data wherever it is stored, used, or in transit over the network and at the perimeter. (Source: NSA/CSS Securing Data and Handling Spillage Events)
- Data classification program is a program that categorizes data to convey required safeguards for information confidentiality, integrity, and availability; establishes controls required based on value and level of sensitivity. (Source: Derived from SANS Institute InfoSec Reading Room)
- Source Appendix C: Glossary of FFIEC Cybersecurity Assessment Tool
- Data Loss Prevention
What can go wrong in DLP implementation - Source: Data Leak Prevention © 2010 ISACA.
|
Risk |
Impact |
Mitigation Strategy |
|
Improperly tuned network DLP modules |
|
Proper tuning and testing of the DLP system should occur before enabling actual blocking of content. Enabling the system in monitor-only mode will allow for tuning and provide the opportunity to alert users to out-of-compliance processes and activities so they may make adjustments accordingly. Involving the appropriate business and IT stakeholders in the planning and monitoring stages will help ensure that disruptions to processes will be anticipated and mitigated. Finally, establish some means of accessibility in the event there is critical content being blocked during off-hours when the team managing the DLP solution is not available. |
|
Improperly sized network DLP module |
|
Ensuring that the size of the DLP module is appropriate for the amount of network traffic is a critical design consideration. However, it is just as important to monitor the DLP network modules to ensure that network traffic does not increase over time to a point that renders the module ineffective. |
|
Excessive reporting and false positives |
|
Similar to an improperly configured intrusion detection system (IDS), DLP solutions may register significant amounts of false positives, which overwhelm staff and can obscure valid hits. Avoid excessive use of template patterns or “black box” solutions that allow for a little customization. The greatest feature of a DLP solution is the ability to customize rules or templates to specific organizational data patterns. It is also important that the system be rolled out in phases, focusing on the highest risk areas first. Trying to monitor too many data patterns or enabling too many detection points early on can quickly overwhelm resources. |
|
Conflicts with software or system performance |
|
DLP systems, particularly crawlers and end-point agents, can conflict with other system software and performance. Allowances must be made for ample planning and testing before deployment. Ideally, a permanent testing and staging environment should be available. Check with the vendor for known conflicts. Ensure that crawlers are properly configured and tuned and that their operation is scheduled in such a way as to avoid peak system processing windows. When avoidable, end-point scans should not be scheduled for peak work hours or when systems are remotely connected. Also, ensure that all patches and upgrades are tested within the test environment prior to deployment to production. |
|
Changes in processes or IT infrastructure rendering DLP controls ineffective |
|
The DLP system administrator or a representative should be involved in change control processes to ensure that changes made do not circumvent or otherwise degrade DLP capabilities. In addition, the enterprise should be well prepared for changes associated with DLP to reduce the risk of intentional bypassing of the DLP system in the name of efficiency. |
|
Improperly placed DLP network modules |
|
It is important to ensure the proper placement of DLP network modules. Ensure that accurate network maps are available and that the modules are placed at the outermost egress point for data flows the enterprise wishes to monitor. |
|
Undetected failure of DLP modules |
|
DLP modules can fail, but do not always report their state to the console. It is important to periodically test to ensure that modules and their associated filters are performing as expected. |
|
Improperly configured or incomplete directory services |
|
The directory service is the key connection between a network address and an actual user, and most enterprises will want to have this process in place as opposed to manual discovery of this information, which can be time-consuming and is not always possible. Enterprises that lack or have incomplete directory services should consider addressing this gap prior to implementing a DLP solution. |

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics