Data Loss Prevention (DLP) refers to applications and appliances aimed at identifying sensitive information in an IT system and preventing it from leaking out.

  • Sensitive customer information – or generally data that is sensitive contains
  • A customer’s name, address, or telephone number, in conjunction with the customer’s social security number, driver’s license number, account number, credit or debit card number, or a personal identification number or password that would permit access to the customer’s account. Sensitive customer information also includes any combination of components of customer information that would allow someone to log onto or access the customer’s account, such as username and password or password and account number.
  • Source: Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice
  • Managing DLP as a GRC program and project
  • Mission – Work with Business and Security to Prevent Data Loss through programs and technology known as DLP
  • Mission – Establish a culture of continuous improvement
  • Don’t do everything at once
  • Qualitative risk assessment
  • Leverage existing BIA and Data Retention Strategy,
  • Information Security Threat analysis, and
  • Integrate with Goals for enterprise IT
  • Program v. Product:
    Products prevent channels through which data can leak, HOWEVER, DLP is only effective as part of the security architecture and the compliance culture

DLP suites are often integrated into endpoint security tools and network application gateways  (examples)

  • Symantec
  • McAfee
  • Web-sense
  • Microsoft
  • RSA
  • DLP Involves a lot of Security and Engineering

A security service is a collection of security mechanisms, files, and procedures that help protect the network via:

  • Authentication
  • Access control
  • Data confidentiality
  • Data integrity
  • Non-repudiation
  • Logging and monitoring

We engage in subjects including:

  • Encipherment
  • Digital signature
  • Access Control
  • Data Integrity
  • Authentication
  • Traffic Padding
  • Routing Control
  • Notarization …
  • Data Leakage Prevention: ILDP, ILP, CMF, IPC, EPS

Some other terms associated with data leakage prevention are 

  • information leak detection and prevention (ILDP), 
  • information leak prevention (ILP), 
  • content monitoring and filtering (CMF), 
  • information protection and control (IPC), and 
  • extrusion prevention system (EPS), as opposed to intrusion prevention system.

Wrapping up, the main Elements in DLP

  • The compliance team will spend a majority of their time focused on data classification processes including:
  • Inventory of hardware and software assets
  • Network topology
  • Business process and data flow maps
  • Mapping technology operations to corporate strategic objectives
  • Data Loss Prevention involves technical knowledge and rules-based implementation. Team oversight provides tremendous value to audit, security, the enterprise and the business.
Main Menu