• No results found

Practical DLP Deployment

N/A
N/A
Protected

Academic year: 2021

Share "Practical DLP Deployment"

Copied!
16
0
0

Loading.... (view fulltext now)

Full text

(1)

Practical DLP Deployment

Practical DLP Deployment for your Organization

(2)

DLP Basics Overview

A few items discussed today

What is DLP?

Define a DLP program using business driven approach

DIM, DIU and DAR details

DLP incident triage, reporting and remediation

(3)

What is DLP?

Context aware analysis of data at the network, endpoint and storage levels with the ability for preventative actions

Key here is Data Loss “Prevention”

Business driven – the business has to work with the

DLP team to identify the sensitive information that is valuable to the organization – this becomes the

(4)

Business Driven Approach

Key steps with all DLP programs

Conduct DLP “Workshops” to identify the following:

Discuss current business processes to identify sensitive content you would like to protect with DLP

Discuss acceptable use cases of sensitive content

Gather sample sensitive content to design and tune DLP policies

Determine “where” to apply DLP Policies to monitor

SMTP/HTTP (DIM), Endpoint USB (DIU), NAS Shares (DAR), etc.

As confidence with DLP grows, slowly introduce preventative actions such as block email, modify HTTP sessions or even block copy to unapproved USB devices

(5)

DLP Policies

Area of DLP where you define the sensitive

data (context) to filter on - includes both out of

the box and custom policies

Can be combination of multiple detection

technologies including keywords, regular

expressions (DCM), file indexing (EDM/IDM),

file type, etc.

Multiple rules can be combined in policy logic

to increase the accuracy and reduce the false

positive rate of DLP incidents

(6)

DLP Deployment Planning

Crawl, Walk then Run works best

Start slow with one vector such as Network or Endpoint

Pick 3-5 policies in audit only mode to assess leakage scope

As DLP program matures, slowly add additional policies, vectors and proactive actions such as block or quarantine

You can only protect sensitive information you have identified moving forward – DLP can’t look

(7)

Data in Motion (Network)

Monitors SMTP, HTTP, HTTPS* and other clear text protocols

SMTP is most common starting point as most organizations already have web filtering in place via proxy servers

Can be inline or passive

Inline is most common for SMTP

DLP can connect to existing proxy servers via ICAP

Passive monitoring is common for internal to internal network monitoring via network tap or spanning port

Inline is required if you plan on implementing preventative actions such as block, modify, etc.

(8)

Data in Use (Endpoint)

Monitors data at the endpoint such as local

disk, copy to USB, printing, etc.

Allows context driven analysis of both stored data and actions such as copy to local disk and USB storage devices, printing, application monitoring

Can be configured to monitor both on and off the network

Logic can be built into Endpoint policies to allow copy to approved USB devices while blocking copy to unapproved USB storage devices

(9)

Data at Rest (Storage)

Monitors stored data on NAS, SharePoint, Exchange and Databases

NAS is most common starting point as most organizations struggle to identify where sensitive data is stored

Supports multiple vendors such as NetApp, EMC and Win NASSharePoint is rapidly become more common in DAR

Lack of user access control and organization leads to proliferation of sensitive data on SharePoint sites

Database scanning supports Oracle, SQL server, DB2 and other common formats

(10)

DLP Incident Triage

This is where the DLP analyst reviews each

incident to verify accuracy and determine

follow up actions

Dedicated, full time resources here will quickly

recognize broken business processes,

potential security violations and provide much

more ROI with DLP than shared resources

Don’t create an incident unless you can review

(11)

DLP Reporting

While DLP does a great job of explaining

incident details, manual analysis of exported

incident data is usually required for trending

Reports detailing trending analysis of users,

increase/decrease of DLP incidents over time

and incidents by business units are common

Consider third party tools such as IT

Analytics, SIEM, etc. to improve reporting

capabilities

(12)

Use Case – Large Healthcare

Large healthcare company providing medical

services

Primary goal is protection of PHI and PII – custom index (IDM) policies created from PHI & PII databases, additional regular expressions/keywords (DCM) PHI & PII policies

DIM for HTTP and SMTP, DAR for PII and PHI stored on unsecured network shares and external facing SharePoint sites

DIU for endpoint copy to USB with exception for copy to

approved USB, quarterly scans for PHI and PII data stored on local disk

(13)

Use Case – Small Manufacturing

Small manufacturing company with

engineering designs in various file formats

Custom index (EDM/IDM) policies for all design

documents, additional regular expression/keywords (DCM) policies for similar design documents

Unique situation with Office 365 in use for SMTP

Endpoint SMTP monitoring via Outlook application monitoring*, endpoint copy to USB and printing

(14)

Recap

What did we cover today?

What is the difference between DLP and other security tools? – Context

Business driven approach

Deployment details on DIM, DIU and DAR

Incident triage and reporting

(15)
(16)

Contact Information

Jon Damratoski, DLP Architect, Black Diamond Technology

[email protected]

Office (615) 469-2468

Chris Mitchell, Senior Security Solutions Engineer, TN, Symantec

[email protected]

References

Related documents

This paper presents the performance and emission characteristics of a CRDI diesel engine fuelled with UOME biodiesel at different injection timings and injection pressures..

However, an ASM disk group can contain files belonging to several data- bases, and a single database can use storage from multiple ASM disk groups. You

Soot oxidation was studied by evaluating PSDs in the two-stage burner by using a SMPS. This experimental technique, along with measurements of flame temperature,

Oklahoma store had a specific complaints dollar general district manager because you were in the basic email address richard is.. Against me on, email dollar district manager and i

А для того, щоб така системна організація інформаційного забезпечення управління існувала необхідно додержуватися наступних принципів:

2010-present Director of Writing Programs, Indiana State University 2010 Acting Director of Writing Programs, Indiana State University 2008-present Associate Professor of

The author uses a form of qualitative research known as narrative inquiry to view the temporary closure of an academic branch library from the viewpoint of students who used

© 2013 WB MUSIC CORP., WHEN I’M RICH YOU’LL BE MY BITCH, PRESCRIPTION SONGS, MXM MUSIC AB, KASZ MONEY PUBLISHING, ONEIROLOGY PUBLISHING, ITALIANS DO IT BETTER and DEEETTA MUSIC.