Skip to main content
Cover Story

DLP is not Enough

5 min read1 views
Sharefin

 Kumar Mitra,
 Country Manager, India,
 Blue Coat System Inc.

 

A spate of recent data thefts in the business process outsourcing (BPO) industry have once again focussed attention on the need for putting in place more stringent data protection regulations and securing data more effectively.  In 2008, the Information Technology (Amendment) Act put in place some guidelines for data protection. While these protections are not nearly as strong as they need to be to fundamentally change how companies handle confidential information, it is a good beginning. It shows the Government is committed to putting in place the regulations that are essential for protecting its growing IT services and BPO industries.  

Given this commitment, companies in India that deal with sensitive and confidential information could soon find that they need a solution to protect sensitive information on their networks.  

That is where data loss prevention (DLP) technology can play a role. To sustain the rapid growth in the BPO industry, India will inevitably move towards more stringent data protection laws, but organizations don’t need to be caught offguard.  Companies in Germany and the U.S., countries with strong data protection laws, have pioneered the deployment of DLP solutions and can provide best practices for utilizing those solutions to ensure regulatory compliance.   

Prioritize the Need

There are many things an organization can do with a DLP solution, and they should do most of them.  Eventually, if they do everything at once, the project will grow to an unmanageable size and become a burden for IT.  

It is crucial that organizations understand and prioritize the key issues that are driving their deployment of a DLP solution, whether they are compliance, proprietary information concerns or some other issue. Organizations should determine the top priority items and create a deployment plan that reflects those priorities. The goal should be to claim initial success without requiring a full DLP deployment.

Understanding the key drivers of the deployment will also help select the appropriate solution.  Not all DLP solutions provide the same functionality, and understanding those drivers will help determine which products an organization should consider. 

A global organization or even a regional organization will need a solution that supports multi-byte characters so that it can match content in the Japanese, Chinese, Arabic and many other languages. Without that support, a business will have to deploy local solutions in each country, creating a multi-vendor policy, management and reporting headache.  

Carefully analyzing how a solution catches sensitive content is equally important.  The lack of advanced data recognition technologies, for example, could result in high false positives or overblocking that impedes productivity. Organizations that are concerned about overblocking content should be sure their solution has fingerprinting technology in addition to keyword matches.  

Using fingerprinting to accurately register content helps reduce false positives, which can be high when keyword or pattern-based matching is used alone. Fingerprinting enables organizations to create signature-like profiles of proprietary and sensitive data that is then matched against traffic running on the network.  It also eliminates the need to manually maintain white lists or other resource-intensive workarounds.

DLP is not Enough

While the right DLP solution can be effective for preventing loss of sensitive, personal or confidential data, it is not foolproof and should not be deployed as a standalone solution.  It works best when it is deployed in tandem with proactive user education programme and a security architecture that features other layers of defence. 

Most leaks are accidental, and DLP solutions are most effective if they can inform the employee when they are attempting to do something that violates policy.  A solution that provides real-time feedback to the user can help them become more aware of their responsibilities and the risk involved with seemingly innocent activities. This type of education increases the user's awareness and results in self-policing of policy.  

DLP systems should both directly enforce policy and reinforce education efforts through context-sensitive messaging to the user.  Employee education can take many forms, such as written policies that are propagated through the organization or even coaching pages that pop up when an employee tries to send sensitive information via webmail.  These pages allow organizations to educate employees about the types of data that cannot leave the corporate network, and they can even point the employee to the appropriate policy documentation. This constant reinforcement has proven highly effective in reducing unintentional employee data leaks. It also serves to create an awareness of the defences that are in place to help prevent malicious data breaches.

Integrating DLP into an existing security framework that provides multiple layers of defense is also critical to successfully prevent data loss. In this framework, DLP can work with other defences like anti-virus and web filtering solutions to ensure that sensitive data doesn't leave the network.  For example, if a user is infected with malware that collects personal identification information to send back to a server, a web filtering solution could identify that link as malicious and block it, preventing the data from leaving the corporate network.  

The bottom line is that DLP solutions offer organizations an effective way to prevent data breaches, particular in the context of a strong multi-layer security architecture. In countries that already have data notification regulations and where DLP adoption is up, data breaches are clearly down. For Australian organizations, the lessons from these earlier deployments are plentiful and provide a good map for how to successfully deploy DLP technology without the pitfalls.