The Definitive Guide To Data Loss Prevention
The Definitive Guide To Data Loss Prevention
THE DEFINITIVE
GUIDE TO
DATA LOSS
PREVENTION
1
THE DEFINITIVE GUIDE TO DATA LOSS PREVENTION
TABLE OF CONTENTS
03 Introduction
04 Part One: What is Data Loss Prevention
08 Part Two: How DLP Has Evolved
11 Part Three: The Resurgence of DLP
24 Part Four: The Shift to Data-Centric Security
28 Part Five: Determining the Right Approach to DLP
40 Part Six: Business Case for DLP
47 Part Seven: Buying DLP
53 Part Eight: Getting Successful with DLP
62 Part Nine: Digital Guardian—Next Generation Data Protection
66 Conclusion
67 Resources at a Glance
2
INTRODUCTION
3
THE DEFINITIVE GUIDE TO DATA LOSS PREVENTION
PART ONE
WHAT IS DATA LOSS
PREVENTION?
4
PART ONE: WHAT IS DATA LOSS PREVENTION?
DLP DEFINED
“DLP [Data Loss Prevention] is a system that performs real-time scanning of data at rest and in motion,
evaluates that data against existing policy definitions, identifies policy violations and automatically –451 Research, “The
Data Loss Prevention
enforces some type of pre-defined remediation actions such as alerting users and administrators, Market by the Numbers,”
quarantining suspicious files, encrypting data or blocking traffic outright.” July 2015
50%
DLP BASICS WHO USES DLP?
WHAT: In short, DLP is a set of technology tools and processes that COMPANY SIZES: Large enterprises in the Fortune Global 500
ensure sensitive data is not stolen or lost. have invested in DLP for almost 15 years. Today’s DLP puts this
critical security strategy within the reach of mid-size enterprises.
HOW: DLP detects and protects your organization’s sensitive data by:
• Scanning data in motion, in use and at rest INDUSTRIES: Historically DLP has been heavily utilized in regulated
• Identifying sensitive data that requires protection industries such as financial services, healthcare, manufacturing,
• Taking remedial action—alert, prompt, quarantine, block, encrypt
• Providing reporting for compliance, auditing, forensics and
energy, even government. But new and motivated adversaries aren’t
limiting themselves; services companies across a wide range of
OF ORGANIZATIONS
have some form of DLP in place, but Gartner
incident response purposes industries are a major target for example. predicts that will rise to 90% by 2018. (source:
Gartner “Magic Quadrant for Enterprise Data
WHY: accidental (i.e. employee error) or malicious actions (i.e. cyber Loss Prevention”, 1 February, 2016 , Brian Reed
criminal breach) put your organization's data at risk. and Neil Wynne)
5
PART ONE: WHAT IS DATA LOSS PREVENTION?
DO WE NEED DLP?
Take a look at these common situations. If any of them apply to your organization, DLP will almost always make sense.
6
THE DID YOU KNOW?
GREAT
BRAIN SEE OUR BLOG
To learn more we
recommend, WIPOut:
ROBBERY
The Devastating
Business Effects of
Intellectual Property
Theft on our blog.
Intellectual property
is increasingly being
compromised.
In January 2016, 60 Minutes ran a feature, "The Great Brain Robbery," by Lesley Stahl that covered China’s wide-
scale attack on U.S. companies to steal their intellectual property. Rather than competing with the U.S. economy
through innovation and development, the 60 Minutes report shows how China is committed to stealing IP through
acts of cyber-espionage.
The Justice Department declared that China’s espionage activities are so wide in scale that they constitute a
national security emergency, as China targets almost every sector in U.S. business. According to 60 Minutes, this
activity is costing U.S. companies hundreds of billions of dollars in losses and more than 2 million jobs.
7
PART ONE: WHAT IS DATA LOSS PREVENTION?
ENTERPRISE DLP
OR INTEGRATED DLP?
THOUGHT LEADER INSIGHT: JARED THORKELSON, PRESIDENT DLP EXPERTS
DG: Because of the increased interest and the detection methodologies, which translates into FREE
demand for DLP, more security vendors are adding meaningful increases in DLP effectiveness. Another DOWNLOAD
DLP functionality into their products in what is unique and critical feature of Full Suite DLP solutions
referred to as integrated DLP. So we asked Jared is a central management console. This eliminates · Get the DLP Experts
Thorkelson of DLP Experts, to explain the difference the need for multiple management interfaces and 2016 DLP Vendor
between Enterprise DLP and Integrated DLP. significantly reduces the management overhead of a Review Report.
comprehensive DLP initiative.
JT: Enterprise or Full Suite DLP technologies, are
focused on the task of preventing sensitive data loss Integrated DLP or Channel DLP solutions were
and providing comprehensive coverage. They provide designed for some function other than DLP then
coverage across the complete spectrum of leakage were modified to add some DLP functionality.
vectors. Significantly, Full Suite DLP addresses the Common Channel DLP offerings include email
full range of network protocols, including email, security solutions, device control software and
HTTP, HTTPS, FTP and other TCP traffic. Another secure web gateways. In each case, Channel DLP
critical distinction of most Full Suite DLP solutions solutions are limited in their coverage and detection
is the depth and breadth of their sensitive data methodologies.
8
THE DEFINITIVE GUIDE TO DATA LOSS PREVENTION
PART TWO
HOW DLP
HAS EVOLVED
9
PART TWO: HOW DLP HAS EVOLVED
10
PART TWO: HOW DLP HAS EVOLVED
11
WE HOPE YOU ENJOYED THIS SAMPLE!
TO READ ON, CLICK HERE & DOWNLOAD THE COMPLETE GUIDE
THE FULL GUIDE INCLUDES INSIGHTS FROM 451 RESEARCH, DLP EXPERTS, FORRESTER RESEARCH AND OUR SECURITY
ANALYSTS TO HELP YOU:
1 Select the right DLP for your organization.
2 Make the case for DLP to your executive team.
3 Get fast wins. Build from there.
TO READ ON, FILL OUT OUR SHORT FORM AND DOWNLOAD THE COMPLETE GUIDE NOW >>