home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
Lead Analyst:
Jordan Wiens
Jordan Wiens


More analysis, strategies and news at our
Data Privacy
Immersion Center


Subcribe to This Blog's
RSS Feed
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



Data Privacy Immersion Center Blog

May 08, 2008
Data Loss Prevention Systems Help Battle Against Insider Threats
By Randy George

If you're responsible for the security of your network and its data, you might want to shift your focus away from looking at your network from the outside in, and look at it from the inside out.

From a threat perspective, insider attacks can be thought of like an al-Qaida element operating within your walls. You might not see the threat or an actual attack on a daily basis, but you know the threat exists and you must plan for it. Similarly, attacks from the outside can be thought of as a Hamas-like element that exists outside your corporate boundary. Hamas-like attacks are more predictable and identifiable in nature, and as a result are easier to plan for. While both threats are serious, it's the attack from within that always comes as a surprise.

But how does one plan for an attack from the inside? The answer to that question is that there's no easy answer. If you start by assessing who has access to what, IT professionals themselves are at the top of the risk factor food chain due to their knowledge and pervasive access to key systems.

But from a practical standpoint, it's not possible to limit IT's access due to the nature of the job. However, you can certainly audit access, and there's no shortage of tools to do that. One genre of security tools that helps with the auditing and securing of internal threats is data leak/loss prevention systems. DLP systems come in a variety of flavors and protect against a variety of threats, and products in this space focus on everything from securing and auditing file access to monitoring communications and content leaks to encryption of USB devices and hard drives, all the way up through the definition and real-time monitoring of policy-based information access.

Unfortunately, it's no longer possible to simply lock down resources via user credentials and fall asleep hoping that your own employees won't attack you when you're not watching. The fact is that we need to set permissions accordingly and then monitor how those permissions are being used across a wide range of technologies. With DLP systems, much of the threats that you will find will be well-intentioned, like the marketing professional who decides to copy a customer database to a laptop for use on a flight. While that's certainly a legitimate business need, there also are security implications to consider when such sensitive data leaves the organization's walls.

But don't expect DLP systems to solve all of your problems on day one, because much like a home is built by first excavating a foundation, organizations must first identify what resources and information is vital, and then move on to identifying what personnel should have access to what resources. Simultaneously, acceptable use policies should be developed that dictate what information can be accessed remotely and what information can be stored on removable media. Once security and use policies are fully developed, DLP systems can then be used to enforce and report on those policies. According to Gartner, the leaders in the DLP space right now are Vontu, WebSense, Reconnex, and Vericept.

Do you use an enterprise DLP system in your environment? Share your experience here. I'm especially interested to hear about how you've used your DLP system to catch an intruder or thief red-handed.

-- Posted at 02:57 PM in Data Privacy Immersion Center





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media Limited  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights