Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Data loss prevention solutions=expensive exercises in failed policy

DLP solutions are the first-last opportunity to correct a policy problem...and do so at the last frontier (the network perimeter). If some confidential data has been inadvertently exposed via an email, isn't the problem procedural and policy not a technology issue? Answer: Yes.

Yet, here we are today with countless DLP vendors pitching their respective solutions (starting at $25,000 dollars and going up from there) as a way to prevent data loss. It's laughable! People are trying to control human behavior with automated controls. It doesn't work. Throwing a lock on the Internet gateway just means that someone can carry data out of the network on a thumb drive or in a printout. It's not a technology issue, it's how the technology is used issue.

If users are taught about the risks and what they can do to minimize them, an organization will be vastly better off and more secure WITHOUT having to buy the expensive 1st last solutions to supposedly prevent data leaks.

Click to read the article this is in response to.

The Holes In A Network's Security

0

Companies seem to have more holes or potential leaks than all the dikes in Holland. Worrisome, especially given the fact that "everyone" has a smart phone and is IMing. Common sense is the first solution. Unfortunately, not everyone......

Plug the Holes???

0

What about the human factor? You can patch, close ports, set a policy, etc., but if the education hasn't been done for everyone accessing the network, than your parameter is still Swiss cheese.

I'm curious why you the problems with WLAN connection (or other open connection protocols) haven't come up more. Not man in the middle per se, rather devices authenticating themselves to the network, open the door for packet drops onto the device. Big problem here.

A company called NCP engineering has a VPN client that makes any network authenticate itself to the device (no packet transfer at all). They call this 'friendly net detection'. I don't think anyone else does this.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: