Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Why data-loss prevention tools scare the hell out of some

DLP can highlight poor data practices, raise legal issues, early adopters say
By Ellen Messmer , Network World , 05/22/2008
  • Share/Email
  • Comment
  • Print

Though data-loss prevention gear is proving a boon for corporate security, its “see all, know all” style of content monitoring can cast a harsh glare on business practices and legal issues that end up putting information-technology staff on the spot.

DLP content-monitoring equipment often gets rave reviews from security managers deploying it because it can give them a view they never had before into their organization’s daily business communications. It may present the big picture, zeroing in on where sensitive data slipped out and who did the deed. But chief security officers with months of DLP experience caution all this newfound knowledge can be disruptive, spotlighting internal data-management practices that incite concern about possible regulatory violations.

“You move from ignorance to compliance jeopardy,” acknowledged Tony Spinelli, senior vice president of information security at credit information services firm Equifax, describing one impact that deploying DLP — in this case, the Symantec Vontu equipment — made at his firm. “A lot of regulations say when you know what’s leaving your network, you have to disclose that.”

Spinelli, who spoke on a panel at last month’s RSA Conference on the topic, said in spite of the initial disruption caused by finding out about internal business data practices that had to be fixed, Equifax is now so accustomed to DLP content-monitoring that it’s now considered just part of the security “hygiene,” he said.

DLP also has played a role in bringing together the human resources, legal and security groups at Equifax to coordinate content-monitoring policy, he added.

Two other security managers who joined Spinelli at the RSA panel to discuss DLP also cited its disruptive influence.

“How do you look at your data, know your data and understand what you have? We never had tools to tell us what was happening and we relied on anecdotal evidence or audits to find out,” said Patrick Lefemine, chief information security officer at Hartford, Conn.-based firm Lincoln Financial Group, another Vontu user.

Lefemine acknowledged the initial piloted use of DLP “scared the hell” out of both management and IT staff, especially the time it spotted the CEO’s salary, Social Security Number and home address being inadvertently transmitted. “That got us the funding for this project,” he added.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

DLP and ERMBy Ralph Sherman on May 27, 2008, 3:12 pmWhen we deployed DLP, it did identify some compliance issues (we are a pharma company). More importantly, it identified what sensitive documents (Word, Excel, PDF)...

Reply | Read entire comment

Why scared?By tuomoks on May 23, 2008, 4:14 pmA good advice from the article "business people need to be active participants in data monitoring, not leaving it to the IT department" Why to be scared? Knowing...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed