Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Security breaches: 3 tools for preventing data loss

By Jarina D'auria , CIO , 10/21/2008
  • Share/Email
  • Tweet This
  • Comment
  • Print

When it comes to protecting data, there isn't one end-all, be-all solution. That's more true now than ever, when your most likely threat is your own employees. As more workers blur the line that surrounds the workday and bring their laptops, smartphones and other devices home, they are potentially putting their companies' data at risk. In a recent CIO survey, 34 percent of respondents had a security breach where their own current employee was the culprit. More on CIO.com Why Technology Isn't The Answer To Better Security The Rising Threat of Intellectual Property and What You Can Do About It 8 Cheap Tips for Avoiding Pesky (and Expensive) Data Breach Notifications

Data loss prevention tools provide ways to identify risky data-handling activity and enforce a remediation action, says Jonathan Penn, VP of security and risk management at Forrester Research. Currently available software to prevent data loss addresses three levels of security: protecting networks from rogue devices, protecting systems from inappropriate access and protecting the data itself. A modern strategy to keep data secure should involve a bit of each, says Penn.

Block Unknown Devices

Deputy CIO Jeff Kuhns needed to protect the networks of 24 campuses within the Pennsylvania State University System against rogue devices-that is, any device not expected to be on the LAN. To address this need, Kuhns deployed software from Mirage Networks.

The software offers a traditional approach to protecting data by keeping outsiders at bay. Once installed, the Mirage system locates connected devices. The IT department can set up access policies for each device and for individuals or groups of users. The system protects data by blocking unauthorized devices from accessing prohibited data.

Such "agentless" solutions are good for organizations that have little control over the devices that end users choose, says John Kindervag, a senior analyst at Forrester. Unlike agent-based solutions, which require software on the device itself, agentless solutions reside on the network. However, as with any security tools, they can't stand on their own. "Agentless [technology] has been the primary way data loss prevention has been deployed," says Penn, "but few vendors have rich agent functionality that is unified with network scanning and remote discovery."

At Penn State, says Kuhns, Mirage software is part of "a defense-in-depth deployment of multiple systems and strategies." These include traditional security devices and software such as firewalls and antivirus technology.

From Devices to Databases

With limits to network-based protection in mind, some organizations have turned to tools that ensure legitimate users don't access data improperly. That's the problem that Nick Ray, CEO of expressHR, wanted to address.

ExpressHR helps companies in the U.K. manage temporary workers. "Our whole business is this application of sensitive data," including Social Security numbers and passport information. "If there was a security breach, it would be terminal," says Ray. Before heading up expressHR, he was cofounder and CEO of Prevx, an Internet security company.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (4)
Login
Forgot your account info?

DLP is only as good as its Detection EngineBy Anonymous on October 21, 2008, 7:37 pmYou need to know from the DLP Vendor what their False Negative Rate (not stopping the data) and False Positive Rate (stopping the wrong data). If it's a virtual...

Reply | Read entire comment

DUHBy Anonymous on October 22, 2008, 11:04 amUmmm.. Do you think ANY DLP vendor will advertise a high false positive/false negative rate?

Reply | Read entire comment

Clarification on Data Security and DLPBy DaveMeizlik on October 22, 2008, 11:58 amDLP is really a subset of Data Security, which includes technologies like device control and encryption. I think perhaps that point was missed here, and led to...

Reply | Read entire comment

GTB Technologies - virtual zero false positive & zero false negaBy Anonymous on November 10, 2008, 3:48 pmFrom Frost & Sullivan's 2008 report "solving the market limitation of high false positive rates". No other vendor is willing to make a claim.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed