Gartner: Don't let suppliers set your DLP strategy
- 29 September, 2009 03:44
- Comments
Businesses should plan a thorough data loss prevention strategy before talking to suppliers, Gartner has advised.
Vendors are likely to sway discussions to specific aspects of DLP, when a full strategy is required for the technology to be effective, the analyst house said.
DLP software monitors data that is in use, moving on the network and in storage, in order to prevent its unauthorised use or transmission. Gartner predicts it will become commonplace in European firms during the next six years, and said deployments were already being considered by many businesses.
"You've got to define your strategy first, then talk to the suppliers," said Paul Proctor, VP at Gartner. "At the moment businesses aren't labelling data properly, they don't know where it is, they aren't handling it properly, and their policies are poorly defined and enforced."
Speaking at Gartner's information security summit in London this week, Proctor outlined how businesses can define a complete strategy for DLP.
Organisations needed to first define their data types, followed by building a list of possible actions for that data, then defining policy, and finally negotiating with suppliers.
For defining data types, Proctor said, firms should categorise the information according to its nature and where it resides. For example, intellectual property could be split into drawings (then divided as CAD, PDF, and GIF), documents (split as structured, unstructured, labelled and unlabelled), and personal data (split by types such as credit cards or ID numbers, or by its application such as order processing or online sales).
For building a list of possible actions that could happen to the data, businesses should "boil the possible uses down to 10 to 15 situations", Proctor said. These could include data crossing the enterprise boundary; data stored in unauthorised places; the copying, printing, moving, saving, cutting and pasting of data; and business processes that could put the data at risk.
Common areas of worry for businesses included sales people stealing client information, and the offshoring of work involving critical intellectual property, he said.
Lastly, for defining policy, firms needed to set different levels of reaction according to how concerned they would be about the incident. The lowest stage could be alerting the business and recording the situation for future analysis.
The next higher stage would be intercepting the data to automatically encrypt it, move it from the risk area, or demand user justification for a particular operation. Above that, the particular operation could be automatically halted.
Proctor also highlighted Gartner's 'Magic Quadrant' of DLP suppliers, which covers those that are judged to provide the best product and service and to have the most innovative long-term business plan. Symantec, Websense and RSA were the only suppliers it placed in this category.
"A lot of people have deployed a sort of DLP for simple requirements, like protecting credit card data," he concluded. "But that isn't enough -- they need to protect all data including their valuable intellectual property."
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Get Control: make document management an integral part of your overall IT strategy
- Lower Your IT Costs When You Standardize on Oracle Database 11g
- Advanced Malware Exposed - How advanced malware, zero-day and targeted APT attacks are evading today's network defences
- Providing effective endpoint management at the lowest total cost
- 10 Essential Steps to Email Security
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Leaving your job? Take your data with you
-
A Technical Overview of the Oracle Exadata Database Machine and Exadata Storage Server
Businesses today increasingly need to leverage a unified database platform to enable the deployment and consolidation of all applications onto one common infrastructure. Whether OLTP, DW or mixed workload a common infrastructure delivers the efficiencies and reusability the datacenter needs – and provides the reality of grid computing in-house. Read on. -
IDC Insight: V-Ray Gives Symantec NetBackup a Competitive Advantage Today and into the Future
Over a decade ago, Veritas software announced NetBackup FlashBackup to address the millions of small files problem, which had been and often remains the nemesis to fast and efficient backup of large file servers. Today, the FlashBackup technology is used to provide a logical understanding of what is stored with a VMDK- or VHD-image-level backup, without the necessity to install an agent inside each virtual machine. Read more. -
Sun Blade 6000 Modular System: Power and Cooling Efficiency
Most IT organizations are struggling with the need to deploy ever more applications in the fixed space, power, and cooling envelope of their data centers, the ability to save even a hundred watts per system quickly turns into more breathing room for future applications and the servers to run them. Read on.
-
Windows 7 for Seniors for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Office 2007 for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition








Comments
Post new comment