DLP Experts News

...................................................

All-New Q2 Webinar Series

We have developed a new series of DLP webinars designed to provide relevant and practical guidance that can be acted upon for immediate impact in any organization. Topics include DLP Complexities: Unplugged and DLP Technical Requirements ReviewClick here for info and to register!

...................................................

Listen to the rebroadcast of DLP Experts, CA and Capella University in the (ISC)² ThinkTank on Integrated Data Governance: Identity Aware Data Protection and Control from December 14, 2010.

...................................................

DLP Experts' Jared Thorkelson visits once again with Tom Field of BankInfoSecurity.com for a podcast entitled The True Value of Data Loss Prevention.

...................................................

Read the new feature article by DLP Experts on infosecurity.com Simplifying Data Loss Prevention....................................................

Download the new DLP Experts White Paper sponsored by Blue Coat entitled, The Evolution of Data Loss Prevention:  Reducing Complexity.

...................................................

Jared Thorkelson of DLP Experts presented at the recent (ISC)²® e-Symposium, Assets vs. Liabilities - Managing the Insider Threat, on the topic of Effective Employee Management for Better Data Protection

Also see these DLP Experts archived events:

Effective Employee Management for Better Data Protection - "This e-Symposium was, without a doubt, superior to many others...These topics cannot be overly emphasized. Thanks a ton - Keep preaching it!"

The Truth About DLP

Building a Solid Foundation for DLP

Understanding the Limitations of DLP

...................................................

See DLP Experts in the recent BrightTALK Data Loss Prevention Summit. View the archived event

...................................................

DLP Experts' interview and podcast with founder, Jared Thorkelson, on BankInfoSecurity.com. Listen to the archived event.

« DLP Myth #3: You can "buy" DLP | Main | DLP Myth #1: You can get DLP as an add-on to an existing solution. »
Monday
Aug302010

DLP Myth #2: DLP is Architecturally Complex

A common misconception is that DLP must always be archtiecturally complex.  This myth has roots in reality; traditional DLP techonologies have been architecturally complex.  However, as DLP technologies evolve, there is a move toward greater archtitectural simplicity.

To understand how we go to the architectural complexity, consider the origins of data loss prevention:  built for the world's largest enterprises and with an immature roadmap that was a moving target in early years.  Original DLP technologies were really DLD, data loss detection.  They were designed first as passive network monitors looking for patterns matching simple expressions such as for social security and credit card numbers, but there was no blocking involved.  As companies saw data leaving the organization, it didn't take long for the next requirement to come to light:  blocking.  Then came discovery, endpoint and so on. 

Most early vendors employed a modular, multi-server architecture, which is typical among the .  This gave them the ability to develop one server component at a time as market demand required, rather than bring everything together under a single server.  The results were shortened development times.  Plus, it allowed early adopters to get their feet wet with the new technology, one component at a time. 

A key side benefit of the modular approach was that it spread the load among many servers, keeping the network monitor free for the all-critical task of identifying sensitive information.  It was an unspoken concern that an overloaded network monitor could "slip," allowing sensitive data to get by without being seen.  This was an especially important concern to address among the early adopting large enterprise, who have a tendency to run at bandwidths that can overload packet filters.

This evolution resulted in DLP architectures that require many servers:  management server, network monitor, database server, email blocking server, web blocking server, discovery server, endpoint management, etc.  Couple this mult-server approach with separate integrations for mail transfer agents, ICAP proxies, databases, active directory, etc., and you end up with a very complex architecture.

Contrast this traditional DLP architecture with the concept of a single appliance that combines everything required for a complete DLP suite:  network monitor, management interface, incident database, web and email blocking, discovery and endpoint management.  This is the approach of a couple of DLP vendors.  And even the traditional DLP vendors normally requiring 4-5 servers are reconizing the need to simplify with single appliances running 2-3 DLP components as virtual machines.

DLP does not have to be architecturally complex.  Some vendors have developed simple architectures combining components in single appliance, while others are leveraging virtual machines to make their architectures more steamlined and easy to deploy.

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>