On CBS MoneyWatch: Report: Tiger to Pay Wife $60 Million
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 5 of 5:
« Previous
RE: How to keep your data secure
Suedell,

Two comments:

The real question about a content inspection product, like any other security product is "Does it reduce your risk ?" and "By how much ?"

A DLP product can reduce a risk by blocking behaviour that creates risk for the organization. It can reduce risk a LOT more by helping a CISO educate the end user what risky behavior is, and through that help reduce that behavior. Only in a few severe cases blocking the user in mid-action is recommended - and this recommendation is from a company whose blocking capabilities were the basis to its content inspection, not the other way around.

As to detection rates - I agree that inaccurate results reduce the effectiveness of the product, as was the case for HIDS.

However, I know of no agreed way of measuring false positive and false negative rates for DLP, or any independent 3rd party doing those tests. Contrary to SPAM or Anti Malware testing where you have a sample you can test across vendors, and a mostly clear outcome - for DLP this is not the case.

Given that FP rates depend not only on the sample, but also on the subjective decisions of a tester and the fine tuning of the rules (and resulting FN rate) to fit with a specific organization, I do not see what is the meaning of "67%" or "99.999%" as a single number for an end user.

I could understand a sentence like "Out of the box 99.95% detection of credit card numbers with less than 0.3% false positives on a sample of 10,000 emails and 20,000 files from N customers", but none of the vendors seems to be as specific.

I did not even see "X% detection with Y% false positives after only 6 weeks of fine tuning"

The advantage for a product that has rich file based port control is that on day 1 you can have 100% accuracy for some flows that reduce risk considerably. Then, it is a lot easier to continue improving the more difficult flows.Part of the improvement will definitely come from end user training, not just rule fine tuning.
Posted by: edyalmer   Posted on: 01/21/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

The Most important point of DLP - Accuracy Rate  suedell | 01/14/09
GTB Technologies - Most Accurate DLP solution  ShaneGold | 01/14/09
RE: Have you looked into Vontu?  jacec | 01/14/09
Vontu 67% accuracy rate - per The Tolly Group  suedell | 01/15/09
RE: How to keep your data secure  edyalmer | 01/21/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

IT Solutions for 2010

  • Get cost-effective strategies and roadmaps on the most important issues facing IT leaders in 2010! Learn how to easily cut costs and deliver greater efficiency starting with your database, IT compliance management and data center. Visit the IT Leaders Dashboard. Visit the IT Leaders Dashboard.
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline