Sunday, June 02, 2024

My Experience with DLP - Data Loss Prevention (Airbus)

 ForcePoint DLP

Forcepoint Data Loss Prevention (DLP) is a robust solution designed to safeguard sensitive data across various channels, including web, cloud, email, network, and endpoints

  • The solution dynamically adjusts policy enforcement based on user behavior to prevent data breaches. (risk based policy enforcement)
  • Real-time audit and intervention help stop data loss before it occurs. 
  • Forcepoint DLP accurately classifies sensitive data using artificial intelligence.
  • It protects against unauthorized actions (e.g., downloading, emailing) on files containing intellectual property or sensitive information.
  • Unstructured data discovery
  • Email data theft prevention (outbound and inbound emails).
My activities.

  • DLP Network and Endpoint security project.
  • Due diligence - 79 laptops identified and deployed DLP. Gathered stats and reporting.
  • Eventually 600 laptops. Filton.

> Data prioritization was done by the business (what data to classify / protect, etc.)
> Categorize data -- apply appropriate classification tags
> Policy creation and configuration (Security devs in conjunction with security teams)
> Deployment options -- POC on 79 laptops, gather stats, report.
> Actualy deployment on 600+ laptops.
> Dashboard configuration, monitoring / reporting, define BAU processes. 
> Training and user education.

Metrics gathered

On time resolution rate
Resolution rate
Delivery time
Audit rate
Bug fixing change time
Change blocking incident
Change duration
Change incident
Change volume
On time change rate
On time urgent change rate 
Unplanned change communication
Planned change communication
Urgent change time


No comments:

Post a Comment

DSPM, Data Security Posture Management, Data Observability

DATA SECURITY POSTURE MANAGEMENT DSPM, or Data Security Posture Management, is a practice that involves assessing and managing the security ...