May 13, 2009

RSA Data Loss Prevention Suite 7.0 - Review

RSA Data Loss Prevention Suite 7.0 - Review

Introduction

Acquired from Tablus in 2007, the RSA Data Loss Prevention (DLP) Suite (formerly the Tablus Content Loss Prevention Suite) is a multi-component platform that enables the Enterprise to both identify potentially sensitive corporate data and enforce centrally defined policies pertaining to that data, including remediation actions such as moving or quarantining the data or enforcement actions such as blocking the transmission of the data in E-mail communications or preventing it from being copied to a USB drive. The suite consists of three main components: RSA DLP Datacenter, RSA DLP Network, and RSA DLP Endpoint.

The RSA DLP Datacenter component (Windows 2000 Server/Server 2003) is targeted to server farms and data centers, and provides the ability to periodically (and incrementally) scan resources (including file shares, SAN/NAS storage, DBs, CMSs, etc.) for the existence of sensitive data, with policy-based remediation actions (including quarantine, delete, or move the data) automatically applied. Sensitive data is identified via detection algorithms that analyze keywords and patterns as well as their contextual placement, with provided pre-built detection templates offered for the identification of data related to regulatory requirements such as PCI, PII, HIPAA, GLBA, and SOX. Support is also provided for the customization of detection rules. Other features include centralized management and policy definition (more below), as well as workflow-enabled incident tracking, and alerting (E-mail, RSS, IM) to appropriate individuals.

The RSA DLP Suite comprises a comprehensive data loss prevention solution that enables customers to:

* Discover and protect sensitive data in the enterprise. Leverages common policies across the infrastructure to discover and protect sensitive data in the datacenter, on the network, and on endpoints

* Mitigate risk. Mitigates risk through identity aware policy based remediation and enforcement

* Reduce Total Cost of Ownership. Reduces TCO with industry leading scalability, automated protection of sensitive data, and most comprehensive policy library

* Simplify security operations. Streamlines the security operations process with incident handling and workflows, and by integrating the RSA DLP Suite with enVision
RSA DLP Datacenter

DLP Datacenter helps you locate sensitive data no matter where it resides in the datacenter – on file systems, databases, email systems and large SAN/NAS environments.


RSA DLP Network

DLP Network monitors and controls sensitive data leaving your network.


RSA DLP Endpoint

DLP Endpoint helps you discover, monitor and control sensitive information on endpoints such as laptops and desktops.


Microsoft AD RMS Integration

The integration of DLP Datacenter and DLP Endpoint Discover with Microsoft Active Directory Rights Management Services (RMS) helps you to automatically apply RMS protection to sensitive documents at rest discovered by RSA DLP.

New Enhancements to the RSA DLP Suite

The latest release of the RSA DLP Suite allows organizations to secure sensitive content in a way that saves time and streamlines processes for data security personnel. Sensitive data at rest can now be moved or quarantined automatically, reducing administrative costs, and end users can apply self-remediation for sensitive emails quarantined due to violations. In addition, the RSA DLP Suite is engineered to generate and send reports automatically to the appropriate personnel. These new automation enhancements can help reduce the time spent handling security incidents by up to 45 percent.

These new features also help organizations reduce risk by proactively locating and controlling data for even more sensitive data types and sources. Organizations will now be able to discover structured content in Oracle and SQL Server databases with native scanning and fingerprinting. The RSA DLP 7.0 Suite is also engineered to broaden protection of intellectual property with automated file fingerprinting functionality across all three modules of the DLP Suite: Datacenter, Network, and Endpoint. Additional enhancements also make the RSA DLP Suite the only data loss prevention offering that supports CATIA, a multi-platform commercial software suite used in the aerospace, automotive, and discrete manufacturing industries.
With 22 new policy templates, RSA also continues to provide one of the most comprehensive DLP policy and classification libraries in the industry. These new policies include support for North American Electric Reliability Corp (NERC) compliance along with additional coverage for policies that help protect personally identifiable data in Australia, Italy, Netherlands, Spain, Sweden, and New Zealand. These new policies have been added to RSA’s already-robust database of more than 100 different policy templates. By leveraging RSA’s pre-built policy and classification library, customers can reduce risk by securing more types of sensitive data while reducing the costs associated with false positives, according to a recent study commissioned by RSA which found that RSA’s solution offers 27% higher accuracy in avoiding false positives over one of its main competitors.

Overall, the RSA DLP 7.0 Suite is engineered to deliver more than 68 enhancements in the areas of policy management and classification, remediation, database scanning, reporting and administration.
Milestones

Integration With The RSA enVision Platform Helps Simplify Security Operations

The RSA DLP 7.0 Suite is designed to integrate with the RSA enVision platform, RSA’s market-leading Security Information and Event Management (SIEM) offering which is designed for simplifying compliance, enhancing security operations and risk mitigation, and optimizing IT and network operations through the automated collection, analysis, alerting, auditing, reporting and storage of all logs. The integration streamlines the process of understanding security risk – through efficient correlation of security and DLP event logs, security analysts gain insight into the type and sensitivity of information involved in the incident and can quickly determine when and how to remediate it and assess what damage has been done. The integration also enables centralized management through the enVision technology of DLP events, simplifying security and compliance reporting. New enVision reports leverage events from the RSA DLP Suite to enable holistic data protection across information, identities, and infrastructure.


RSA DLP Suite Helps Microsoft Secure Data and Accelerate Compliance With Regulatory Requirements

One organization that has successfully leveraged the RSA DLP Suite is Microsoft Corporation. Microsoft uses the solution to enhance the security of sensitive data about employees, customers and intellectual property in thousands of its own managed file shares, endpoints and Microsoft® Office® SharePoint® sites.


Domino's Pizza Gains Increased Visibility and Awareness Into Data Protection Issues

Domino’s Pizza is the recognized pizza delivery leader in the United States. It must comply with a number of standards and regulations, along with protecting its brand image. Domino’s has used the RSA DLP Suite to scan data at rest to help ensure that it is in compliance with PCI, SOX, HIPAA, and other general guidelines around protecting personally identifiable information (PII).

No comments:

Post a Comment

Popular Posts