Data Loss Prevention

 View Only
  • 1.  Anti-Corruption Policy Creation

    Posted May 02, 2013 05:05 PM

    We are looking into providing DLP support for a partner to identify the following keywords related to external/internal corruption. 

    Cover up
    failed investment
    Nobody will find out
    Grey area
    Gray area
    They owe it to me
    do not volunteer information
    not ethical
    Off the books
    Pull earnings forward
    Friendly payments

    Obvious as you can see these keywords will create a high false positive rate when monitoring 3m emails per day.  Have others created any policies related to Anti-Corruption that would help to refine and augment 15 keywords identified?

     



  • 2.  RE: Anti-Corruption Policy Creation

    Trusted Advisor
    Posted May 13, 2013 02:31 AM

    hello A. de monaco

     this type of policy is what i used to call a "behaviour policy" and it is the most difficult one (i know you have already understand this point if you ask the question). Usually the way i proceed (dont know if it is the best), it is first to check policies in place in the company to define the "normal" behaviour when sharing information with business partners. Then you can define which type of corruption you want to cover because as usual you have to find the good mix between risk coverage and cost to do it.

     then after that if it is anormal behaviour, you can also imagine that email will be "anormal" with respect to other ones. I cant list here all this parameter as it is part of DLP policies for most of my customer but i think that for anormal behaviour you have to know the normal behaviour. you can contact me via MP or email to see if i can help you to go further.

     

     regards.



  • 3.  RE: Anti-Corruption Policy Creation

    Posted May 14, 2013 12:51 PM

    As you know there are more chances of false positive as people are not serious to use these words and they might be using in general but still there are chances that u will find something from this.



  • 4.  RE: Anti-Corruption Policy Creation

    Posted May 14, 2013 01:21 PM

    Thank you for the feedback.  I did not expect an easy solution.  We believe the key is to use the behavioral policy along with other correlated security logs to understand a profile.

    I thought some one may have some fresh ideas on the subject but I will continue to build off what we have started.