DLP Endpoint for preventing data transfer via SD Card off the network
Created: 04 Dec 2012 | 7 comments
I'm using DLP 11.1 Endpoint prevent. I would like to know if DLP can prevent data transfer via SD card while the laptop is off the network. And what exactly are the configurations that needs to be done at the enforce server to prevent data transfer via SD card.
Discussion Filed Under:
Comments 7 Comments • Jump to latest comment
Yes, DLP Endpoint can monitor and block the sensitive data to be transfer to SD card, no matter the laptop is on the cooperation network or off the network.
Yang: Couple of days back I had an incident wherein data was transfered to SD and it was captured by the DLP, but it was not prevented. Whereas all my data transfer to pen drives are blocked. So is there any special configuration for preventing data transfer via SD card.
yes, You can do the same. But what exactly you wanted to achieve. You completely wanted to block any data transfer to SD card or only SD card Since you can do it by disable by endpoint Protection policy setting .
If you wanted to block only confidenhtail data than you should add class ID of that SD card devices. you should also take help of DLP application monitoring and control feature.
https://www-secure.symantec.com/connect/forums/dlp...
https://www-secure.symantec.com/connect/forums/usa...
In short the services which helps to copy any data tranfer throgh some device driveres for medium bluetooth, wifi,usb,SD card can be blocked.
I want to block all data transfer via SD card and give exceptions only to Senior Mgmt. So where can I find this option of "Endpoint Protection Policy setting" in DLP?
@ vstanley : Possibly, the data which was transferred to the SD card was protected under an IDM policy.
Endpoint Prevent cannot prevent the transfer of sensitive data under IDM Policy because it takes time for the DLP to match the sent data with the IDM Profile. However, the Admin or the concerned authorities will be notified with an Incident.
Off the networkd DLP agent work on DCM technology and u should either use Application Control or make responce rule based on DCM rule to block sensetive information transfer.
Would you like to reply?
Login or Register to post your comment.