Data Loss Prevention

 View Only

DLP Policy Implementation Approach 

Sep 29, 2011 07:04 AM

Policy Implementation approach

Certain DLP policies are likely to generate a huge extent of False Positives. The below described approach shall be helpful for Implementing such policies. This approach has been considered keeping three factors in mind:

  • Monitor
  • Validate
  • Implement

 

Define a policy for Monitoring

The Initially created policy may be leveraged for Monitoring purposes (eg. “<Policy name>-Monitor”). The incidents generated from this policy may be analyzed for identifying keyword sets of ‘False Positive’ and ‘False Negative’ keywords.

The identified keyword sets may then be added to the exception list of the “-Monitor” policy.

 

Validate the keyword sets

The keyword sets identified in the Monitor phase, may be leveraged for creating a Validation policy, (eg. “<Policy name>-Validate”), with two rules.

Example:

  • “<Policy name>-False Positive Keywords rule”
  • “<Policy name>-False Negative Keywords rule”

The Incidents generated from these rules may be analyzed for validating the keywords, ie:

  • “<Policy name>-False Positive Keywords rule” must generate False Positives
  • “<Policy name>-False Negative Keywords rule” must generate False Negatives

Note: The Validation policies may be deleted at a later stage along with its associated incidents.

 

Implement the Validated keyword sets

Once Validated, the ‘False Negative’ keyword sets may be leveraged as rules for creation of the Final policy (in Prevent mode).

The ‘False Positive’ keyword sets may be leveraged as exceptions, if required.

Statistics
0 Favorited
7 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Aug 16, 2017 12:36 PM

What are you seeing for incidents? Too much information, such as false-positives? Or, not enough information, such as, you see a detection not enough to qualify it?

 

Aug 16, 2017 03:58 AM

Hello,

Can i get some references for , how to fine tune already implemented policies ?

Feb 17, 2012 04:53 PM

This is just perfect. Awesome. Wise.

Well-established approach.

Oct 05, 2011 05:45 AM

 Thank for the breif explaination it would be great if you share your exp more about DLF

Related Entries and Links

No Related Resource entered.