Brian Contos
Senior Director & Customer Security Strategist Brian Contos, CISSP, is senior director of emerging ...
|
|
Simply put, information is valuable. From intellectual property and financial data to personal details and government secrets, internal and external attackers have been targeting sensitive information since well before the digital era. The difference today is that information has gone viral. It lives in the datacenter, laptop, removable storage device, mobile phone, and in the cloud.
Because not protecting information is not an option, information protection must be addressed by bringing together discovery, classification, enforcement, monitoring, forensic analysis, and encryption – to name just a few information protection solutions. McAfee has a number of solutions that can help address information protection. But instead of naming them all, we’ll just focus on a few that are absolutely essential to an effective strategy. They include data loss prevention (DLP), controls for removable storage, encryption, and database activity monitoring (DAM).
DLP can help discover and fingerprint sensitive data and work across networks and hosts to protect data from careless or intentional loss. Because of the popularity of removable storage devices such as USB drives and MP3 players, they make for an easy conduit to quickly lose gigabytes of information. Solutions need to be in place to enforce what types of devices can be used and the type of information that can be copied to them across physical, wireless, Bluetooth and infrared. By centralizing DLP and removable media controls, policy setting becomes more streamlined and consistent.
Encryption in many aspects such as full disk encryption, data encryption, and USB drive encryption is a fundamental and intuitive piece of information protection. Encryption is especially useful when a combination of file and folder level encryption can be utilized in an automatic and transparent mechanism thus limiting the value of the information should it be nefariously acquired.
Finally, DAM solutions bring greater security to structured data stores – i.e. databases. DAM solutions should be able to identify databases, assess their vulnerabilities, virtually patch those vulnerabilities, and provide attack prevention controls as well as session termination for incident response. The key to successful information protection is the more strategic integration of DAM with DLP, device control and encryption though a unified and centralized management console that allows discovery, policy setting, analysis, and response to be centralized.
Take a look at McAfee’s reference architecture for more information on how McAfee can help protect your information as well as other aspects of your environment with a cost effective and holistic security framework.
|
|
Tags: Information Protection, Security Connected Reference Architecture
Submit your own comments / message for this post