A layered approach to data protection What do we mean by data protection?

A layered approach to data protectioncompliance should provide control over applications
What do we mean by data protection?(e.g., instant messaging, P2P file sharing), removable
Data protection is an umbrella term for technologies,storage devices (e.g., USB keys), and corporate
tools, and best practices related to protecting sensitivesystems (e.g., web browsing and email). Controlling the
data within organizations. An effective data protectionway in which these are used means that employees
strategy is one that balances protection withcan be given the tools they need to do their job
productivity — ensuring that all sensitive andwithout putting data at risk.
confidential data is secure without preventing usersData Loss Prevention: DLP provides automated
from going about their daily business tasks.oversight and monitors data movement to prevent
For a strategy to be successful, the technologies needusers from accidentally exposing sensitive information
to be implemented in a timely fashion while beingvia removable storage devices or internet applications.
affordable, easy to deploy and simple to administer.Content control lists (CCL’s) are a critical element
The ideal solution to the problem of data protection isof DLP, defining data types that need to be protected
therefore one that integrates key technologies withsuch as personally identifiable information (PII) or
best practices and pre-packaged intelligence to makefinancial data including credit card numbers and bank
effective policies out of the box — helping you getaccounts.
started faster.The ideal solution should provide pre-packaged
Effective data protection = Technology that embodiesCCL’s to make deployment and configuration quick
best practices + Pre-packaged intelligenceand painless while also integrating tightly with policy
A comprehensive data protection strategy shouldcompliance and other components of the data
cover the following four key areas:protection strategy — all while providing a seamless
Threat Protection: Threat protection should protectexperience for users that minimizes impact on
data against infection from malware and preventproductivity.
hackers from gaining direct or indirect access toEncryption: Encryption is essential for protecting the
sensitive data on your systems and network. Thusconfidentiality, integrity, and authenticity of data at rest
threat protection must include: intrusion prevention,or on the move and is a key requirement for many
firewall, anti-virus, anti-malware, and anti-spam toregulations. It should secure data on desktops and
ensure hackers do not gain a foot-hold on yourservers, mobile devices including laptops and
network with which to compromise and steal sensitiveremovable storage media, as well as data that is
data. Since threats are constantly evolving andallowed to be sent via email. The ideal solution is one
becoming more financially driven, proactive protectionthat is both transparent to the end user to avoid
that can identify and block new threats before theyproductivity and workflow disruptions, while also being
are cataloged is critical.easy to deploy and manage with flexible policies that
Policy Compliance: The role of policy compliance is toadapt to your business. Furthermore, a solution that
reduce the threat landscape, legal liability and exposureintegrates encryption with DLP provides a significant
by implementing best practices in the form of policy toadvantage in ensuring any sensitive data that is
prevent users from inadvertently putting themselves orallowed to be moved off the network for valid
the organization at risk while still giving them the toolsbusiness reasons cannot be compromised.
they need to go about their daily work. Policy