I can't help but notice that amongst the Information Security professionals I've talked to lately at various conferences and venues across the country there is a very serious push to return to basics. There is a backlash against vendors selling an appliance of a quick fix to point-in-time problem. The glut of blinking lights, and devices that require time and effort to manage has gotten out of control ...or so I'm being told. I've not manged an Information Security team in 4 years now (my how time flies!) but even back when I managed the glut of boxes, products and solutions was becoming too much to bear. I can only imagine it now.
So, first let me start off by saying that I'm with you. I understand the over-dependence on solutions sold by vendors who aren't really thinking of your enterprise long-term, past their point of sale. Let's look at how Data Loss Prevention (DLP) can be addressed without having to put in a $1M solution...
Before I get to that though ... I do completely acknowledge that there are some organizations which cannot even identify where their data is, much less do much about it's loss without adding more complexity and hardware/software to the portfolio ...that's OK because at least you have a real reason to add...
7 Practical Ways to Reduce Data Leakage (Aid Data Loss Prevention (DLP) )
Now that I've written this, I just realized that each of these 7 points will probably require its own blog post over the next few weeks ...if you feel strongly about one of these posts, please leave me a comment or note ... or hit me on Twitter and we can talk about it. I welcome contributions and ideas!