By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    stress disorder
    5 Ways To Manage Post-Traumatic Stress Disorder
    October 27, 2021
    Medical device classification and development strategies
    Medical device classification and development strategies
    January 19, 2022
    varicose veins
    Varicose Veins Prevention: 3 Lifestyle Changes to Make Right Now
    May 1, 2022
    Latest News
    6 Essential Strategies for Improving Your Medical Practice
    January 25, 2023
    Staying Positive While Living with Mesothelioma
    January 24, 2023
    The Many Health Benefits of Being Outdoors
    January 17, 2023
    How to Assess a Safe Placement of a Nasogastric or Nasoenteric Tube and Its Complications
    January 19, 2023
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    9 Great Resources For Your Medical Assistant Training
    August 16, 2018
    Waiting for HIPAA Clarity? Who Has Time?
    September 19, 2014
    Topics You Need To Study And Prepare For When Taking The NCLEX
    August 12, 2020
    Latest News
    Simplifying the Genetic Testing Process: How At-Home Kits are Changing the Game
    January 25, 2023
    9 Hospitals That Have Introduced Green Initiatives
    January 25, 2023
    Why a Health Retreat Can Be the Best Medicine
    January 12, 2023
    Best Money-Saving Tips for Health Managers
    January 12, 2023
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Dealing with DLP and privacy
Share
Sign In
Notification Show More
Latest News
ABA therapist
Everything You Need to Know About Applied Behavior Analysis
Health
Small Lifestyle Changes That Can Have A Big Impact On Your Well-Being
lifestyle Wellness
The Future Of Medicine: How Immunotherapy Is Saving Lives
The Future Of Medicine: How Immunotherapy Is Saving Lives
Technology
medical practice and technology advancement
6 Essential Strategies for Improving Your Medical Practice
Technology
digital dental x-ray
How Does A Digital Dental X-Ray Work?
Dental health
Aa
Health Works CollectiveHealth Works Collective
Aa
Search
Have an existing account? Sign In
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Technology > Dealing with DLP and privacy
Technology

Dealing with DLP and privacy

Danny Lieberman
Last updated: 2015/08/16 at 2:57 PM
Danny Lieberman
Share
8 Min Read
SHARE

Dealing with DLP and privacy

It’s a long hot summer here in the Middle East and with 2/3 of  the office out on vacation, you have some time to reflect on data security. Or on the humidity.  Or on a cold beer.

Contents
Dealing with DLP and privacyDealing with DLP and privacyWhat is DLP and what are the privacy concerns?DLP rules and policies are content-centric not user-centric.Making your data governance policy work for your employeesIn summary:

Dealing with DLP and privacy

It’s a long hot summer here in the Middle East and with 2/3 of  the office out on vacation, you have some time to reflect on data security. Or on the humidity.  Or on a cold beer.

Maybe you are working on building a business case for DLP technology like Websense or Symantec or Verdasys, or Mcafee or Fidelis in your organization.  Or maybe you  already purchased DLP technology and you’re embroiled in turf wars that have put your DLP implementation at a standstill as one of your colleagues is claiming that there are employee privacy issues with DLP and you’re trying to figure out how to get the project back on track after people get back from their work and play vacations in Estonia and brushing up on their hacking skills.

Unlike firewall/IPS, DLP is content-centric. It is technology that drives straight to the core of business asset protection and business process.  This frequently generates opposition from people who own business assets and manage business process. They may have legitimate concerns regarding the cost-effectiveness of DLP as a data security countermeasure.

More Read

AI helps healthcare providers with record keeping through the use of medical code extraction

Medical Code Extraction Using Artificial Intelligence

Maximizing Outcomes Through Effective Patient Engagement Strategies
Telemedicine App Development Cost & Key Features
Robotic Technologies Can Improve Hospital Working Conditions
Materials and Techniques for Taking Dental Impressions

But – people who oppose DLP on grounds of potential employee privacy violations might be selling sturm and drang to further a political agenda.   If you’re not sure about this – ask them what they’ve done recently to prevent cyber-stalking and sexual harassment in the workplace. 

For sure, there are countries such as France and Germany where any network or endpoint monitoring that touches employees is verboten or interdit as the case may be; but if you are in Israel, the US or the UK, you will want to read on.

What is DLP and what are the privacy concerns?

DLP (data loss prevention) is a solution for monitoring/preventing sensitive outbound content not activity at an endpoint. This is the primary mission. DLP is often a misnomer, as DLP is more often than not, DLD – data loss detection but whatever…Network DLP solutions intercept content from the network and endpoint DLP agents intercept content by hooking into Windows operating system events.  Most of the DLP vendors offer an integrated network DLP and endpoint DLP solution in order to control removable devices in addition to content leaving network egress points. A central command console analyzes the intercepted content and generates security events, visualizes them and stores forensics as part of generating actionable intelligence. Data that is not part of the DLP forensics package is discarded.

In other words, DLP is not about reading your employees email on their PC.  It’s about keeping the good stuff inside the company.    If you want to mount surveillance on your users, you have plenty of other (far cheaper) options like browser history capturer or key loggers. Your mileage will vary and this blog does not provide legal guidance but technically – it’s not a problem.

DLP rules and policies are content-centric not user-centric.

A DLP implementation will involve writing custom content signatures (for example to detect top-secret projects by keyword, IP or source code) or selecting canned content signatures from a library (for example credit cards). 

The signatures are then combined into a policy which maps to the company’s data governance policy – for example “Protect top-secret documents from leaking to the competition”. 

One often combines server endpoints and Web services to make a more specific policy like “Alert if top-secret documents from Sharepoint servers are not sent via encrypted channels to authorized server destinations“. 

In 13 DLP installations in 3 countries, I never saw a policy that targeted a specific user endpoint. The reason for this is that it is far easier using DLP content detection to pickup endpoint violations then to white list and black list endpoints which in a large organization with lots of wireless and mobile devices is an exercise in futility.  

We often hear privacy concerns from people who come from the traditional firewall/IPS world but the firewall/IPS paradigm breaks when you have a lot of rules and endpoint IP addresses and that is why none of the firewall vendors like Checkpoint ever succeeded in selling the internal firewall concept. 

Since DLP is part of the company data governance enforcement, it is commonly used as a tool to reinforce policy such as not posting company assets to Facebook. 

It is important to emphasize again, that DLP is an alert generation and management technology not a general purpose network traffic recording tool – which you can do for free using a Netoptics tap and  Wireshark.

 Any content interception technology can be abused when in the wrong hands or in the right hands and wrong mission.  Witness NSA. 

Making your data governance policy work for your employees

Many companies, (Israeli companies in particular) don’t have a data governance policy but if they do, it should cover the entire space of protecting employees in the workplace from cyber-threats.

An example of using DLP to protect employees are the threat scenarios of cyber-stalking, sexual harassment or drug trafficking in the workplace where DLP can be used to quickly (as in real-time) create very specific content rules and then refined to include specific endpoints to catch forensics and offenders in real-time. Just like inCSI New York New York.

In summary:

There are 3 key use cases for DLP in the context of privacy:

  1. Privacy compliance (for example PCI, HIPAA, US State and EU privacy laws) can be a trigger for installing DLP. This requires appropriate content rules that key to identifying PHI or PII.
  2. Enforcement of your corporate  data governance and compliance policies where privacy is an ancillary concern.   This requires appropriate content rules for IP, suppliers and sensitive projects. So long as you do not target endpoints in your DLP rules, you will be generating security events and collecting forensics that do not infringe on employee privacy.   In some countries like France and Germany this may still be an issue.  Ask your lawyer.
  3. Employee workplace protection – DLP can be an outstanding tool for mitigating and investigating cyber threats in the workplace and at the very least a great tool for security awareness and education. Ask your lawyer.

If you liked this or better yet hated it,  contact  me.  I am a professional security analyst specializing in HIPAA compliance and medical device security and I’m based in Israel and always looking for interesting and challenging projects.

Idea for the post prompted by Ariel Evans.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Danny Lieberman August 16, 2015
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article BHM Healthcare Solutions | Independent Review Organization 5 Signs That It Is Time to Reevaluate Your Independent Review Organization
Next Article Who Deserves Quality Medical Care?

Stay Connected

1.5k Followers Like
4.5k Followers Follow
2.8k Followers Pin
136k Subscribers Subscribe

Latest News

ABA therapist
Everything You Need to Know About Applied Behavior Analysis
Health January 26, 2023
Small Lifestyle Changes That Can Have A Big Impact On Your Well-Being
lifestyle Wellness January 26, 2023
The Future Of Medicine: How Immunotherapy Is Saving Lives
The Future Of Medicine: How Immunotherapy Is Saving Lives
Technology January 26, 2023
medical practice and technology advancement
6 Essential Strategies for Improving Your Medical Practice
Technology January 25, 2023

You Might also Like

The Future Of Medicine: How Immunotherapy Is Saving Lives
Technology

The Future Of Medicine: How Immunotherapy Is Saving Lives

January 26, 2023
medical practice and technology advancement
Technology

6 Essential Strategies for Improving Your Medical Practice

January 25, 2023
patient tracking systems for medical staff and innovation
Medical InnovationsTechnology

Patient Tracking Systems: Improving Facilities for Patients and Medical Staff

January 2, 2023
telemedicine business feature benefits
TechnologyTelemedicine

Building Telemedicine System: Features and Tips

December 28, 2022
Follow US

© 2008-2023 HealthWorks Collective. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?