November 26, 2007

Data leakage prevention becomes a feature

Along with anti-spyware apps, spam filters, IDSes, and firewalls, DLP may go from stand-alone platform to become regular part of bigger packaged security suites

Driven by market consolidation and the ongoing efforts of large IT security vendors to meld DLP (data leakage prevention) tools into their broader portfolios, some experts contend that the technologies will increasingly become perceived as product features and less so as stand-alone platforms.

As with countless other security technologies that previously flourished as separate products but are now largely consumed as elements of packaged security suites -- including anti-spyware applications, spam-filtering tools, intrusion detection systems (IDS), and firewalls -- some market watchers claim that DLP is rapidly shifting into a mere piece of other offerings.

Over the last six months, a slew of independent DLP vendors have been acquired by large security providers, including Vontu, Tablus, Provilla, PortAuthority, and Oakley Networks.

Just as customer demand for DLP technologies -- considered valuable tools in stemming the theft and misplacement of sensitive corporate information -- drove Symantec, EMC, Trend Micro, WebSense, and Raytheon to buy those firms, respectively, the ubiquitous need for data protection among enterprises will drive further integration of the applications into other systems, according to some industry watchers.

"If you look at what DLP does, the real value will become more of a stack value than a vertical play," said Jon Oltsik, analyst with Enterprise Strategy Group. "A lot of devices can do packet filtering at the edge, and that filtering will become the enforcement of a policy, versus stand-alone data leakage prevention; the DLP system will still be where you might classify data, enter policies, and do analysis, but other products will likely take over the enforcement piece."

As Symantec had not yet announced details of its $350 million deal to buy Vontu when the market leader convened its second quarter earnings call on Oct. 23, Chief Executive John Thompson deferred questions about the impending acquisition in favor of highlighting DLP features that already resided in a number of the company's existing products, such as its database security programs.

While Symantec executives claim that the firm is planning to continue to sell Vontu's technology as a stand-alone platform for the foreseeable future, they also concede that one of the major benefits of adding the startup will be giant vendor's ability to further weave the acquired tools throughout a number of its other products.

"If you're going to have an agent on the end point, clearly you want all those capabilities to be integrated, and that includes DLP," said Ken Schneider, chief technology officer of Symantec's Security and Data Management group. "One of the things we're always trying to do is take disparate sets of technologies and build them into our architecture; we will continue to sell DLP as a stand-alone, but we will also introduce DLP capabilities throughout the portfolio."

As with many other security technologies, one of the hardest parts of effectively using DLP tools in the enterprise setting lies in customers' abilities to manage the systems, Schneider said.

Based on that reality, the degree to which Symantec can bond the technology with other security tools to allow for centralized management and policy control will play heavily into further adoption of DLP applications, according to the executive.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
dbsnaps 10-Jun-09 1:42am
checkout www.orbiumsoftware.com for database security tools

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.