January 13, 2006

Guard your data against insider threats

Oakley, Reconnex, Tablus, and Vontu prevent costly data leaks

U.S. companies exposed the personal information of more than 53 million people in 2005, according to the Privacy Rights Clearinghouse. Alas, the possibility of serious consequences for leakers doesn't seem to deter insiders from divulging private, protected information -- and for good reason: Statistics clearly show enterprises are ill-prepared to thwart them.

For all their good work, many security professionals are still saddled with first- and second-generation ITM (insider threat management) products. Typically, these are limited to monitoring certain communications channels, such as e-mail and Web browsing.

Today's solutions, however, cover almost anything traveling over your network. Furthermore, they often sense data manipulation -- such as modification of files -- and track inappropriate use of media, including USB drives and CDs at the desktop. Other solutions monitor the equally important world of data-at-risk residing on unsecured file shares and intranets. Finally, when problems in any of these areas surface, products offer real-time alerts followed by automatic remediation.

Using these requirements as guideposts, I tested upgraded versions of two network scanning products that InfoWorld first reviewed last June, along with two new agent-based approaches.

The network gateways Reconnex iGuard 2.1 and Vontu 5.0 show maturity and polish. iGuard now offers better dashboard reporting that the user customizes, faster performance, and more tools for investigators. Traditionally strong in offering complete compliance policies and high accuracy, Vontu now scans data at rest; the company is also out front in addressing worldwide employee privacy standards.

Agent technology was just awakening six months ago. After a good ride in U.S. government agencies, Oakley Networks now offers its SureView technology to commercial customers. It may have a little ways to go concerning policy administration, but the agents do an admirable job stopping violations at the desktop.

Tablus is still working on its Content Alarm 3.0 release, due out later this year. The solution unifies both agent-based and network gateway technologies. After looking at an early beta, I believe Tablus may pose a serious threat to the competition because of its comprehensive and integrated approach. In the interim, the company also has released a minimal agent solution, Content Sentinel 1.0, which finds files with potential compliance problems on desktops and file shares. Two other familiar names in this space, Verdasys and Orchestria, declined to participate.

Oakley Networks SureView 3.3

You likely haven't heard much about Oakley Networks' insider protection technology until recently, but there's good reason: The company's been busy securing vital-mission data for hush-hush projects with the U.S. Department of Defense and other government entities. This experience gives Oakley a lot of credibility as a supplier of ITM solutions for commercial enterprises.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.