Data Loss Prevention (DLP)
PII Data Detection and De-identification
Protecting sensitive data with data loss prevention
Data Loss Prevention (DLP) activities begin with profiling at-risk data, whether in motion or at rest. This is followed by protecting that data through the proper application of security features and protocols. Together, these activities form a powerful form of content-aware DLP.
Leading DLP solutions offer capabilities for scanning, filtering, highlighting, and monitoring (for protection enforcement) of at-risk data. The granular data discovery and de-identification technology in these products:
- IRI FieldShieldfor discovering and masking classified data in RDBs and flat files
- IRI CellShieldto do the same, but within and between Excel® spreadsheets
- IRI DarkShieldfor the same sources as above, plus semi- and unstructured sources
- IRI Voracityfor all of the above, as well as for the cleaning, integration, and processing of all this data
can work alone or in conjunction with a heat-mapping DLP or endpoint scanning solution to enable authorized users to, Create profiles Classify and search, to protect (mask or delete) and to prove (Risk assessment and audit), that they acted to prevent or at least minimize the loss of sensitive data nullify.
Classify, profile, and scan sensitive data sources through location- and content-based searching across multiple several sources simultaneously. Identify, isolate, and diagram and report on data across multiple tables, files, and other sources at the same time. IRI DarkShield's search and masking logs, and the dashboard charts you can create from them, yield heatmaps for ranked Data risks like these:
When data is in flat files or databases, IRI FieldShield can also protect it from misuse. Built-in data format (composite) template and range functions ensure content-aware identification and validation of column values. DarkShield uses the same data class definitions to locate and evaluate these values as well as data in semi-structured and unstructured data sources on-premises and in the cloud.
Select and apply integrated or custom Data masking functions for sensitive fields. Choose which function you want to apply as needed:
Security – how strong the encryption or other algorithm needs to be
Speed - what functions hide (and/or reveal) data faster
Reversibility – whether you need to re-identify the data later
Appearance – When the ciphertext must retain the original format
applying these functions ad hoc or in bulk (consistently across all sources) using Rules For example, use pattern matching expressions to automatically apply a format-preserving encryption key to specific tables while using a different key for other tables. This consistency in applying the data masking function maintains referential integrity.
Route output to the same source or a new destination. Enforce data- and role-based access controls that persist regardless of where the data resides later. This goes far beyond what other pure encryption or DLP solutions offer.
Verify that you have protected or de-identified the sensitive data by generating a statistical output and an audit trail. The job statistics show column names, input/protected/output row counts, and more.
The job specification script is self-documenting and easy to review in a text editor or in the GUI. It is also automatically integrated into a query-ready XML audit file. This log file also contains system information, e.g., who executed the job, when, and where.
Along with the sources and targets they identify, these records help validate the work you've done to comply with privacy laws.