bitglass webinar - dlp: content vs on-premises

16
STORYBOARD S DLP Cloud vs On- Premises Salim Hafid Product Marketing shafid@bitglass .com Rich Campagna VP, Products [email protected] om

Upload: bitglass

Post on 11-Apr-2017

277 views

Category:

Technology


5 download

TRANSCRIPT

Page 1: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

DLPCloud vs On-

PremisesSalim HafidProduct [email protected]

Rich CampagnaVP, [email protected]

Page 2: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Vote #1

Page 3: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

User wants access

Starbucks

Managed Device

Any Device...

Anywhere...

Unmanaged Device

CorporateNetwork

Page 4: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Enterprise wants security and control

Visibility and audit

Restrict data on unmanaged devices

Prevent hacked accounts

Prevent data leakage & control access

Page 5: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

First Approach: Secure the Infrastructure

Firewall DLP

Web Proxy

VPN

HQ & Branch Office

Starbucks

ApartmentVPN

MDM

Page 6: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Traditional Data Loss Prevention (DLP)

Limited to managed devices and applications only

Assumes trusted devices - DLP on Outbound/Send traffic only

Content analysis - keyword matches, regular expressions, etc

Doesn’t handle out-of-band access (external/public sharing, etc) typical with cloud apps

No visibility into encrypted traffic from public cloud applications

Performance concerns - WAN latency with cloud apps

Page 7: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Vote #2

Page 8: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

CASB Data Loss Prevention (DLP)

Support BYOD, public cloud apps in any access scenario• Ex: BYOD iPad from Starbucks accessing O365

Bidirectional scanning with contextual access control• Ex: Restrict credit card download to BYOD outside of US

Content analysis policies match/integrate via ICAP with Premises DLP

Control external sharing and API-based access to data• Ex: File shared publicly can be quarantined for analysis

Full decryption and analysis of cloud application data

Global, cloud-scale distributed infrastructure minimizes perf impact.

Page 9: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

CASB Cloud DLPInbound Policy

Data, User, Device, Location

Any Cloud App

Email, Files

Outbound PolicySharing, Sending, etc

Email, Files

● Contextual DLP

● Any device, zero footprint

● Real-time, proxy-accelerated API scans

Modify sharing permissions, Watermark, DRM, Redact, Encrypt

Page 10: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

● Reverse Proxy and ActiveSync○ Secure BYOD without agents

● Forward Proxy○ Enforce policies on managed

devices● API control

○ Watermark, DRM, Redact, Encrypt

How it worksComprehensive CASB Architecture

Page 11: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Typical Policy

Managed device

Application Access Access Control Data Protection

BYOD

In the Cloud

Forward ProxyActiveSync Proxy

Device Profile: Pass● Email● Browser● Thick clients

● Full Access

Reverse Proxy + AJAX VMActiveSync Proxy

● DLP/DRM/encryption ● Device controls

API Control External Sharing Blocked

● Block external shares● Alert on DLP events

Device Profile: Fail● Mobile Email● Browser

Page 12: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Policy

Page 13: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Bay Cove Human Services - Google Apps + HIPAA

2500 Employees

HIPAA Compliance with Google Apps and BYOD

● Secure Protected Health Information (PHI)● Remain HIPAA compliant with DLP, identity

management, mobile data protection

Page 14: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Ad Agency - O365 OneDrive

Protect unreleased creative files in OneDrive

● Visibility and control● Limit access from unmanaged devices; project team

members only● Prevent data leakage

200 EmployeesGlobal clients

Page 15: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

Resources

1. Definitive Guide to Cloud Access Security Brokers http://pages.bitglass.com/definitive-guide-to-cloud-access-security-brokers.html

2. Bitglass Case Studies http://www.bitglass.com/resources#case_studies=1

3. Glass Class - Traditional DLP Limitations https://www.youtube.com/watch?v=ZXKvoqQCdNs

Page 16: Bitglass Webinar - DLP: Content vs On-Premises

STORYBOARDS

DLPCloud vs On-

PremisesSalim HafidProduct [email protected]

Rich CampagnaVP, [email protected]