The public is growing impatient with data leaks, as we can see from stricter laws, fallout surrounding reputational damage, and law suits. This new focus makes information security a 'bottom-line' business requirement. When 40% of reported data breaches are caused by human error, we must expand our attention to include the business processes supported by information technology.
Data Leakage Prevention in Depth provides professionals with time-tested methodologies for detecting data leakage risks and identifying safeguards. When students return to work they will be able to address their organization's requirements for protecting confidential information, create a data leakage prevention team, conduct an information risk assessment, analyze possible weaknesses in technical systems, and recommend effective approaches for safeguarding systems and processes.
During class we will go in depth into technical subjects to discuss how confidential information gets into the wrong hands. For example, a good security design is pertinent to the storage of critical information in databases, Web applications, e-mail, cloud computing, VPNs, and many other technologies. The course will demystify encryption, text pattern matching, outsourcing, cloud computing, and social networking as they relate to DLP. Moreover, other relevant issues include the fact that outsiders, including the general public and hackers, can also access confidential information through low-tech means, like paper, social engineering, physical access, and portable storage media. The course will teach you about the data leakage risks in all of these areas and more and will demonstrate safeguards with hands-on exercises.
This course provides a comprehensive discussion of DLP requirements and provides techniques for students to determine and evaluate their organization's DLP risks. The material presents both technical and management subject matter and is designed for technical professionals who are responsible for protecting the confidential information within their organization.
Please Note: While the course provides information about legal obligations for protecting confidential information, it is not offered as legal advice or as a comprehensive educational program around your or your organization's legal obligations. For more information in these areas, please consider taking one of the SANS legal courses.
Author Statement
Many companies are fighting the battle against data leakage. This course will provide an overview of the landscape and a plan of action in making it better. The first day covers the core methodology, and then the rest of the course will deep-dive into the components, highlighting what questions to ask and options to protect yourself.
- Megan Restuccia and Chris Cronin