This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Data Control Policy - security hole?

I have created a new data control policy where destination is optical or removal storage, allow transfer and log event and for any of the default files. The policy works to a degree however there are some interesting results.

I have two excel doc's, now if I open doc A and file save as to the removable media nothing gets logged nor do I receive a triggered email? on the client this doesn't even register that an event had taken place? and in the sec console nothing?

If I drag & drop doc B to the removable storage bingo, events are logged both on the client and sec console and I receive my triggered email.

I have sent Sophos all the information, diag logs and even the XML policy however  still no joy?

:23167


This thread was automatically locked due to age.
Parents
  • Hey Christian,

    So DLP ultimately is useless as 50% at a guess save their documents from said menu to the removable media, this not getting logged leaves and enormous holes in ones security.

    I understand the complexities of it however very misleading  DLP well sort of :)

    :23193
Reply
  • Hey Christian,

    So DLP ultimately is useless as 50% at a guess save their documents from said menu to the removable media, this not getting logged leaves and enormous holes in ones security.

    I understand the complexities of it however very misleading  DLP well sort of :)

    :23193
Children
No Data