This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is Data Control buggy?

Dear All,

Bit of background :- we are using Sophos 9.5 clients on XP and Windows 7 endpoints with SEC 4.5.x

I have implemented Data Control in Alert mode only across the firm.  So far I have some interesting results.  I have implemented just 4 rules, all UK, Bank Routing numbers, credit or debit, national id and PII.  We use Lotus Notes for email and am I right in thinking that Data Control simply monitors Windows Explorer transfers, thus we can send a plain text email breaching the rules, but Sophos will never pick it up?  It appears that way for me?  Attachments are scanned but plain text in an email is not?  is that right?

Also, on one OU I have implemented Data Control to Allow transfer on acceptance.  What I have found here makes no sense to me at all.  I create a blank Excel 2007 document and attaching that to an email breaches all rules and flags up a message box?  I create the same file but save it as a 2003 xls file and I am not prompted?  I have also added tons of attachments with all sorts of bank details and nothing is stopped, yet when I added a spreadsheet with a list of my servers it was flagged by the rules again!?

I have enabled verbose logging on my PC for data control but this adds nothing to normal logs, i.e. it does not drill down to the phrase that has breached the rule in the file, it simply records the file name of the document.

Please can anyone offer any advice as we are looking at creating a policy asap to combat DLP, but if the technology is failing its a no go-er.

Thanks in advance

Stuart

:5930


This thread was automatically locked due to age.
Parents
  • Hi Stuart,

    QC is correct about data control on the endpoint not currently scanning email content. It will scan attachments but not email content - in fact clarification of what is / isn't scanned can be found in the "Policy Setup Guide": http://www.sophos.com/sophos/docs/eng/manuals/sesc_95_psgeng.pdf.

    If you want to scan email content then I'd recommend considering the Email Security appliance which also includes integrated DLP and is a much more flexible solution for email DLP. If you don't want to invest in additional gateway hardware then the good news is that the email appliance will soon be available as a virtual image.

    Again QC is correct about verbose logging. For content rules it should show exact details for what content was matched for all files scanned by the DC rules - even when a file doesn't trigger. If this isn't happening then I'd recommend calling support and they can help fix the issue or raise a defect.

    The Excel 2003 / 2007 problem sounds interesting. In principal the behaviour should be consistent but the internal format for Excel 2003 and 2007 if quite different and so there are likely to be differences in the content extraction carried out by the engine. Having said this we'd aim for the results to be consistent. Again if you can contact support and provide files samples and verbose log output we can have a closer look at what is happening.

    Best regards,

    John

    :5959
Reply
  • Hi Stuart,

    QC is correct about data control on the endpoint not currently scanning email content. It will scan attachments but not email content - in fact clarification of what is / isn't scanned can be found in the "Policy Setup Guide": http://www.sophos.com/sophos/docs/eng/manuals/sesc_95_psgeng.pdf.

    If you want to scan email content then I'd recommend considering the Email Security appliance which also includes integrated DLP and is a much more flexible solution for email DLP. If you don't want to invest in additional gateway hardware then the good news is that the email appliance will soon be available as a virtual image.

    Again QC is correct about verbose logging. For content rules it should show exact details for what content was matched for all files scanned by the DC rules - even when a file doesn't trigger. If this isn't happening then I'd recommend calling support and they can help fix the issue or raise a defect.

    The Excel 2003 / 2007 problem sounds interesting. In principal the behaviour should be consistent but the internal format for Excel 2003 and 2007 if quite different and so there are likely to be differences in the content extraction carried out by the engine. Having said this we'd aim for the results to be consistent. Again if you can contact support and provide files samples and verbose log output we can have a closer look at what is happening.

    Best regards,

    John

    :5959
Children
No Data