How can we create a "combination of boxing" to prevent information leakage "?

Source: Internet
Author: User

Information Leakage Prevention is an overall solution that includes encryption, management, auditing, monitoring, and other aspects. Information Leakage Prevention requires "Combination boxing ". However, whether it is encryption, management, audit or monitoring, there are single-function products on the market. In this regard, are enterprises buying multiple single-function products combined into an information leakage prevention system, or are they using an integrated information leakage prevention integration solution provided by a manufacturer? To this end, vendors, enterprises, and experts gathered to discuss how to defend against information leakage ".

Make a good combination of boxing. First, you need to make sure that each boxing in the combination is pretty. To select the overall solution, each module must have its own strengths and functions. This requires good cooperation between modules. Products of different manufacturers may have different product concepts and technical systems, and there may be compatibility issues between them. blindly selecting the best products in different fields may lead to a situation of independent governance, ignore this. In addition, there may also be duplicate functions between a single product, which will undoubtedly result in a waste of capital. Therefore, "even if you choose the product A of the best Vendor A and the product B Combination of the best Vendor B, the best results may not be created. "Said Huang Kai, product director of Yixin technology.

Second, you need to manage the "Combination boxing" in real time to make the attack accurate. The overall solution involves many functional modules and management is a challenge. Dr. Huang Pei, an informatization expert in the manufacturing industry, said: "If one or more products have a management platform, or some of them have a management platform, vulnerabilities may occur due to inconsistent management. The integrated solution has a unified management console, and can coordinate the best cooperation between different functional modules to ensure the use effect. "Obviously, the combined solution does not provide a unified management platform.

Starting from the above two points, Yi Feng, Information Director of Qingdao CIMC refrigerator Manufacturing Co., Ltd., and Zhou qingxiang, CIO of Zhengzhou sanquan Food Co., Ltd., have selected an integrated information leakage prevention solution. With the integration solution selected, there may be fewer compatibility issues, more smooth coordination between different modules, and convenient management and use. Therefore, it can achieve better results theoretically. For various reasons, Hangzhou Steam Turbine Co., Ltd. can only use a single function product to build a platform. Director Huang Liang has a deep understanding of the inconvenience. When using this solution, technical development requires repeated tests on the performance and compatibility of multiple products. Employees need to install a large number of clients, and each product needs to be logged in separately, both management and user experience have an impact. Relatively speaking, the overall solution is easy to manage and requires few plug-ins and client programs to be installed, which can minimize the impact on the performance of the client. "Although one of the overall solutions may not have the best performance, the overall performance must be good as long as it is sufficient and useful. "He said with deep feelings.

Of course, although the integration solution is good, the integration solution does not exist in the beginning. Many enterprises also have their own "DIY" integration solutions. To some extent, because of the existence of such cases, enterprises will choose whether to combine a single product into an overall solution or an integrated solution. The success of the combined solution is actually based on the "thick foundation" of the enterprise. This requires the enterprise's own excellent architecture, proper management, and rich IT personnel as the precondition. Dr. Li Yang, an information security expert, said that some enterprises are equipped with a lot of manpower to carefully select, purchase, and deploy various products, and collect the strengths of each product, or even secondary development, then the most suitable enterprise solution is formed. Tan Junfeng, Information Manager of the General Research Institute of Sany Heavy Industry Co., Ltd. with rich informatization experience, proves that for some enterprises with good infrastructure, third-party integration, and sufficient IT manpower, A single-choice product can sometimes achieve the effect of selecting a vendor's integrated solution.

From this point of view, for systems that do not have enough manpower and capabilities to integrate, the integrated solution can help them quickly build a security system than the combined solution. Enterprises with enough manpower and capabilities can also use DIY. However, these combinations that can meet enterprises' needs for DIY are not necessarily long-term solutions. As the enterprise is developing, its architecture may be upgraded, its staff may increase, and its business may change, Huang Kai, product director of Yixin technology, reminded enterprises to pay attention to application scalability during application, that is, whether the deployed products can be easily expanded as the business needs or scale expand in the future. In general, the integrated solution has a complete product architecture. Compared with the combined solution, the integrated solution can provide users with a forward-looking view of future applications. The integrated solution of Yixin Technology IP-guard Information Leakage Prevention is used as an example, it provides 15 function modules covering all applications with Intranet security. It can enable and use functions as needed, disable unused functions, and extend the functions available at any time.

In short, information leakage prevention is a concept and a system. To implement information leakage prevention, we need to consider many aspects. Because of the wide variety of Enterprise situations, it is a complicated task. Looking at everyone's point of view, according to the current situation of most enterprises, selecting an integrated information leakage prevention solution is more helpful to launching a powerful and brilliant Information Leakage Prevention "Combination boxing ". The reason is as follows:

1. If a single product is used for combination, there may be a situation of "headache and headache.

2. A vulnerability may occur if one product is missing or the combination of items is insufficient. The integrated solution is based on the overall demand of information leakage prevention. The problem is generally more comprehensive and the solution is more rigorous.

3. Even if a single product is combined with comprehensive functions, the solution can produce 1 + 1> 2 results due to different product concepts and different technical systems, and may be counterproductive. On the contrary, the integrated solution is in the same line in product design, with better coordination degree and best effect.

4. The integrated solution has a unified management platform. In terms of management, maintenance, and user experience, the integrated solution also has advantages.

5. The integrated platform architecture can be upgraded based on the enterprise's extended applications without any need to be added.

To sum up these five points, we need to make a good combination of boxing techniques to prevent information leakage. The functions are incomplete, and the functions are overlapping. According to these points, enterprises also need to pay attention to themselves when selecting information leakage prevention solutions. Zhu xiaozhe, manager of the Information Department of Wuhan fangu Electronic Technology Co., Ltd., reminded the company to make full investigation, compare and test, and select the best product within the scope of its own discriminant ability. "In addition, the background of China's security market is worth the attention of enterprises in terms of selection. After several years of development, the security market in China has not yet formed a unified standard. It is a situation of great competition. If there is no standard, the product will be uneven. Because of this, Zhang baichuan, webmaster of the ranger security network, recommends that you strictly examine the comprehensiveness of the integrated solution provided by the vendor, because "not every vendor has the ability to provide integrated solutions. "

Behavior auditing is an important part of "Combination boxing ". However, there has always been a debate on "Whether behavior auditing infringes on personal privacy". How to Use the audit function is also a topic of great concern to enterprises and vendors. Please pay attention to "Intranet Security" ten years of "debate" Series 6: Information Leakage Prevention, how to make good use of behavior auditing?

  1. Intranet security: 10 years of debate
  2. Intranet security, where is the heart?
  3. Intranet security, he Ma is the first?
  4. Intranet security: "spending money" OR "earning money "?

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.