Data Loss (or Leak) Prevention (DLP) – Damming the Estuary

For some time I have been seeking a metaphor for the well-nigh impossible task of protecting all the sensitive information in which organizations have been awash. And then I was invited to be on a panel at a recent “CSO Executive Seminar Series on Data Loss Prevention” event and so I tried extra hard to come up with something that would illustrate the dilemma with which information security professionals have been struggling.

  1. Rob Lewis Jan 20, 2009 at 8:39 am | Permalink

    A very insightful post. There is a problem with Mr. Amaroso’s thinking though. A patched and updated computer does not make it secure. Perhaps it removes the lowest hanging fruit, but reactive technologies such as we depend on today can’t defend against zero day attacks, so there would still be bot armies.

