Personas workflow for DLP

The workflow outlines the responsibilities of the data security administrator and data security viewer in identifying and assessing data protection requirements, creating data-in-motion rules, investigating DLP-related issues, and protecting the organization's assets and data properties.

Data security administrator

The data security administrator views and manages all data security information, including objects and data patterns.

They are responsible for creating and managing data-in-motion rules and identifying and investigating DLP-type threats and attacks within an organization.

Steps:

  1. Configuring Endpoint DLP Settings: Configure the settings according to your organization's needs.
  2. Configuring sensitive data definitions: Identify and classify sensitive data (Data Profiles and Data Patterns).
  3. Configuring policies: Set rules to apply for sensitive data.
  4. Investigate: Review and analyze DLP-related issues to gather information to reduce false positives, refine policies, and improve incident response and auditing.
  5. Refine policies: Adjust DLP rules to improve accuracy, reduce false positives, and address new risks.

Data security viewer

The data security viewer reviews and analyzes DLP-related issues to gather information that will help reduce false positives, refine policies, and improve incident response and auditing.

Steps:

  1. Investigate and remediate: For true incidents, stop the data loss and investigate what happened and why.
  2. Document and report: Create a record of the incident for legal and compliance purposes.
  3. Communicate and educate: Speak to the user involved and update security training to prevent future issues.