There always seems to be a considerable gap between policy development and execution.
This often stems from a delineation between the org that develops versus audits said policies.
Beyond administrative controls, many companies are now deploying security solutions (e.g., DLP, CASB, EMM/MDM, MAM, IAM/IDM, DMARC/SPF, ATP) w/ policy engines. To implement either admin and/or technical safeguards and not validate their utilization is a noticeable risk.
Showing posts with label DMARC. Show all posts
Showing posts with label DMARC. Show all posts
Tuesday, February 7, 2017
Vetting Security Policies
Tuesday, January 3, 2017
Why Enterprise DLP Solutions Will Go Away
Large, traditional, enterprise DLP deployments will go away as organizations look to leverage multiple, integrated DLP solutions. The reasons for this include:
With that said, the real question is what else will be migrated away from on premise?
- A focus on cloud & mobile solutions, & a migration away from on premise
- Consolidation of vendor solution capabilities (e.g., CASB, DLP, DCAP, RMS, DMARC, SPF)
- Portable / interoperable policies / rules (e.g., SCAP, CTP)
- A focus on agile deployments
- Cost / economies of scale
With that said, the real question is what else will be migrated away from on premise?
Labels:
CASB,
CTP,
DCAP,
DLP,
DMARC,
enterprise,
integrated,
RMS,
SCAP,
SPF
Tuesday, July 26, 2016
SPF, DMARC, or both?
Most orgs have email filtering in the way of sender policy framework (SPF: http://www.openspf.org/), though some seem to omit the use of domain-based message authentication reporting and conformance (DMARC: https://dmarc.org/).
While a belt and suspenders approach may not fit all budgets, in the wake of email-based malware, it may behoove orgs to use both...
While a belt and suspenders approach may not fit all budgets, in the wake of email-based malware, it may behoove orgs to use both...
Subscribe to:
Posts (Atom)