EdgeWave Authorized ProPartnerEdgeWave Data Loss Protection

Content analysis and policy engine that uses proprietary technology

EdgeWave Data Loss ProtectionThe EdgeWave Messaging Security Suite includes a content analysis and policy engine that uses proprietary technology to protect private information transmitted via outgoing email. This data protection technology analyzes information being sent out of your network, to detect private content in data in motion and prevent sensitive and confidential data from leaving your network. EdgeWave DLP gives you the powerful tools you need to comply with government regulations, such as HIPAA and GLBA, and prevents the outbound communication of all types of private or objectionable data, including:

Overview:

Our DLP feature gives you the powerful tools you need to comply with government regulations and prevent the loss of sensitive private data.

EdgeWave Email Security includes a content analysis and policy engine that uses proprietary technology to protect private information transmitted via outgoing email. As part of EdgeWave's Secure Content Management portfolio, this data protection technology analyzes data being sent out of your network to detect private content in data in motion and prevent sensitive and protected data from leaving your network. EdgeWave DLP gives you the powerful tools you need to comply with government regulations, such as HIPAA and GLBA, and prevents the loss of all types of private data, including, patient healthcare information, financial information and social security and credit card numbers.

Data Compliance

Easy Deployment

EdgeWave DLP is easily managed from the central dashboard and can be provisioned within hours to start protecting your organization. With technology that delivers unrivalled accuracy while assuring low latency, you can add a layer of protection to your security strategy without adversely affecting the delivery of your legitimate email.

Proprietary Technology

The DLP feature can be enabled in the EdgeWave Email Security solution whether you are using the hosted solution or have an EdgeWave appliance installed at the edge of your network to monitor all outbound SMTP traffic. Our built-in content analysis detects and prevents critical private data from being sent out of your network, allowing you to comply with regulatory legislation and defend against email-borne threats.

Features:

Proprietary Algorithms, Pattern Matching Technology
This DLP Service can be enabled in the EdgeWave Email Security solution whether you are using the hosted solution or have an appliance installed at the edge of your network to monitor all outbound SMTP traffic. In this configuration, EdgeWave DLP can perform the following:

  • Initial Detection: DLP analyzes the content of data in motion to identify any sensitive data, such as private health or financial information, leaving the network.
  • Define & Enforce: You can specify what action to take when a content analysis violation is found: deliver to recipient, hold in quarantine for review, or block.
  • Content Analysis: Performs deep packet inspection in data and files being transferred on your network to analyze the content of reassembled network packets and identify private information that may be leaving your network. Content analysis is performed across numerous file types.

EdgeWave built-in content analysis helps you comply with regulatory legislation and defend against: Exposure of personal healthcare information

  • Capture of financial information
  • Credit Card Matching
  • Social Security Number Matching

Benefits

  • Easy To Deploy
  • Unprecedented Accuracy – Lexicons and logic engine allows precise deterministic analysis
  • Low Latency – Proprietary technology rapidly analyzes and detects data triggering compliance enforcement

Implementation Is Easy
Just route your SMTP email to the EdgeWave Email Security solution and configure the policies for DLP. The EdgeWave solution then analyzes the email leaving your organization for violations of any content analysis types that are enabled. You can also specify what action to take when a content analysis violation is found: hold in quarantine until further review or block. You may define rules that apply to all users or only to specified sender email addresses or content analysis types.

Credit Card Matching
Major credit card companies use standard numbering sequences that are unique to each brand of card, such as Visa, MasterCard, or Discover. EdgeWave DLP catches any credit card numbers that might be leaving your organization with matching technology that recognizes the identifiable patterns of numbers all major credit card companies use. In addition, we employ the LUHN algorithm to validate the number, which virtually eliminates the possibility that messages will be incorrectly identified as policy violations.

Social Security Numbers
EdgeWave DLP has a built-in extended regular expression that identifies U. S. Social Security numbers contained in data and files being transferred from your network. With identity theft still a critical, global problem, keeping this information from leaving your organization is vitally important.

File Types Analyzed
In addition to the features mentioned, EdgeWave DLP analyzes many other types of files for private content.

Personal Healthcare and Financial Information
A lexicon is an xml file that contains a list of specialized vocabulary and phrases unique to a specific subject. EdgeWave DLP includes built-in lexicons for the financial and healthcare industries that prevent accidental or malicious exposure of personal health or financial information – a critical factor in complying with regulatory requirements. Our solution uses these and other lexicons to examine the contents of data and files, identifying specific words and phrases unique to the financial and healthcare industries. This feature also requires a match on information that would identify the person, helping prevent false positives. For example, if the phrase "broken tibia" is matched, information that would identify the person involved must also be matched, such as "client John Doe" or "patient number 0123456".

Personal health information (PHI) is protected by the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule enacted in 1996. Protection of personal financial information is required by the Gramm-Leach-Bliley Act (GLBA) enacted by the U.S. Congress in 1999.

Objectionable Content
The DLP Service can be configured to filter out profanity using a common American English profanity lexicon.

File Types:

EdgeWave Email Data Compliance analyzes many other types of files for private content. The following table lists the file types that are analyzed. Metadata, text, and character sets are extracted for all types, except those marked with an asterisk (*). For these file types, only metadata (title, subject, author, etc.) is extracted.

Format/Version/Extension

Archive Formats
PKZIP ZIP
WinZip ZIP
LZA Self-ExtractingCompress
LZH Compress
Microsoft Office Binder 95-97
RAR 1.5-2.9
Self-extracting .exe
UNIX Compress, Gzip, tar
Uuencode
Vector Image
Adobe Illustrator* through 7, 9, 11-13
Adobe InDesign* 3.0-5.0
Adobe InDesign Interchange*
Adobe PDF 1.0-1.6 (Acrobat 1-7)
Adobe PhotoShop* 4, 8.0-10.0
AMI Draw SDW
AutoCAD Drawing 2.5, 2.6, 9.0-14.0, 2000i, 2002,
    2004-2007
DWG
AutoShade Rendering 2.0
Corel Draw 2.0-9.0
Corel Draw Clipart 5.0, 7.0
Enhanced Metafile EMF
Escher graphics
Framemaker Vector and Raster
Graphics through 5.0 FMV
Gem File
Harvard Graphics Chart for DOS 2.0-3.0
Harvard Graphics for Windows
HP Graphics Language 2.0
IGES Drawing 5.1-5.3
Micrografx Designer 6
Micrografx Drawing products through 3.1
Novell PerfectWorks Draw 2.0
OpenOffice Draw 1.1, 2.0
OS/2 PM Metafile 3.0
Microsoft Visio 5, 2000, 2002, 2003 VSD
Microsoft Visio (Page preview mode only.)
WMF/EMF 4
Windows Metafile
Database Formats
DataEase 4.x
DBase III, IV, V
First Choice DB through 3.0
Framework WP 3.0
Microsoft Access 1.0, 2.0 MDB
Microsoft Works DB for DOS 2.0
Microsoft Works DB for Macintosh 2.0
Microsoft Works DB for Windows 3.0, 4.0
Microsoft Works WP for DOS 1.0
Paradox 2.0-4.0
Paradox for Windows through 1.0
Q&A Database through 2.0
R:Base 5000, System 5
Reflex 2.0
SmartWare II DB 1.02
Raster Image
CALS Raster (GP4) Type I, II
Computer Graphics Metafile ANSI, CALS NIST 3.0
Encapsulated Postscript/TIFF (header only)
EPS
GEM Image (Bitmap)
Graphics Interchange Format GIF
IBM Graphics Data Format 1.0 GDF
IMB Picture Interchange Format 1.0
JBIG2 Graphic Embeddings in PDF
JFIF (JPEG not in TIFF format)
JPEG JPG
JPEG 2000 JP2 JPG
Kodak Flash Pix
Kodak Photo CD 1.0
Lotus Pic PIC
Lotus Snapshot
Macintosh PICT, PICT2 BMP only PCT
MacPaint MAC
Microsoft Windows Bitmap
Microsoft Windows Cursor
Microsoft Windows Icon
OS/2 Bitmap BMP
OS/2 Warp Bitmap
Paint Shop Pro (Win32 only) 5.0, 6.0
PC Paintbrush PCX
PC Paintbrush DCX
Portable Bitmap PBM
Portable Graymap PGM
Portable Network Graphics PNG
Portable Pixmap PPM
Progressive JPEG JPG
StarOffice Draw 6.x-8.0
Sun Raster RAS
TIFF Group 5, 6 TIF
TIFF CCITT Fax Group 3, 4
TIFF CCITT Group 3 & 4 through 6
TruVision TGA (Targa) 2.0 TGA
WBMP wireless graphics format
Word Perfect Graphics 1.0. 2.0, 7.0-10.0 WPG
X-Windows Bitmap x10 compatible
X-Windows Dump x10 compatible
X-Windows Pixmap x10 compatible
Email
Encoded Mail Messages MHT, Multi-Part
Alternative, Multi
Part Digest, Multi-Part Mixed, Multi- Part News Group, TNEF
Microsoft Outlook MSG
Microsoft Outlook Express EML
Microsoft Outlook Forms Template OFT
Microsoft Outlook OST OST
Microsoft Outlook PST 97, 98, 2000, 2001 Mac,
    2002, 2003
Flash (text only) 6.x, 7.x, Lite
Microsoft Project (text only) 98, 2000, 2002, 2003
Microsoft Windows DLL
Microsoft Windows Executable
Microsoft XPS (file ID only)
MPEG-1 Audio layer 3* ID3 versions 1 and 2
MP3
MP3*
MPEG-2 Audio
MPEG-1 Video V2, V3
QuickTime (file ID only)
RealMedia (file ID only)
vCalendar 2.1
vCard 2.1
Windows Media Advanced Systems
Format
ASF
Windows Media Digital Video
Recording
DVR
Windows Media Audio WMA
Windows Media Video WMV
Wireless Markup Language
Yahoo Messenger 6.x-8.0
Presentation Formats
Corel Presentations 6-12, X3 SHW
Harvard Graphics Presentation DOS 3.0
Lotus Freelance 1.0, 2.0, SmartSuite Millennium,
SmartSuite Millenium 96
Lotus Freelance for OS/2 1.0, 2.0
Lotus Freelance for Windows 95 96, 97
Microsoft PowerPoint Windows
3.0, 4.0, 95 (7.0), 97 (8.0), 2000, 2002 (XP),
    2003, 2007 PPT
MP3
Microsoft PowerPoint Macintosh
4.0, 98, 2001,2004, v.x PPT
Novell Presentatons 3.0, 7.0
OpenOffice Impress 1, 1.1, 2.0 SXI, SXP, ODP
StarOffice Impress 5.2 (text only), 6.x, 7.x, 8.0
SXI, SXP,
ODP
WordPerfect Presentations
Spreadsheet Formats
Enable Spreadsheet 3.0, 4.0, 4.5
First Choice SS through 3.0
Framework SS 3.0
Lotus 1-2-3 1.0-5.0, SmartSuite 97,
SmartSuite
Millenium, SmartSuite Millenium 96
WK4
Lotus 1-2-3 Charts (DOS & Windows) through 5.0 123
Lotus 1-2-3 for OS/2 2.0
Microsoft Excel Windows 2.x through 2003,
2007 Binary (file ID only) XLS
Microsoft Excel Charts 2.0-7.0 XLS
Microsoft Excel Macintosh 98, 2001, 2004, v.X
XLS
Microsoft Works SS for DOS 2.0 S30, S40
Microsoft Works SS for Macintosh 2.0
Microsoft Works SS for Windows 3.0, 4.0
Multiplan 4.0
Novel PerfectWorks Spreadsheet 2.0
OpenOffice Calc 1.1, 2 SXC, ODS
PFS:Plan 1.0
Quattro for DOS
QuattroPro 5.0-12.0, X3
QuattroPro for DOS through 5.0
Smart Ware Spreadsheet
Smart Ware II SS 1.02
StarOffice Calc 5.2, 6.x, 7.x, 8.0 SXC, ODS
SuperCalc 5.0
Symphony 1.0, 1.1, 2.0
VP-Planner 1.0
Text and Markup Formats
ANSI Text 7 & 8 bit TXT
ASCII Text 7 & 8 bit TXT
DOS character set
EBCDIC
HTML 1.0-3.2 HTM
Macintosh character set
IBM DCA/RFT
Rich Text Format RTF
Unicode Text 3.0, 4.0 TXT
UTF-8
XHTML 1.0 HTM
XML (text only) XML
Word Processing Formats
Adobe FrameMaker (MIF only) 3.0-6.0 MIF
Adobe Illustrator Postscript Level 2
Ami
Ami Pro for OS2
Ami Pro for Windows 2.0, 3.0
DEC DX through 3.1, 4.0
DEC DX Plus through 4.1
Enable Word Processor 3.0-4.5
First Choice WP through 3
Framework WP 3.0
Hangul 97, 2002, 2005, 2007 HWP
IBM DCA/FFT
IBM DisplayWrite 2.0-5.0 IP
IBM Writing Assistant 1.01
Ichitaro 5.0-13, 2004 JTD
JustWrite through 3.0
Legacy 1.1
Lotus Manuscript through 2.0
Lotus Word Pro 9.7, 96, 97, 97 (non-Win32),
SmartSuite Millennium (+non-Win32),
SmartSuite Millenium 96(+non-Win32)
LWP
MacWrite II 1.1
Mass 11 through 8.0
Microsoft Word for DOS 4.0-6.0
Microsoft Word for Macintosh 4.0, 5.0, 6.0,
    98, 2001, 2004, v.X DOC
Microsoft Word for Windows 1.0, 2.0, 6.0,
    95 (7.0), 97 (8.0), 2000, 2002 (XP), 2003,
    2007, 98J
DOC
Microsoft WordPad
Microsoft Works WP for DOS 2.0
Microsoft Works WP for Macintosh 2.0
Microsoft Works for Windows 3.0, 4.0
Microsoft Write for Windows 1.0-3.0 WRI
MultiMate 3.6, 4.0
MultiMate Advantage 2.0
Navy DIF
Nota Bene 3.0
Novell PerfectWorks Word Processor 2.0
OfficeWriter 4.0-6.0
OpenOffice Writer 1.1, 2.0 SXW, ODT
PC File Doc 5.0
PFS:Write A, B
Professional Write for DOS 1.0, 2.0
Professional Write for Windows 1.0
Q&A Write 2.0, 3.0
Samna Word through IV+
Signature 1.0
SmartWare II WP 1.02
Sprint through 1.0
StarOffice Writer 5.2 (text only), 6.x, 7.x, 8.0
SXW, ODT
Total Word 1.2
Volkswriter 3 & 4 through 1
Wang IWP through 2.6
WordMarc through Composer Plus
WordPerfect for DOS 4.2
WordPerfect for MacIntosh 1.0, 2.0, 2.1, 2.2, 3, 3.1 WPS
WordPerfect for Windows 5.1-12.0, X3 WO
Wordstar 2000 for DOS through 3.0
Wordstar for DOS 3.0-7.0
Wordstar for Windows 1.0
XyWrite through III
* Metadata only (title, subject, author, etc.) is extracted

FAQs:

Our DLP feature gives you the powerful tools you need to comply with government regulations and prevent the loss of sensitive private data.

Many organizations handle increasing amounts of confidential data on a daily basis. However the technologies that make this data easy to access and share also increase the risk of unauthorized disclosure and loss of sensitive, protected data. This has potentially serious consequences, including financial penalties, customer dissatisfaction and increased regulatory scrutiny that can cause significant damage to your business and brand reputation.

Q. What is Data Loss Protection (DLP)?
A: DLP, part of EdgeWave Email Security is an automatic surveillance system that consistently watches computer activity on your outgoing email (SMTP) traffic being generated by servers, desktop and laptop computers. EdgeWave DLP protects confidential data by identifying and securing it to prevent security policy violations and maintain regulatory compliance. EdgeWave DLP gives you the powerful tools you need to comply with government and industry regulations, such as SOX, FINRA, PCI DSS, HIPAA/HITECH and GLBA.

Q. What kind of data does DLP monitor?
A: DLP monitors and prevents the loss of all types of private data, including:

  • Patient healthcare information
  • Financial information
  • Social Security Numbers
  • Credit Card Numbers
  • Profanity (Optional)

Q. What will happen if DLP detects confidential information?
A: When DLP detects confidential data, it automatically categorizes the message and related content so action can be taken. You can configure EdgeWave DLP to block, quarantine and send notifications, markup or allow delivery. You can also configure the Advanced Reporting tool to send daily reports of such activity.

Q. Will my email be blocked?
A: In most deployments, DLP is configured to block or quarantine any outgoing message containing confidential information.

Q. What if I am sending confidential information for legitimate business purposes and it is blocked by the DLP?
A: If you are sending a legitimate email that happens to contain confidential information and it is blocked, you must contact your IT Administrator to resolve the issue.

Q. Will DLP slow down the performance of the network or my computer?
A: DLP should not significantly impact or slow down the distribution of your email.

Q. What files types are supported by the full attachment scanning feature?
A: For a full list of file types supported, please refer to our data sheet

Q. How do I add DLP to my EdgeWave Email Security solution? A: DLP is a premium feature. To add it to your new or existing EdgeWave Email Security purchase, please speak with your EdgeWave Representative.

Documentation:

PDF File
Download the EdgeWave Data Loss Protection Data Sheet (PDF).

PDF File
Download the EdgeWave DLP File Types Data Sheet (PDF).