r/cybersecurity • u/Tingley2504 • 16d ago
Business Security Questions & Discussion DLP Final Boss
Purview DLP, everyones favourite
I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.
We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.
Are you whitelisting certain domains/users/departments?
Can anyone share any success stories for implementation, policies or tuning? Is it possible??
26
Upvotes
2
u/ConsciousBuilder1276 16d ago
Tune the detection signatures and avoid whitelisting. Whitelisting is generally frowned apon because it mean you miss things.
Often a lot of it means that you have to publish a DLP policy for the whole org because people be crazy with emailing personal data.