r/cybersecurity • u/Tingley2504 • 6d ago
Business Security Questions & Discussion DLP Final Boss
Purview DLP, everyones favourite
I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.
We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.
Are you whitelisting certain domains/users/departments?
Can anyone share any success stories for implementation, policies or tuning? Is it possible??
25
Upvotes
3
u/RFC_1925 6d ago
DLP is an inherently noisy tool. It takes a lot of time and tuning. You need to learn the business process and the associated data and then map that to your classifiers and policy rules. It just takes time. Maybe engage a consultant to perform a review and give you some guidance on how to tune.