Securing Corporate & Documents Richard Elphick Titus Labs
Titus Labs Overview East Midlands WARP
Titus Labs Overview Headquartered in Ottawa, Canada Established in the UK since 2005 Microsoft platform Solution Provider Classification Document Classification Sharepoint Solutions Data Classification Market Leader - Local Authorities, Criminal Justice, Central Government, Defence, Commercial 1.5 million+ seats world wide 150,000+ seats in UK 3
Top Reasons for Protective Marking Awareness Accountability Compliance Efficiency Enforcement Automation 4 RESTRICTED PROTECT NOT PROTECTIVELY MARKED
UK Government Compliance HMG Security Policy Framework Security Policy No. 2: Protective Marking and Asset Control GCSX Code of Connection (CoCo) v4.1 Government Protective Marking Scheme (GPMS) 5 | © TITUS LABS. ALL RIGHTS RESERVED | GCSX NETWORK CONTROL NUMBER 23 (MUST) The mail client or user adds security labels to each that carries a protective marking of PROTECT or higher MANDATORY REQUIREMENT 11 Departments and Agencies must apply the Protective Marking System and the necessary controls and technical measures as outlined in this framework.
GPMS Classification Levels Protective MarkingImpact level Top Secret6 Secret5 Confidential4 Restricted3 Protect2, 1 Not Protectively Marked0 6
Sensitive Data Breach: Fines Lawsuits Embarrassing headlines Loss of IP Possible risk to public safety
Communication and Security Challenges Information Security High storage and eDiscovery costs with “archive everything” Low adoption of security technologies e.g. Encryption Leveraging Data Loss Prevention and perimeter security solutions Inadvertent Data Loss Unstructured information assets Sensitive s forwarded to inappropriate recipients Confidential document leaks Compliance with government classification schemes e.g. GPMS Inconsistent enforcement of classification policies Lack of information handling awareness and accountability Policy Enforcement 8
| © TITUS LABS. ALL RIGHTS RESERVED | Start with Protective Markings Helps inform risk-management based decisions Promotes secure information sharing Forces users to stop and think about the value of data RESTRICTED PROTECT NOT PROTECTIVELY MARKED
Message Classification Document Classification Titus Labs Protective Marking Solutions 10 SharePoint Server 2008 R2 FCI Classification & policy enforcement at the desktop
Titus Labs Message Classification Key FeaturesBenefits Classification Selector Enforce classification at point of creation Label MarkerRaise security awareness through visual markings Metadata GeneratorEnhance archiving, DLP, perimeter security solutions Policy VerifierEducate users and stop slips Security EnablerTransparently encrypt and protect s 11 Classification and policy enforcement at the desktop for s, meeting requests, and tasks
Classification Selector – Simple for Users 12 Compose Click Send Classification pop-up Guided classification
Help Tooltips in Select Dialog
Customizable Online Help 14 Customizable help page......reinforces classification training
Visual Labels for Awareness 15 Header Footer Disclaimer Subject Marking Titus Labs Task Pane & Ribbon (Office 2007)
Reduce Inadvertent Disclosure 16 Policy Verifier: Before Send Trusted Domains Safe Recipients Content Validation No Change/Downgrade Maximum Recipients Warn on Send All messages are customizable
Message Classification Web Access Key FeaturesBenefits Classification Selector Enforce classification at point of creation Label MarkerRaise security awareness through visual markings Metadata GeneratorInteroperate with TMC for Outlook, and enhance archiving, DLP, perimeter security solutions Policy VerifierEducate users and stop slips OWA PreventPrevent viewing of confidential information when using OWA 17 Classification and policy enforcement for OWA s, meeting requests, and tasks
TMC & TDC 3.3 Platform Support Microsoft Office 2003, 2007, 2010 Microsoft Windows XP, Vista, 7 Microsoft Exchange 2003, 2007, 2010
Key Takeaways 19 UseableHigh user acceptance/adoption with minimal disruption DeployableDeploys fast and easily; SMS and Group Policy 1 MB footprint per application AffordableLow cost per user; leverages existing infrastructure High ImpactImmediate compliance and information protection
Conference Round-up John Doyle Leicester City Council, EMGWARP Vice Chair
EMGWARP Conference Thank you