Advanced Data Loss Prevention
The Challenge
The most coveted entity a hacker wants in a cybersecurity attack is an organization's data so developing effective data defense strategies is vital for
business continuity. However, the sheer volume of new and unfiltered information makes distinguishing exactly what is important and
worth protecting difficult to determine. If highly critical information is not tracked, it can result in misuse or unauthorized disclosures that
can be incredibly costly to recover from. To address this issue, an efficient data loss prevention tool has to be implemented that prioritizes
the detection and safeguarding of sensitive data in particular.
The Solution
ManageEngine Endpoint Data Loss Prevention (Endpoint DLP Plus), is an integrated software that can be leveraged to automate the process of locating, tagging, and controlling the movement of data across a network. It identifies and protects sensitive data contained in endpoints, mitigates accidental data disclosures, and helps eliminate external and internal cyberattacks.
Insider threat prevention with Endpoint DLP Plus
Endpoint DLP Plus strategically curbs insider risks by first, accounting for all digital assets considered sensitive by discovering an organization's confidential data and classifying it based on source and context. Second, it helps IT administrators create rules that function as virtual boundaries to prevent sensitive data from being leaked by negligent users, or hijacked by malicious actors. Lastly, it provides detailed reports to help flag suspicious user behavior and proactively stop unauthorized file actions
Get a Quote or Download Free Trial
Endpoint DLP Plus Features
Data Discovery
- Stay on top of the data influx by continuously locating archived as well as newly created files containing sensitive information.
- Deploy policies to detect all structured and unstructured sensitive items.
- Create groups of target computers according to department, function, project or role in order to focus the search efforts and to find specific types of sensitive documents.
- Receive real-time metrics to track evolving data trends and changes in security posture.
Data Classification With Pre-Defined Templates
- Categorize sensitive data into groups based on similar attributes.
- Utilize the numerous pre-defined templates to silo common forms of sensitive content, such as personally identifiable information (PII).
- Classify various types of PII, such as financial and health records based on country using nation-specific pre-defined templates.
Data Classification With Custom Templates
- Create custom templates to pinpoint miscellaneous sensitive items not covered by the pre-defined templates.
- Utilize fingerprinting technique to find sensitive files that follow company-specific or frequently used formats.
- Implement RegEx to identify documents with strings of a specified length or specific combination of characters.
- Launch a keyword search to locate content containing unique texts
Cloud Upload Protection
- Enhance web protection by allowing only select browsers to be used to process sensitive data.
- Inhibit files containing sensitive items from being exported to various cloud storage software.
- Disallow sensitive content from being transferred via third-party file sharing application.
Device Control
- Label authorized USB and peripheral devices as trusted so that all others will be blocked by default.
- Enable printer security by blocking the downloading of confidential information.
- Permit the superimposition of watermarks on sensitive documents that are allowed to be printed.
False Positives Remediation
- Allow trusted users to override restrictive policies.
- Permit personnel to request override permission through the self-service portal.
- Review reasons for requested overrides directly from the console.
- Fine-tune policies when necessary to suit user needs.
Data Containerization
- Label trusted or highly secure applications as 'Enterprise apps' to ascertain that sensitive information is processed only within these select software applications.
- Ensure that all data emerging from Enterprise apps are automatically tagged as sensitive by default.
- Restrict the transfer of data from enterprise apps to non-enterprise applications to prevent unverified and vulnerable software from accessing confidential content.
Clipboard Tool Regulation
- Enforce clipboard monitoring to prevent screenshots being taken of sensitive content.
- Prohibit users from importing content from work to non-work spaces and apps.
Email Security
- Choose which organizational domains to trust for transferring sensitive content.
- Authorize sending information to legitimate Outlook email addresses.
- Block uploading of work content through personal emails.
Reports and Alerts
- Visually navigate the dashboard highlights for a quick overview of network health.
- Conduct forensic analysis to gauge the security profile of each endpoint.
- Receive alerts about blocked attempts at transferring data.
System Requirements
The system requirements when using Endpoint DLP Plus include the following:
- Hardware requirements for Endpoint DLP Plus servers, distribution servers and Endpoint DLP Plus agents
- Software requirements for Endpoint DLP Plus servers, agents and distribution servers
- Supported Browsers
- Supported Database
- Supported Web Servers
Hardware Requirements
This section gives you information about the hardware requirements for distribution servers, Endpoint DLP Plus servers and agents.
Hardware Requirements for Endpoint DLP Plus Servers
The hardware requirements for Endpoint DLP Plus servers include the following:
No. of Computers |
Servers used |
Processor Information |
RAM Size |
Hard Disk Space |
1 to 250 |
Endpoint DLP Plus Server |
Intel Core i3 (2 core/4 thread) 2.0 Ghz 3 MB cache |
2 GB |
5 GB* |
251 to 500 |
Endpoint DLP Plus Server |
Intel Core i3 (2 core/4 thread) 2.4 Ghz 3 MB cache |
4 GB |
10 GB* |
501 to 1000 |
Endpoint DLP Plus Server |
Intel Core i3 (2 core/4 thread) 2.9 Ghz 3 MB cache |
4 GB |
20 GB* |
1001 to 3000 |
Endpoint DLP Plus Server |
Intel Core i5 (4 core/4 thread) 2.3 GHz. 6 MB cache |
8 GB |
30 GB* |
3001 to 5000 |
Endpoint DLP Plus Server |
Intel Core i7 (6 core/12 thread) 3.2 GHz. 12 MB cache |
8 GB |
40 GB* |
SQL Server |
Intel Core i7 (6 core/12 thread) 3.2 GHz. 12 MB cache |
8 GB |
30 GB* |
5001 to 10000 |
Endpoint DLP Plus Server |
Intel Xeon E5 (8 core/16 thread) 2.6 GHz. 20 MB cache |
16 GB |
60 GB* |
SQL Server |
Intel Xeon E5 (8 core/16 thread) 2.6 GHz. 20 MB cache |
16 GB |
40 GB* |
10001 to 20000 |
Endpoint DLP Plus Server |
Intel Xeon E5 (8 core/16 thread) 2.6 GHz. 40 MB cache |
32 GB |
120 GB* |
SQL Server |
Intel Xeon E5 (12 core/24 thread) 2.7 GHz. 30 MB cache |
32 GB |
80 GB* |
* May increase dynamically according to the frequency of scanning.
- While managing more than 3000 computers, it is recommended to use an SQL Server.
- While managing more than 1000 computers, it is advised that you install Endpoint DLP Plus on a Windows Server Edition.
Hardware requirements for Secure Gateway Server
The hardware requirements for Secure Gateway Server include the following :
Processor : Intel Core i5(4 core/8 thread) 2.3 GHz. 6 MB cache
RAM size : 4
GB
Hard disk space: 5 GB
Hardware Requirements for Endpoint DLP Plus Agents
The hardware requirements for Endpoint DLP Plus agents include the following:
Hardware |
Recommendations |
Processors |
Intel Pentium |
Processor Speed |
1.0 GHz |
RAM Size |
1 GB |
Hard Disk Space |
100 MB* |
* May increase dynamically depending on the operations performed on the client computer
Software Requirements
This section gives you information about the software requirements for
distribution servers, Endpoint DLP Plus servers and agents.
Supported OS for Endpoint DLP Plus Server & Distribution Servers
- Windows 8
- Windows 8.1
- Windows 10
- Windows Server 2012
- Windows Server 2012 R2*
- Windows Server 2016*
- Windows Server 2019*
* - recommended for managing 5000 or more endpoints.
Supported OS for Endpoint DLP Plus agents
Windows OS |
Windows Server OS |
Windows 11 |
Windows server 2022 |
Windows 10 |
Windows server 2019 |
Windows 8.1 |
Windows server 2016 |
Windows 8 |
Windows server 2012 R2 |
|
Windows server 2012 |
Supported Browsers
You are required to install any of the following browsers on your computer to access the Endpoint DLP Plus console:
- Microsoft Internet Explorer 10 and later versions
- Mozilla Firefox 44 and later versions
- Google Chrome 47 and later versions
Note: The screen resolution should be 1280 x 1024 pixels or higher.
Supported Database
Endpoint DLP Plus supports the following databases:
The following versions of MSSQL are supported:
- SQL Server 2005
- SQL Server 2008
- SQL Server 2012
- SQL Server 2014
- SQL Server 2016
- SQL Server 2017
Supported Web Servers
Endpoint DLP Plus uses the following web servers:
- Apache (for static file services)
- Nginx (for static file services)
- Tomcat (for application related services)
Note:
- The UEM Edition is basically a new licensing model in
addition to the Professional, Enterprise and Free Editions that we already
have in Endpoint Central.
- We have a flexible pricing and it is not necessary to buy only within the prescribed slabs. If the total number of computers in your network do not match with the prescribed slabs, contact us to get the pricing for the actual number of
computers/technicians that you wish to license.
Pricing
Annual Subscription
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
* Annual Maintenance & Support Fee
** Manufacturers price subject to change - contact us for a quote.
Perpetual
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
Products
License Fee
AMS*
** Manufacturers price subject to change - contact us for a quote.
or Download Free Trial