Posted and provisioned by Fortify 24x7. Protection standing over the ground American businesses built.Your stationReach the crew
Red White and Blue Networks
District 05 / Protected records

Nobody can tell you where the sensitive files are. That is the actual problem.

Ask an office where the social security numbers live. The answer comes back confident and roughly a third right. The rest sit in a mailbox attachment from years ago, a spreadsheet on somebody's laptop, and a folder made during a migration nobody documented. Two posts: one that finds them, one that governs them.

ActifileDiscovery and scoringEncryption and channels
2 posts / find it, then govern it / per device
Posts on this guide2
Runs onActifile
Billed perOne device
SequenceLocate first, govern second

Exposure is a number, and the number ranks the work

Discovery on its own produces a very long list, which is another way of producing nothing. What makes it usable is scoring: how many regulated records sit on this particular machine, of what kind, and therefore what the loss of that one machine would actually mean.

Once every device carries a number, cleanup has an order. The laptop holding nine thousand records gets attention this week. The one holding four does not. That is a conversation an owner can hold without a security background, which is exactly the point.

A list nobody can rank is another way of producing nothing at all.

Governing the routes out

The second post acts on what the first one found. Encryption applied to the sensitive material itself, and control over the channels records leave by: removable drives, upload destinations, and the copy-out paths people reach for when they are in a hurry.

We tune this the way we tune everything, which is slowly and against real traffic. A control that stops the bookkeeper from doing the job gets switched off by somebody inside a fortnight, and then you have neither the control nor an honest account of it.

Posts on this guide

Detail and rates

Each rate below comes from billing the moment the page opens. Anything under this district drops into your roster while you read on.

Fortify-DLP-ClassifyPost detail

Sensitive Data Discovery

Sweeps, sorts and scores what each machine carries, by Actifile

Finds the regulated and proprietary material sitting on machines and shares, sorts it by kind, and puts a number on what each device is carrying.

  • Sweeps machines and network shares for records that are regulated or proprietary.
  • Sorts findings by kind, so the risk conversation has categories in it.
  • Puts a number on each device, and that number decides the order of the cleanup.
Runs onActifile
Turns upRegulated and proprietary records, on machines and on shares
BucketsBy record kind, so the categories mean something
ScoreA number per device, tracked over time
You receiveA ranked list you can work your way down
Billed perDevice, each month
Pullingper device
charged before the month starts
QTY
Fortify-DLP-EnforcePost detail

Encryption and Channel Control

Cipher on the material, plus rules on the routes out, by Actifile

Acts on what discovery turned up. Encryption on the sensitive material and rules on the channels records travel out by.

  • Encryption applied to the sensitive material rather than whole volumes.
  • Channel rules for removable drives and upload destinations.
  • Tuned against real traffic, because a control people bypass is not a control.
Runs onActifile
CipherApplied to sensitive material, not the whole volume
RoutesRemovable media, uploads, and copy-out paths
RolloutWatched first, enforced after, adjusted against real work
RequiresDiscovery, which has to run before this can act
Billed perDevice, each month
Pullingper device
charged before the month starts
QTY
Honest scope

Where this guide stops

Finding records and governing them is useful work that stops well short of a compliance program. Here is the edge of it.

  • Discovery is very good and it is not complete. Records inside odd formats, pictures of documents, and systems nobody mentioned during scoping can be missed. We will tell you what was swept and what was not.
  • This is not your compliance program. These posts produce evidence and cut exposure. They do not write your policies, run your assessments, or answer an auditor on your behalf.
  • A person allowed to send it can send it. Channel control raises the effort and leaves a record. It does not stop somebody with legitimate access and a decision already made.
  • Encryption protects the file, not the account. A record encrypted at rest is still readable inside an authorized session. Identity controls are what bound that, and they live elsewhere.
  • Enforcement waits on a decision from you. We will not switch on a rule that blocks daily work without your say. That means a stretch where discovery has run and enforcement has not.
MARKER

Heads up: card statements show FORTIFY 24X7 - Red White and Blue Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.