This document is based on a Reconnex/TechTarget webcast entitled "The Ins and Outs of Data Leak
Prevention Tools" by Rich Mogull, who has over 17 years experience in information security, physical security, and risk management.
According to Mogull, there is a typical migration path for these tools. Most of the time companies start by wanting to see how people are using sensitive information, and they want to see if they are leaking information. This is where the term Data Leak Prevention (DLP) comes from. So, they start looking around and they want to implement something we call a network-monitoring mode. This monitoring usually causes some degree of anxiety, because they see how much information is flowing out of the organization. From there, they move into filtering and enforcement, especially over e-mail. Then they want to know where all this information came from in the first place and that is when they move into a phase of content discovery. This phase amounts to crawling through their storage infrastructure to figure out where all that sensitive information resides.