The Zscaler Data Protection Tour: Enhancing DLP with Exact Data Match

In this blog series, we’re taking our readers on a tour of the various challenges faced in enterprise data security today. As we do so, we will detail the ins and outs of each subject, describe why they all matter when it comes to keeping sensitive information safe, and explain how your organization can thoroughly and easily address each use case with Zscaler technologies—like cloud access security broker (CASB), data loss prevention (DLP), and more.

In each portion of this series, a brief video will accomplish the above while presenting a succinct demonstration in the Zscaler user interface, concretely showing how you can protect your data. 

Prior topics include shadow IT, risky file sharing, SaaS misconfigurations, noncorporate SaaS tenants, and sensitive data leakage. This blog post’s topic is:

Enhancing DLP detection

Organizations often want to secure specific data values rather than any information matching a given data pattern. For example, a company may want to secure customer credit card numbers, but not care about employees using their personal credit cards to make personal purchases. In such scenarios, DLP solutions that can only scan for data patterns (like generic credit card numbers) will generate a myriad of false positive results. This translates to wasted time for admins who have to comb through countless alerts to ensure that the right data is actually being protected. 

Zscaler Exact Data Match (EDM) addresses the aforementioned use case and alleviates the above headaches. By identifying specific data values that need to be protected rather than generic data patterns, detection accuracy is enhanced, false positives are reduced, and time is saved for administrators. Because only hashes of exact data are uploaded to Zscaler for EDM, sensitive data never leaves the customer’s purview. 

To see how EDM works in the Zscaler user interface, watch the demo below.



