Blog

New Capability: DAS Sensitive & Regulated Data Classification

Author

  • hanan_levy

    SailPoint

Description

Data Access Security now supports the classification and cataloging of regulated and sensitive data!

Regulated Data Classification enables SailPoint’s ISC customers to quickly, easily, and consistently discover, govern, and secure sensitive unstructured data governed by Data Protection and Privacy regulations. Enabling customers to establish the necessary controls to protect sensitive data, and the appropriate governance processes to be able to address regulation requirements, respond to audits, and reduce the risk of financial penalties, from compliance fines, ransom fees in case of a breach, and reputation damage.

Customers can now leverage Data Access Security's out-of-the-box data classification policies and predefined classifications rules within their environment to automatically classify and catalog regulated sensitive data, including personal identifiable information (PII), payment card information (PCI), medical records regulated under HIPAA, and information covered under data protection laws like GDPR. Organizations can also catalog content based on internal identifiers and dynamic policies to secure intellectual property, parented information, and classified restricted content.

What is the Problem?

Organizations need a single solution through which they can consistently classify unstructured data and a single place to maintain their policies across their environment so they can secure, govern and report on sensitive data holistically. With the growth of data and the surge in Data Protection and Privacy regulations – the need to identity, classify and govern sensitive regulated data – is becoming more and more significant. Most organizations today need to comply with some regulation around data privacy and data protection. Understanding where sensitive regulated data resides is of the utmost importance to those organization – so they can efficiently govern, secure and protect that data, and account for who can access it in audits and reviews. However, discovering that data across the organization, and doing that holistically and consistently is a significant challenge.

What is the Solution?

Data Access Security extends its classification capabilities to include the discovery, classification, and cataloging of personal, regulated and sensitive data such as PII, payment card information, medical records regulated under HIPAA, and localized data protection laws like GDPR - through a single pane of glass across all unstructured data. In addition, Data Access Security supports defining dynamic policies to secure business-critical data, intellectual property, patented information and classified restricted content - to holistically protect their sensitive data and crown jewels.

Data Access Security provides an extensive list of predefined classification tools such as predefined policies to identify PII and PHI information, and data governed by regulations such as GDPR and HIPAA. Data Access Security includes dozens of classification rules to classify and catalog sensitive content including ICD and PCI related information, as well as enable dynamically defined and user-customizable classification.

New Capabilities

  • Identify and catalog sensitive and regulated data
  • Predefined policies to identify GDPR, PII, ICD, and PHI related information
  • 100+ classification rules, verification algorithms, and masking settings.
  • Create and customize dynamic policies to address unique business needs and complex regulations criteria that requires examining multiple data dimensions. You can also create verification algorithms to validate results and reduce false positives
  • Apply policies and rules to classify and categorize files and data based on content, pattern matching, keywords, and custom requirements.
  • Identify, query, and report on where sensitive data reside across all unstructured data stores holistically and consistently
  • Easily identify Entitlements and access to sensitive information and certify appropriately.
  • “Deploy Anywhere” classifiers - deployed in the customer data center or VPC to enable organizations to classify and catalog sensitive and regulated data within their own environment.

Who is Affected?

All Identity Security Cloud customers who purchased Data Access Security can take advantage of the Data Classification capabilities to be able to classify and catalog personal, sensitive and regulated data.

  • IGA Admins - now able to quickly and easily identify access to regulated data, configure certification campaigns to review and certify that access, and enable the organization to comply with regulations.
  • Compliance Manager - now able to identify access to regulated information that needs to be governed tightly, as well as defined policies to control the classification and cataloging of their organizational data. They can quickly identity Entitlements to be certified, scope campaigns based on the type of data, and identify directly assigned access that needs to be reviewed to comply with policies.
  • Chief Data Officers - can gain visibility into where critical data is, and the types of critical data through out the organization, and can define policies to uniformly and consistently classify and catalog sensitive data
  • Security Admins - can define policies to uniformly and consistently classify their unstructured data to identify where sensitive data is not properly governed and protected and apply the appropriate controls to secure it

Action Required

In order to take advantage of Data Access Security Data Classification within their environments, customers will need to deploy Data Access Security Data Classification Collection Virtual Appliances cluster to deploy the “Deploy Anywhere” collector instances that perform the classification collection task. Please refer to the Data Access Security documentation for information about deploying Data Classification Collectors.

Important Dates

Data Access Security’s Sensitive Data Classification policies are now available to all new customers in the productions and staging environments. Existing customers have been notified, in advance of rolling out to existing environment to allow customers to prepare for transition to VA-based Data Classification collectors.

The new functionality will be roll-out to existing customer environment on April 15th.