New system to improve data loss prevention (DLP) in Google Drive
Google is introducing a new data loss prevention (DLP) system that will make it easier to deploy more advanced detection policies for content on Drive. The new Drive DLP functionality can be found at: Admin console > Security > Data Protection. Key updates include:
- Advanced detection policies which enable more detailed rules using nested conditions, volume based detection, finer detection thresholds, and more.
- New DLP incident management dashboard to see incident trends, view detailed incident reports, dry run rules, and more.
- Simplified deployment with more flexible scoping, roles based access for admins, and more.
Use Google’s Help Center to learn more about the differences between the legacy and new DLP systems.
The new system is separate from the legacy Drive DLP system
Currently, the new DLP system (at Admin console > Security > Data Protection) will exist alongside the legacy DLP system (at Admin console > Rules). Rules created in the new system will be separate from rules in the legacy system, and both will continue to work. You can migrate legacy DLP rules to the new DLP by manually creating a new rule in the DLP and then deleting the legacy DLP rule. When you perform this migration, we encourage you to consider reconfiguring them to use the more advanced functionality offered by the new system. Use our Help Center to learn more about migrating from the legacy to the new DLP system.
Why you’d use it
Protecting your company’s confidential data is critical. DLP supports this by giving you control over what users can share, and prevents unintended exposure of sensitive information such as credit card numbers or identity numbers. You could use it to prevent or warn users from sharing sensitive content (such as confidential information or customer social security numbers) outside of the domain. As an admin you can also use the system to get alerts about policy violations or DLP incidents and investigate information on the policy violation.
Google has developed this new system to provide a more advanced way for you to configure DLP for Drive, going beyond previously announced Drive DLP systems (DLP for Drive, and DLP for shared Drives). You can use it to make your deployment more powerful and flexible with more granular policies customized for the specific needs of your organization. Combined with added deployment flexibility, it will be easier to deploy more advanced DLP policies which add visibility into a control over your data. Use Google’s Help Center to learn more about how the new DLP system is different from the legacy system.
Advanced Detection Policies:
The new Drive DLP system provides more advanced functions to help Admins configure deeper content detection rules including:
- Nested conditions with AND, OR, and NOT – You can now define complex DLP rules leveraging a wide variety of conditions.
- Volume-based detection – Enforce DLP actions based on the number of violations to reduce the incident volume.
- Finer detection thresholds – Additional detection confidence thresholds help to balance DLP settings and reduce false positives.
- Targeted detection – Choose to target detection to comments, suggestions, title, body or all content of a Drive file.
Additionally, you can now utilize DLP rule templates to quickly author new policies. Templates utilize predefined content detectors, which can then be fine tuned with appropriate threshold levels suitable for your environment.
More advanced rules can leverage nested conditions, targeted detection, and more.
Incident management dashboard:
The new system includes a DLP dashboard that will help you test, understand and manage rules and alerts in your domain, including showing incident trends. Features include:
- “Dry Run” for your data protection rules – Generate reports without having the rule active so you can start monitoring your environment without enforcing blocking actions.
- New alert delivery options – Choose who receives alerts for specific rules, including additional members of the organization outside the super admin groups.
- Detailed incident reports – See more detailed reports for all the DLP actions (block, warn, audit).
- Integration with policy investigation tool – Help DLP response teams dig deeper into violations when needed.
New dashboard helps you see violation trends.
New dashboard gives insight into your DLP alerts.
The new system makes it easier to deploy DLP rules with features including:
- Roles-based access for administrators – assign delegated admins for DLP functions in the Admin console.
- Pre-defined content detectors – use 90+ pre-defined content detectors help expand coverage and better manage policy violations.
- Policy exports – download a copy of DLP policies
- Flexibility for scoping policies – scope DLP policies to include or exclude specific groups or OUs.
- Admins: Find the new DLP system at Admin console > Security > Data Protection. Use our Help Center to learn more about the new Drive DLP system.
- End users: No action needed.
You may interested:
- Put your archive data on ice with new storage offering
- Keep data secure with Gmail confidential mode (beta)
- Control access to corporate data on Chrome, Mac, and Windows devices
- Data Loss Prevention now available in Team Drives
- Unintended external reply warnings in Gmail to mitigate unintentional data loss