Symantec Data Loss Prevention Initial Setup

Serif Muammer Sak - PeerSpot reviewer
Cyber Security Consultant at a comms service provider with 201-500 employees

I've handled deployments in the past. I've deployed four or five organizations from scratch.

The setup process is moderate in terms of difficulty. You need to plan which channels you want to monitor. This solution uses Oracle Database, and you need to calculate scalability and extensions. It's not too easy, and it's not the hardest.

If you deploy the DLP properly, you need to have business support from the business side. Two or three people can deploy this solution or all required service policies, et cetera. However, we need support from the organization since you couldn't define a policy by yourself. You need to understand what data is important and which data is sensitive. You need to talk with all of the stakeholders. For example, software developers. You need to sit with them, and you need to talk about what they are working on, and which data is important. You need to talk with human resources, finance, the entire company.

Generally, we deploy the solution in a central way. We will have one central management console and then granular access for stakeholders. For other business functions, for example, we can create a GDPR policy for the HR business since we need to follow the guidelines. And then, other shareholders can access the central data to granular access. 

In the past, I have deployed 26 DLP components into an organization with 2000 clients. It was a huge project.

Once deployed, you need to maintain the solution. You need to follow product updates. Databases are updated with new features and security fixes. A database update is not very common. You just need to update the database once a year. Also, for example, if a new Windows or Google Chrome, or Firefox version becomes available, you will also need to update your DLP product. Every three or four months, you likely have maintenance tasks related to updates. 

View full review »
Kamran Jameel - PeerSpot reviewer
Head Cyber Digital and Security at a financial services firm with 10,001+ employees

The solution has a simple setup and upgrade process. But both things require time to mature and further improve. The deployment process takes only a day if you have the hardware. 

View full review »
RP
Senior Consultant at a consultancy with 10,001+ employees

There are a few tricky parts when setting up Symantec DLP, but it's straightforward overall. We used an integrator for the deployment and didn't experience any hiccups after they were finished. About ten people from my company were involved. 

We have two or three people doing maintenance on the solution, like weekly health checks to ensure services are running and traffic flows through the console dashboard. We need to check the incidents generated from the detection servers and verify that everyone can log in. The main part of maintenance is periodic system updates and vulnerability patches.

View full review »
Buyer's Guide
Symantec Data Loss Prevention
March 2024
Learn what your peers think about Symantec Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.
Shahram Dehghani - PeerSpot reviewer
Security Technical Manager at Modaberan Fanavari Pasargad

The initial setup is difficult. You need knowledge to use it. Symantec uses Oracle for the database, and not everybody can work with Oracle.

The solution takes one day, but only for server installation. But that is because it has a template. When you deploy the template on an Oracle database, it will take about 30 minutes to deploy the template.

View full review »
DM
Data Loss Prevention and Data Classification at a insurance company with 10,001+ employees

The initial setup for Symantec Data Loss Prevention is straightforward, particularly if you use the guide, but it gets a little complex based on the networking connectivity you have within your environment. Sometimes setting up the solution can get a little tricky because it would depend on your internal infrastructure. For example, you have to connect the Symantec Data Loss Prevention platform and you need to integrate it, so that could make the process somewhat difficult.

View full review »
MuhammadJunaid6 - PeerSpot reviewer
Consultant at CNS Engineering

Our deployment process begins by understanding the customer's requirements and ensuring they have the necessary server infrastructure in place. We then install our DLP product on the customer's site and set up data agents. The customer is responsible for installing the agent on their users' devices. We proceed by creating and applying data protection policies tailored to their specific data requirements. Many of our customers have a lot of sensitive data, so they worry about its safety even after we've applied the rules. I would rate the easiness of the initial setup as a seven out of ten. It is quite user-friendly. The deployment time for this product varies based on customer needs and availability. If everything goes smoothly, it typically takes around one and a half months to deploy all the necessary components, including agents and other requirements. 

View full review »
Moataz  Ahmed - PeerSpot reviewer
Senior Network & Security Administrator at a financial services firm with 10,001+ employees

The initial setup takes a few days. However, overall, it requires a month to fine-tune the components. The deployment team includes one or two vendor executives and multiple teams from our organization. One executive can easily maintain the product. I rate the process a seven out of ten.

View full review »
SK
Associate at a insurance company with 10,001+ employees

The initial setup is straightforward.

Usually, if we are doing it from the scratch, every time when we are doing the implementation, there will be one document that will be created for other servers. 

If new users come on, they'll reference the document. It's part of our best practices. 

We recommend that someone should be available via stacking, somewhere. For example, to set up the password with the protector, or as an admin password. We used to prefer at least one person. If we get stuck, we'll have a Symantec engineer on a call to assist us. 

Usually, I'll do everything from the scratch, setting up the port under whatever LAN is required and what other system requires. 

For an Oracle installation, it will take three hours or four hours. And for the server that's at least one hour. A total of five hours to six hours is required in order to complete our implementation.

The maintenance is contract-based. Some of the clients will ask that only I implement the Symantec DLP. Then we'll do the implementation and we'll create some documents as per requirements. Clients will ask the contract be for one year or two years, and we'll do the analysis and the reports, which we need to send on a daily basis and weekly basis and monthly basis and quarterly basis. On yearly ones, we'll do the auditing. 

We used to delete the duplicate machines, or any machines supposed to be in stock or offline. Every month we will send the policy to our customers asking if there is anything they want to add, or any rule they want to delete, or anything specifically they want to create, et cetera. For example, if there are any personal kinds of users they want to monitor. We'll whatever they recommend. This is the type of maintenance I do.

View full review »
UK
Global Infosec Lead at a tech services company with 501-1,000 employees

Deploying Symantec DLP is a little complex. We had to create an Oracle database when we implemented the solution. That part was difficult, but the rest was straightforward. 

There are three phases of implementation and many tasks in the beginning. First, we had to identify our sensitive data, where they are, and how they are being used. It was a long process initially. After finding all those things, we implemented the DLP solution in the infrastructure. We had been using an endpoint DLP, which didn't cover most email traffic, so we implemented email and web DLP.

We had to do a lot of work in the early stages, but the solution doesn't need much oversight once it's mature in the infrastructure. One or two people can manage it. I and one of my team members administer it. Two other people handle the incident management. Few changes are required after it is fully deployed and mature. You occasionally need to modify some rules and add some exceptions. 

The initial installation took about a week, but it takes nearly a month to configure all the policies. Two admins and one engineer were responsible for the deployment. Maintenance involves the database, networking team, and DLP teams. That's five people altogether.

View full review »
Aleksandar Prodanov - PeerSpot reviewer
System Admin at a government

We have it installed on-premises on virtual services.

Deploying it to the end-users was not complex. It was very easy for me. I installed it on about 40 computers, each used by two users, who are all in one location. It took two or three weeks in total.

In terms of maintenance, I maintain the agents and all the servers where Symantec is installed.

View full review »
Muhammad Ejaz ul Hassan - PeerSpot reviewer
CEO at RISE Technologies

The initial setup and implementation are very straightforward. 

Setup is very clear and much easier than McAfee or Forcepoint. 

I rate setup an eight out of ten. 

View full review »
Aman-Yadav - PeerSpot reviewer
Sr technical support executive at Immenzza

For Symantec Data Loss Prevention, my company needs to deploy a database from Oracle and add a detection server depending on the organization's needs. A company can proceed with either a two-tier deployment or a three-tier deployment. A database from Symantec needs to be included during the deployment process compulsorily.

The solution can be deployed in a day or two. Preparing the database takes one day, and adding Symantec's detection server takes around 30 to 60 minutes.

The solution is deployed on an on-premises model.

View full review »
BR
Cyber Security Consultant at I(TS)² Saudi Arabia

The initial setup was straightforward. First, we had to install the Oracle database, which requires 19C if you use version 15.8. Then, we had to deploy and make the info server. After that, we had to complete the Oracle and listener configurations and connect the database. We then had to install the Windows Server and add the detection servers from the endpoint server.

During the installation, we imported different templates in .VSP format. The solution allows you to make policies and procedures with built-in templates, and there are templates for multiple sectors, such as energy, banking, financial, and telecommunication. It can be downloaded from the portal during the installation of the Oracle added to the enforce server. We can make different policies like data matching, index data matching, vector machine learning, and desktop content matching. For example, we can use proximity matching to detect data for 70% matches, 50% matches, or 20% matches. We can also upload different documents for index data matching. Exact data matching is for structured data, and index data matching is for unstructured data. Vector machine learning is for positive and negative threats, and the threshold is set for that purpose. I rate the deployment a ten out of ten.

View full review »
AG
Data Protection Manager at a healthcare company with 10,001+ employees

The installation is more complex than other solutions.

View full review »
KP
Network Engineer at LTTS

The initial setup is not very complex but it's not simple either. We had assistance from the vendor. There is no maintenance required - at the initial stage we created a policy for monitoring only and we get the day to day logs. After that we impose a policy for blocking and justification. This solution is used on a daily basis. 

View full review »
SandipArote - PeerSpot reviewer
Technical lead at a tech vendor with 10,001+ employees

We have found the initial setup to be straightforward. I'd rate the ease of deployment nine out of ten. It's not overly complex in any way. 

View full review »
NV
IT Security Specialist at TT Systems LLC

The installation for Symantec Data Loss Prevention was straightforward. It took almost fifteen days to completely roll it out.

View full review »
Raheel Naveed - PeerSpot reviewer
Senior Consultant DIS-InfoSec at Systems Limited

I would rate setting up Symantec Data Loss Prevention (DLP) 7 out of 10. It can be challenging initially, especially for newcomers to the Symantec solution. It typically takes three to four implementation attempts to become comfortable with the setup process. Following the prescribed steps is crucial, as it leads to a smoother experience and better understanding of the setup requirements.The deployment process for Symantec Data Loss Prevention (DLP) is relatively short and can vary depending on specific requirements. If implementing only the core features, it typically takes about two days. However, if additional components like the endpoint and network channels are included, it may extend to three to four days. 

View full review »
Arnab - PeerSpot reviewer
Data Analyst at a tech services company with 11-50 employees

The initial setup was not very straightforward, but it was kind of easy.

View full review »
Meleria Mangaring - PeerSpot reviewer
Solutions Engineer at Trends and Technologies, Inc

The setup is straightforward, as long as you know what you're doing. Back in the day, when I was just starting to learn data loss prevention, it got really confusing. For those who are just starting to learn how it works, it's important to note how the flow works - from identifying what data to protect, to the responses that should be applied to the policies that were configured. It's also important to note the architectural side. You need to pay attention to how the endpoint was set up, as well as the database and the detectors. 

My last deployment for Symantec took a month, however, it came with the testing already. We did it phase by phase. What really took a long time for us to set it up, was encryption, which we deployed together with the data loss prevention. We had Symantec Data Loss Prevention and at the same time, Symantec Endpoint Encryption. We would deploy them together. That client also had the programming codes. We had to deal with a lot of programming codes and it took us a lot of time to review. We had a sit-down meeting with the customer in order for them to disclose the necessary information we would need for the pilot deployment. Then we had to do testing after that. That's why, in that case, it took a month.

View full review »
GG
Senior Systems Engineer at a logistics company with 11-50 employees

The setup is a bit complex due to the Oracle database. I now have many problems installing and managing the Oracle database. At the moment, I just have a huge problem upgrading Oracle 12 to Oracle 19. It is not too easy. That said, if Oracle and the basic DLP are installed, then it can go smoothly. Afterward, there are no problems with it.

View full review »
Shridhar Shimpi - PeerSpot reviewer
Technical Support Engineer at Jainam Technologies

To deploy Symantec to protect sensitive information in our company, we implement various policies such as web, endpoint, mail, and cloud prevention. While the deployment process itself is simple, there is a requirement for an Oracle database, which can add a layer of complexity, particularly for smaller businesses that may not have the infrastructure readily available. However, we offer a software solution that manages this aspect. We leverage both on-premises and cloud-based functionalities, with customization options available for policies. Default configurations work well for cloud-based deployments, and we utilize comprehensive licensing packages. Cloud management simplifies deployment and implementation tasks significantly compared to on-premises setups, reducing the burden on our team and clients. However, there can be challenges when transitioning existing customers from on-premises to cloud-based solutions, particularly regarding feature availability and accessibility.

View full review »
SP
Sr. Manager - IT at Durr India

The initial setup was really good. It's not very easy and also not very complex. There were some issues, but we managed, and it was running well. Managing Symantec DLP isn't difficult. It's easy. 

View full review »
SS
Sales Attendant at Zoffec Infotech

The product's setup is not easy. 

View full review »
MananVora - PeerSpot reviewer
Security Architecture at Tredence Inc

The initial setup was complex and couldn't be done without expert help.

View full review »
AH
Senior Manager Network Design at Meeza

The ease of deployment of Symantec Data Loss Prevention is great. We can deploy it easily and it is flexible after the deployment. The deployment difficulty can depend on the client's requirements, there was not a client that took us more than eight weeks to complete which included the assessment, the design, the data classification, which is the second part of the solution,

View full review »
TN
‎Head: Group Legal at Optiflex

The initial setup of the solution was straightforward. It took us less than a week to make sure that we created all the rules. 

The setup itself it took less than two hours. However, applying all the rules and the configurations, and all the different qualities took longer. It total, everything took close to a week.

We only need two people for deployment and maintenance.

View full review »
Ankit-Mittal - PeerSpot reviewer
Information Security Manager at Cvent

The initial setup was easy.

View full review »
BJ
Manager at a financial services firm with 5,001-10,000 employees

The initial setup was pretty straightforward. We didn't have any issues with it, even when we upgraded to version 15.

View full review »
HX
Systems Architecture Engineer at a computer software company with 10,001+ employees

The initial setup was done by our experienced engineer. The setup is not difficult and one or two hours is enough to complete it.

View full review »
Faisal Mian - PeerSpot reviewer
CTO at ABM Info. tech

The installation of Symantec DLP is not straightforward. You need to understand the concept of the technology before you can deploy it. It's not as simple or straightforward and a certain level of skill set is definitely required. 

You need one engineer, a person in presales, and a backup in order to deploy the product.

View full review »
KN
Principal Consultant at Design Consulting Inc

The initial setup is not very complex. You just have to run it from the configuration spreadsheet. If you follow the applied process, it is fine. If you deviate from the process, then the process can begin to become complex due to lack of understanding. You have to enable all the files based on size and there are some endpoint issues, as well.

It didn't take us very long deploy.

View full review »
SK
Associate at a insurance company with 10,001+ employees

The initial setup is easy.  

View full review »
YW
Information Security Engineer at a security firm with 11-50 employees

the initial setup is not straightforward or simple. It's quite complex.

The whole deployment process took about two days or so.

In Symantec, you have to first install the Oracle database, then you can go on to install the enforce server and then detection servers. It will take time.

View full review »
SK
Engineer - Information Security at a tech services company with 51-200 employees

The setup is straightforward. The only complexity comes from the Oracle Database side. Other than that, it is straightforward. It took a half hour to install it. Once you install the manual server, and the detection server on another server you just have to install the alias. I didn't have much problem installing the system.

View full review »
it_user406974 - PeerSpot reviewer
Chief Cyber Strategist with 1,001-5,000 employees

The installation was pretty straightforward. We had to adjust for policy allowances. Once the user community gained some experience, we were able to expand the scope.

View full review »
RR
System Administrator at a tech services company with 1,001-5,000 employees

The initial setup is a little complex. But once you go through it you get used to it. After using this product it becomes easy to handle, easy to understand. Our deployment took about two months for 2,000 users. 

Our strategy was simple. I needed to implement it for every user so that we could monitor any data.

View full review »
it_user121395 - PeerSpot reviewer
ITSM & AntiFraud Consultant with 51-200 employees

Initial setup is straightforward, as you use the same installation kit, and you choose which component to install.

View full review »
MF
System Engineer at ABM Info. tech

The initial setup is quite complex and can take around two hours. 

View full review »
AT
Manager Cyber Forensic at a financial services firm with 51-200 employees

We deployed locally in our environment. All of the channels such as emails, web, and endpoints are covered.

View full review »
DP
Senior Cyber Security Consultant at Infosec Ventures

The initial setup is complex; it was not a very straightforward implementation.

The deployment took less than two months.

View full review »
MH
Private Security Consultant at a tech services company with 11-50 employees

The complexity of the initial setup depends on the requirements, but most of the time it is very difficult to implement.

View full review »
it_user840159 - PeerSpot reviewer
IT Security Engineer at a tech services company with 1-10 employees

The initial setup was not complex and it was very easy to install the Symantec database. It comes with a guide that explains every small step in detail. The deployment took about two to three days. However, if you install all the modules, it may take up to two weeks.

View full review »
AA
Information Security Consultant at a tech services company with 51-200 employees

The initial setup is complex. It should be made simpler. The deployment takes around a day to day and a half. 

View full review »
Buyer's Guide
Symantec Data Loss Prevention
March 2024
Learn what your peers think about Symantec Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.