DLP Sensitive Information Detection Project for a Macao Government Agency

Learn more

Challenges

For cybersecurity reasons, a Government Agency of the Macao SAR aims to completely isolate its internal network from the Internet. Employees' internal network computers will only have access to intranet resources, while Internet access will be provided solely through Virtual Desktop Infrastructure (VDI). However, routine office work necessitates secure data transfer needs from the Internet to the internal network. The current lack of a secure data transfer channel has led to the consideration of implementing a secure and reliable data exchange solution.

The solution must provide audit trails, approval processes, virus scanning, and Data Loss Prevention (DLP) sensitive information detection during file exchanges between the two networks. Additionally, it requires providing personal space and public space functionality, utilizing an automatic ferry feature to upload files from a designated folder on the user's local machine to their personal space within the NXG system.

Solution

DLP Sensitive Information Detection Project for a Macao Government Agency
Implement a secure and reliable data security ferry system for the department.
This solution will provide auditing, approval workflows, virus scanning, and DLP-based sensitive information detection for files exchanged between the internal network and the Internet. It will create user personal spaces and a LAB file public space. The automatic ferry function will be used to automatically upload files from a specified folder on the user's local machine to their NXG personal space for backup and storage.

Benefits

Establish a secure and controllable file ferry system between the internal and external networks for the department.
Utilize professional network isolation devices integrated with an inter-network data exchange platform to build a secure channel for cross-network data transmission.
Integrate file transfer auditing and approval capabilities, enabling anti-virus checks and content sensitivity checks (via DLP) during cross-network file transfers, thereby ensuring security controls for data exchange operations.