Information Exposure Assessment (IE Assessment)
With control of information passing through endpoints, most organisations have little idea of what information is stored at the endpoints. In addition the exposure through personal, confidential or financial information at the endpoints is also completely unknown. So the investment in security products to protect it may be a waste of time and money.
By using Guardian Technologies consultants and tool sets, the information exposure can be assessed and support justification of the necessary security initiatives. Guardian Technologies advocates a sample set of endpoints is assessed for the amount and type of information stored rather than assessing every endpoint. Clients can make full textual searches to identify specific phrases or credit card numbers. Any type of search or textual combination can be searched for.
The resultant report will identify, collectively what type of files and the amount stored at the endpoint. It will also show files of containing particular textual strings, keywords, number sequences, in fact, anything that is searched for.
IE Assessment Process
- Kick off meeting with client to understand and document requirements, understand and allocate responsibilities and to develop a project plan
- Installation of Versec data discovery agent onto sample endpoints. Agents are loaded via the Versec console or via the standard MSI deployment used by the client
- Data collection initially collects and indexes content on the endpoints. Scans can be performed at any time night or day to suit the client
- Textual searches can be made to the index for fast identification of affected endpoints. Then live textual searches can be used on target endpoints for more detailed analysis. Indexes can be updated overnight if required
- All data is collected and a report created of the capacity by filetype across sample endpoints. Specific searches are listed with the results for the affected endpoints listed. Further searches can be run until complete analysis has been completed. Initial results are discussed with the client to ensure all searches are complete and as expected.
- Agent is removed from all endpoints automatically either by Versec console or by client method
- Final Report and presentation to client with next steps and actions to address information exposure.







