Data Loss Prevention

 View Only

 Scanning AWS S3 buckets with on-prem Enforce server DLP solution

1nfoSec3ngineer's profile image
1nfoSec3ngineer posted Apr 23, 2021 01:47 AM
I'm really hoping someone can answer my question or at least point me in the right direction.

We have been running DLP Network Protect and Network Discover long before I took it over 4 years ago, but like a lot of other companies we have made the move to AWS and need to start scanning S3 buckets for sensitive data. We had purchased Cloud Workload Protection Storage only to find out we needed the DLP add-on which we then purchased months later. After getting the CloudFormation stack & everything else configured, I realized there was no way to hook it into our on-prem Enforce server to use the already configured policies for the scans. Support then advises me that we don't have the correct product and need to purchase the Cloud Management Portal to have the ability to scan S3 buckets using our current setup since our current NP & ND license would cover scanning S3 buckets. Fast forward another 3 months.....we were reimbursed for CWPS and have now purchased the CMP license. This is where my problem currently stands.....I have connected our Enforce server to our Cloud Management Portal, but there is definitely nowhere in that portal to connect our AWS account, nor do I see anything anywhere in the Enforce Admin portal to configure scanning of S3 buckets.  Am I the only one that is not understanding this new license structure that Broadcom has created?  All I know is, if we can't get anywhere with this soon, we will be finding a new solution altogether for DLP because the last year has been the most horrifying experience in my last 15 years of being in IT. Any help would be greatly appreciated!!  Thank you!!
DLP Solutions's profile image
Trusted Advisor DLP Solutions
Hey there.. 

I wrote an article about this a while ago.. it is not using what BRDCM is trying to sell.. but using the original Discover platform.

Take a look.. it's not clean but it worked. 

https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=95d04a93-f53f-4e06-981d-6997536a4b8a&CommunityKey=65cf8c43-bb97-4e96-ae0b-0db8ba1b4d07