Adaptive redaction

Adaptive redaction is a form of redaction whereby sensitive parts of a document are automatically removed based on policy[1]. It is primarily used in next generation Data Loss Prevention (DLP) solutions.[2]

Content and context

The policy is a set of rules based on content and context. Context can include:

  • Who is sending (or uploading) the information.
  • Who is receiving the information (including a website if uploading or downloading).
  • The communication channel (e.g. email, web, copy to removable media).

The content can be 'visible' information, such as that you see on the screen. For example, sending unprotected credit card information outside an organisation breaches the Payment Card Industry Data Security Standard (PCI DSS regulations). Many organisations accept credit card information through incoming email, but a reply to an email containing such information would send out the prohibited information. That would cause a breach of policy. Adaptive redaction can therefore be used to remove just the credit card number but allow the email to be sent.

Content can also be 'invisible' information such as that in document properties and revision history, and it can also be 'active' content which has been embedded in an electronic document, such as a macro. Release of 'invisible' information has on several occasions created embarrassment for government bodies.[3][4]

Purpose

Adaptive redaction is designed to alleviate "False Positive" events created with Data loss prevention software (DLP) security solutions[5]. False positives occur when a DLP policy triggers and prevents legitimate outgoing communication[6]. In the majority of cases this is caused through oversight by the sender.

See also

References

  1. ^ "Debunking Cybersecurity Jargon Part One – What is Adaptive Redaction?". emailsecurity.fortra.com. Retrieved 2026-04-22.
  2. ^ "VESTERGAARD FRANDSEN A/S v BESTNET EUROPE LTD". Reports of Patent, Design and Trade Mark Cases. 130 (11): 894–905. 2013-10-28. doi:10.1093/rpc/rct060. ISSN 0080-1364.
  3. ^ "Federal police mistakenly publish metadata from criminal investigations". The Guardian. 2014-08-27. Archived from the original on 2023-06-04.
  4. ^ How the Conservatives orchestrated the letter from business leaders - and got it wrong
  5. ^ "Cutting Out the 'False Positive' with Lexical Expression Qualifiers | Email Security". emailsecurity.fortra.com. Retrieved 2026-04-22.
  6. ^ "What Is Data Loss Prevention (DLP)? - Meaning | Proofpoint UK". Proofpoint. 2024-10-23. Retrieved 2026-04-22.

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.