← All ProjectsEndpoint Security
Engineering Case StudyASSERSAN

Endpoint Data Protection & DLP Policy Governance

KVKK-Aware Sensitive Data Protection and Endpoint Hardening via ManageEngine Endpoint Central DLP

Configuration of sensitive data filters (TCKN, financial data, confidential documents) and peripheral interface controls using ManageEngine Endpoint Central DLP at ASSERSAN to prevent unauthorized endpoint exfiltration.

OrganizationASSERSAN
RoleIT Manager
Period2025 – Present
Evidence StateVERIFIED
Technologies Used:
ManageEngine Endpoint Central DLPData ClassificationSensitive Data FilteringUSB & Peripheral ControlEndpoint SecurityKVKK Compliance Processes

Verified Technical Scope

01

Configuration of rule sets for TCKN, financial records, and sensitive corporate data filtering

02

Control of USB storage devices, peripheral interfaces, and data exfiltration vectors

03

Management of departmental exception groups aligned with legitimate operational workflows

04

Endpoint event log auditing and false-positive reduction

Context & Objectives

Deploying endpoint DLP controls to protect corporate proprietary information and sensitive personal data within KVKK-aware data protection boundaries at ASSERSAN.

Technical Challenges

Preventing sensitive data exfiltration to portable media without hindering operational productivity, and designing justified exception workflows for specialized business units.

System Architecture & Interaction Layers

Endpoint DLP and Data Protection Architecture

Sensitive data discovery, peripheral control, and incident logging workflow.

11. Data Classification Layer
Data Discovery

Sensitive data definitions, national ID (TCKN) patterns, and financial data filters.

TCKN Pattern MatchingFinancial Account DefinitionsConfidential Document Tags
22. Peripheral & Channel Control Layer
Channel Controls

USB storage restrictions, peripheral policies, and departmental exception groups.

USB Storage RestrictionsPeripheral Device PoliciesDepartmental Exceptions
33. Auditing & Incident Management Layer
Incident Auditing

Endpoint telemetry monitoring, false-positive tuning, and central management.

DLP Incident LogsFalse-Positive TuningCentralized Admin Console
Soyut Katman MimarisiKamuya Açık Doğrulanmış Model

Key Responsibilities

  • ›Designing and configuring ManageEngine Endpoint Central DLP policies
  • ›Creating sensitive data classification rule sets
  • ›Defining USB and peripheral interface access policies
  • ›Managing departmental exception groups and analyzing incident logs

Architectural Approach

Adopted a phased rollout methodology. Initial observation in audit/monitoring mode identified legitimate data flows, followed by targeted enforcement on high-risk vectors and calibrated departmental exceptions.

Implementation & Deployment

  • 1.Distributed Endpoint Central DLP agents across managed workstations.
  • 2.Configured detection filters for national identity numbers (TCKN), financial records, and proprietary documents.
  • 3.Enforced blocking and read-only restrictions for removable USB storage devices.
  • 4.Defined controlled exception groups for departments with verified operational transfer requirements.

Testing & Validation

  • ✓Simulated USB data exfiltration and sensitive data pattern transfers on pilot endpoints.
  • ✓Verified operational continuity and audit log generation for permitted exception groups.

Concrete Outcomes

Outcome 01

Configured sensitive data protection rule sets via ManageEngine Endpoint Central DLP.

Outcome 02

Enforced USB and peripheral device restrictions across managed endpoints.

Outcome 03

Implemented structured departmental exception governance for authorized business units.

Engineering Lessons & Reflections

💡

Phased deployment with an initial audit period minimizes employee friction and prevents unintended business disruption.

💡

Exception governance must adhere strictly to the principle of least privilege with periodic validity reviews.