Workers are constantly creating and sharing new ideas, and keeping these ideas safe needs to be simple, quick and reliable. Google for Work already helps admins manage information security with encryption, audit reports, sharing controls, mobile management and two-factor authentication. But sometimes mistakes happen; for example, you might hit “Reply all” when meaning to send a private message. So today, if you’re a Google Apps Unlimited customer, Data Loss Prevention (DLP) for Gmail will add another layer of protection to prevent sensitive information from being revealed to those who shouldn’t have it.
How Gmail DLP works
Organizations may have a policy that the Sales department should not share customer credit card information with vendors. And to keep information safe, admins can easily set up a DLP policy by selecting “Credit Card Numbers” from a library of predefined content detectors. Gmail DLP will automatically check all outgoing emails from the sales department and take action based on what the admin has specified: either quarantine the email for review, tell users to modify the information, or block the email from being sent and notify the sender. These checks don’t just apply to email text, but also to content inside common attachment types―such as documents, presentations, and spreadsheets. And admins can also create custom rules with keywords and regular expressions.
Check out the DLP whitepaper for more information including the full list of predefined content creators, and get started. Gmail DLP is the first step in a long term investment to bring rule-based security across Google Apps. We’re working on bringing DLP to Google Drive early next year, along with other rule based security systems.
As we round out the year, let’s take a look at some of the other work we brought to our services in 2015 to enhance the security, privacy and the control you have on your information.
- To verify the good work we do on privacy, we were one of the first cloud providers to invite an independent auditor to show that our privacy practices for Google Apps for Work and Google Apps for Education comply with the latest ISO/IEC 27018:2014 privacy standards. These confirm for example, that we don’t use customer data for advertising.
- To make security easier for all, we have expanded our security toolset:
-
- We introduced Security Keys to make two-step verification more convenient and provide better protection against phishing and we launched Password alert, an open source Chrome extension which makes sure you don’t compromise your password by typing it into another tool.
- For admins, we released Google Apps identity services which allows secure single sign on access with SAML and OIDC support and we completed device (MDM) and app (MAM) Mobile Management across Google Apps. And we launched Postmaster tools to help Gmail users better handle large volumes of mail and report spam.
- For Google Cloud developers, the Cloud Security Scanner allows you to easily scan your application for common vulnerabilities (like cross-site scripting (XSS) and mixed content).
- For those who want the power and flexibility of public cloud compute and want to bring their own encryption keys, we announced Customer-Supplied Encryption Keys for Google Cloud Platform.
- To give more transparency on how email security, even beyond Gmail, is changing over the years, we published the Safer Email report.
- To give you more control over your information, we introduced new sharing features, alerts and audit events to Drive for Google Apps Unlimited customers. For example, administrators can now create custom alerts, and disable the downloading, printing or copying of files with Information Rights Management (IRM). New sharing settings give workers better control within their organization unit and now admins can let them reset their own passwords. Google Groups audit settings allow better tracking of Groups memberships. For all, the launch of google.com/privacy gives better control over personal data and we think Android for Work makes it easier to keep personal and work data separate on their devices.
While 2015 was a great year, there’s a lot more in store in 2016. To learn more about how our technology is evolving , please join us at the Enigma conference in San Francisco on January 25th to discuss electronic crime, security, and privacy ideas that matter.

