Discovery is a form of voyeurism – it’s titillating but the fun wears off quickly.
Automated discovery of data at rest is an unsurmountable challenge for institution with large quantities of PCs, data and thousands of document formats, most of which are not well-documented and all the application and database server technologies that were ever invented. Smaller companies may find it either unnecessary or not cost-effective.
Discovery of data at rest is also a double-edged sword. From a compliance perspective, it’s not only not required by PCI DSS 1.x but it can create exposure issues that no business in their right mind would want to deal with. Also – why would a business want to buy products and services from a technology vendor vendor and allow them to “discover” their data?
Love to hear your comments and what you think.