Data leakage prevention
Purpose
Apply data leakage prevention to detect and stop unauthorised disclosure of sensitive information.
How to meet this control
In short: Apply DLP measures to systems and networks handling sensitive data.
- Step 01Classify the data that must not leak and apply sensitivity labels so DLP tooling can recognise it
- Step 02Configure DLP policies in Microsoft Purview, Google Workspace DLP or a dedicated tool to monitor email, cloud uploads and endpoints
- Step 03Set rules that block or quarantine outbound messages and uploads containing card data, PII or confidential labels, with override requiring justification
- Step 04Restrict or monitor copy to removable storage and uploads to personal cloud services on managed endpoints
- Step 05Route DLP alerts to the security team for investigation and hold users accountable through the acceptable use policy
- Step 06Encrypt backups of sensitive data and tune policies to reduce false positives over time
Tip: Start with email/cloud DLP rules on your most sensitive data classes.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Identify and classify the information that needs protection against leakage
- ›Monitor channels where leakage can occur, including email, file transfers and portable storage
- ›Take preventive action such as quarantining emails carrying sensitive information
- ›Use DLP tools to identify sensitive data, detect disclosure and block exposing actions
- ›Decide whether to restrict copy, paste and upload to outside services and enforce it with tooling
- ›Require data owner approval for permitted exports and hold users accountable
- ›Address screenshots and photos through terms of use, training and auditing
- ›Encrypt and protect backups of sensitive data and consider countermeasures like honeypots
Audit evidence to keep
- - DLP policy configuration showing monitored channels and sensitive data types
- - Sample DLP incident showing a blocked or quarantined transfer
- - Sensitivity labelling or classification scheme feeding the DLP rules
- - Removable media and cloud upload restriction configuration
- - Records of DLP alert investigation and user follow-up
Common mistakes
- - Having an incident plan that staff cannot find
- - Closing incidents without root cause or lessons learned
- - Not preserving evidence before systems are changed
Owner, cadence, and proof
Assign one accountable owner for A.8.12. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.