Data Loss Prevention
Data loss prevention (DLP) detects and prevents sensitive information from leaving an organization through unauthorized channels. It uses content inspection, context-aware policies, and enforcement actions to stop accidental or malicious exposure of confidential data.
itDefensive security and security operations | OpenSkills.info
Intro
Data Loss Prevention
Data loss prevention, or DLP, helps you identify sensitive data and control how people and systems use or transmit it. It focuses on confidentiality: keeping data from reaching an unauthorized person or system.
DLP is not one product or one inspection point. It is a policy system that connects data classification, activity context, enforcement, alerts, and investigation. A useful DLP program covers data at rest, data in motion, and data in use.
Why DLP exists
Sensitive data must remain available to authorized work. That same access creates opportunities for disclosure. A worker can address an email incorrectly. A compromised account can download records. A malicious insider can copy files to removable media. A lost device can expose local data.
Digital disclosure is hard to reverse. Once an unauthorized party has a readable copy, you cannot guarantee that every copy is recovered. DLP aims to prevent or limit that disclosure and preserve evidence for response.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/glossary/term/data_loss_prevention
Supports
- DLP identifies, monitors, and protects data at rest, in motion, and in use
- DLP uses content inspection and transaction context to prevent unauthorized use and transmission
- https://www.nccoe.nist.gov/publication/1800-28/VolA/index.html
Supports
- Data confidentiality means preventing unauthorized disclosure during storage, processing, and transit
- Breaches can cause operational, financial, and reputational impacts
- Identification and protection complement detection, response, and recovery
- https://www.nccoe.nist.gov/publication/1800-28/VolB/index.html
Supports
- Data inventory, protection, access control, policy enforcement, logging, and network protection work together
- Accidental email, lost device, compromised credentials, malware exfiltration, and privilege misuse are confidentiality scenarios
- Digital confidentiality loss cannot be reliably undone after an unauthorized party receives the data
- Technical means cannot completely stop every determined malicious insider
- Security monitoring and protection can create privacy risks that require data-flow awareness, minimization, access control, and lifecycle management
- https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
Supports
- DLP policies combine content analysis, locations, activities, and protective actions
- Detection can use keywords, regular expressions, validation, proximity, and machine learning
- Actions can warn, allow justified override, block, quarantine, log, and alert
- Simulation, testing, tuning, user training, and business-process input precede restrictive deployment
- DLP reporting and alerts support investigation and policy tuning
- https://learn.microsoft.com/en-us/purview/dlp-overview-plan-for-dlp
Supports
- Planning starts with stakeholders, sensitive information categories, business processes, goals, and strategy
- https://learn.microsoft.com/en-us/purview/dlp-create-deploy-policy
Supports
- Policy implementation covers intent, scope, conditions, actions, notifications, simulation, tuning, and production use
