Data Loss Prevention (DLP)
Data Loss Prevention (DLP) is the set of technologies, rules and processes with which organizations prevent the loss, outflow or misuse of sensitive data. DLP solutions detect, classify and control data movements, for example in emails, file transfers, cloud applications, endpoints or web uploads. The aim is to protect confidential information such as personal data, intellectual property or financial information against unintentional disclosure and targeted exfiltration.
A DLP concept is based on Data Classification, policies, context information and controlled responses. Depending on the risk, an action can be permitted, logged, blocked or escalated for review. The balance between protection and the ability to work is particularly important: rules that are too strict create tendencies to circumvent them, rules that are too weak leave critical data unprotected. Data Loss Prevention therefore plays a central role as a component of modern security architectures.
DLP is closely linked to Data Protection, compliance and insider risks. While data protection describes the protection of data in general, DLP focuses on concrete data movements and their control. Common variants are endpoint DLP, i.e. control directly on the device (for USB copies, uploads or print jobs, for example), and enterprise DLP, i.e. company-wide, cross-channel policies with uniform visibility and enforcement. In cloud and SaaS environments, DLP gains additional importance because data is processed across many applications, users and devices.
See also: Insider Threat and SaaS Security.