Data loss prevention (DLP) is a combination of tools, technologies, and strategies designed to stop unauthorized transfer, leakage, or exposure of confidential data. Organizations deploy DLP to monitor network activity, restrict external media, and enforce data classification policies that control what information can leave the environment.
Data Loss Prevention (DLP)
Because protecting our data and our customers' data is so important, we want to implement certain controls into place to make sure that data is protected. One of those controls, one of our mechanisms to do that, is data loss prevention, or DLP. So let's take a look at data loss prevention and what it is.
Data loss prevention, or DLP, is a set of tools, technologies, and strategies that we use that are designed to prevent unauthorized transfer, leakage, or loss of confidential data.
What does that all mean? Well, it's not just a tool, it's not just a technology, it's not just a strategy. It's all three of those, the things that we do within our organization that help protect our data.
What it does is it looks through — for instance, if it's a tool, maybe it's a piece of software that looks through our organization to see, hey, is somebody emailing data that they shouldn't be emailing? And then maybe it's a strategy. Maybe it's, hey, is somebody connecting USB devices into the computer and they're not supposed to be doing that? Or maybe they're downloading files onto that USB drive that they're not supposed to be downloading onto it. So all that is under the umbrella of data loss prevention.
One of the things that we use for this data loss prevention is software. There's software that helps us monitor what's happening on our network. So it will go through and realize that, hey, this looks like a social security number or some sort of identification number that's being emailed to the outside of our organization, and that can be problematic, that could be insecure. So it looks for things and then flags those or stops it from happening.
One of the strategies involved in protecting our data and protecting the organization from data leakage would be blocking the use of any kind of external media. This would be like USB thumb drives, or DVDs and CDs, although we don't really use those in computers nowadays. Same thing with floppies. But these external drives, or these external sources that can store data, is one of the things that we might want to block on our network.
Even things like print blocking. We've got printers that can print out sensitive information, and that sensitive information can end up in the trash where it's not destroyed properly, or taken home with them. So that's one of the things that we may implement, print blocking, to make sure that no one's printing sensitive information at work.
Another thing that we might be blocking is remote desktop protocol. This is when users can remote into our network, and maybe they're remoting into one of the other devices on the network. Well, the problem is now that's exposing the rest of the network, and they could be stealing data. So that would be another service that we may end up blocking.
How do these DLP services and other things identify, hey, should this be going outside of our network, or is this a concern? One of the ways that we do that is through data classification and labeling. What will happen is we'll have some sort of label within the documents identifying that this could be a certain level of confidentiality or a certain level of sensitivity. With that, then we can identify what data is okay to exit our organization and what data needs to stay within the walls of the organization.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →