TechKnowSurge
NIST 800-53 AC-4 NIST CSF PR.DS-01 ISC2 CC 5.1 NIST 800-53 SI-4 NIST 800-53 MP-7 NIST 800-53 AC-17 K0865 NIST 800-53 SC-41
VideoSecurityFree

Confidentiality - Data Loss Prevention (DLP)

Data loss prevention (DLP) is a combination of tools, technologies, and strategies designed to stop unauthorized transfer, leakage, or exposure of confidential data. Organizations deploy DLP to monitor network activity, restrict external media, and enforce data classification policies that control what information can leave the environment.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data loss prevention (DLP) is a layered approach to protecting sensitive information that combines software, technical controls, and organizational policy. Rather than relying on a single tool, effective DLP encompasses everything an organization does to prevent confidential data from being transferred, leaked, or lost through unauthorized channels. This includes monitoring outbound communications for sensitive content such as social security numbers or personal identifiers, flagging or blocking suspicious transmissions before they leave the network. Beyond network monitoring, DLP strategies often include blocking the use of external storage media like USB drives, restricting printing of sensitive documents to prevent physical data leakage, and disabling or controlling remote desktop protocol access that could expose internal systems to unauthorized users. Each of these controls addresses a distinct pathway through which data could be exfiltrated, intentionally or accidentally. A foundational element that makes DLP enforcement possible is data classification and labeling. By tagging documents with defined sensitivity or confidentiality levels, organizations enable their DLP systems to make consistent, policy-driven decisions about which data is permitted to leave the environment and which must remain internal. Together, these tools, controls, and classification practices form a comprehensive framework for reducing the risk of data loss across the organization.

What you'll learn

What's covered

Data Loss Prevention (DLP)

Aligned to

NIST 800-53
AC-4 Information Flow Enforcement
SI-4 System Monitoring
MP-7 Media Use
AC-17 Remote Access
SC-41 Port and I/O Device Access
NIST CSF
PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected.
ISC2 CC
5.1 Understand data security

Key terms

Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Data Classification
The process of organizing and labeling data based on its sensitivity or confidentiality level to inform access and handling policies.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
Remote Desktop Protocol
RDP
Remote Desktop Protocol is a Microsoft protocol that enables remote graphical access to Windows systems; it is a frequent attack target commonly exploited via credential brute-forcing, session hijacking, and unpatched vulnerabilities such as BlueKeep.

Topics

Data Loss Prevention Data Classification Cybersecurity External Media Blocking Network Monitoring Confidentiality

Transcript

Because protecting our data and our customers' data is so important, we want to implement certain controls into place to make sure that data is protected. One of those controls, one of our mechanisms to do that, is data loss prevention, or DLP. So let's take a look at data loss prevention and what it is.

What DLP is

Data loss prevention, or DLP, is a set of tools, technologies, and strategies that we use that are designed to prevent unauthorized transfer, leakage, or loss of confidential data.

What does that all mean? Well, it's not just a tool, it's not just a technology, it's not just a strategy. It's all three of those, the things that we do within our organization that help protect our data.

What it does is it looks through — for instance, if it's a tool, maybe it's a piece of software that looks through our organization to see, hey, is somebody emailing data that they shouldn't be emailing? And then maybe it's a strategy. Maybe it's, hey, is somebody connecting USB devices into the computer and they're not supposed to be doing that? Or maybe they're downloading files onto that USB drive that they're not supposed to be downloading onto it. So all that is under the umbrella of data loss prevention.

Software

One of the things that we use for this data loss prevention is software. There's software that helps us monitor what's happening on our network. So it will go through and realize that, hey, this looks like a social security number or some sort of identification number that's being emailed to the outside of our organization, and that can be problematic, that could be insecure. So it looks for things and then flags those or stops it from happening.

Strategies: blocking media, printing and remote access

One of the strategies involved in protecting our data and protecting the organization from data leakage would be blocking the use of any kind of external media. This would be like USB thumb drives, or DVDs and CDs, although we don't really use those in computers nowadays. Same thing with floppies. But these external drives, or these external sources that can store data, is one of the things that we might want to block on our network.

Even things like print blocking. We've got printers that can print out sensitive information, and that sensitive information can end up in the trash where it's not destroyed properly, or taken home with them. So that's one of the things that we may implement, print blocking, to make sure that no one's printing sensitive information at work.

Another thing that we might be blocking is remote desktop protocol. This is when users can remote into our network, and maybe they're remoting into one of the other devices on the network. Well, the problem is now that's exposing the rest of the network, and they could be stealing data. So that would be another service that we may end up blocking.

Classification and labeling

How do these DLP services and other things identify, hey, should this be going outside of our network, or is this a concern? One of the ways that we do that is through data classification and labeling. What will happen is we'll have some sort of label within the documents identifying that this could be a certain level of confidentiality or a certain level of sensitivity. With that, then we can identify what data is okay to exit our organization and what data needs to stay within the walls of the organization.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →