Data Loss Prevention (DLP) encompasses the tools and controls organizations use to keep sensitive data from leaving or being mishandled within their environment. Key mechanisms include blocking removable media, restricting printing and remote desktop access, securing clipboard activity, deploying virtual desktop infrastructure, and applying classification-based controls to monitor and stop unauthorized data transfers.
Data Loss Prevention (DLP)
Data loss protection are mechanisms we have in place to help protect our data, whereas data loss detection just detects if data is where it's not supposed to be. Data loss prevention takes steps to mitigating issues or preventing actions from loss.
Data loss prevention are the mechanisms we put into place to help protect our more sensitive data. Data loss prevention is any mechanisms or controls we put in place to help protect our data from being lost, but a lot of times it's associated with software. There's specific DLP software that helps manage our data and make sure that it doesn't get put into places that it shouldn't belong.
One of the dangers is when our users use removable media to store certain sensitive data, so one of the things we could do is block the use of any external media and resources. Then we don't have the sensitive data even being stored on them, and it can't leave the grounds, it can't leave the facility, it can't get lost track of.
Another step that we could take is print blocking. We could set up print blocking so people can't use printers to print out certain documents and certain data.
Another thing that could be a danger for our systems is remote desktop protocol. If we allow people to remote desktop into our network, they have access to all the resources on the network. We may want to block remote desktop protocol so it can't be used on our network.
Here's the clipboard on my machine. I have several slides that I copied on here. This is a concern, because the clipboard can expose certain sensitive information, so we need to be concerned about possibly clearing the clipboard, or setting certain privacy controls on our clipboard to make sure that it's not exposing sensitive data.
One of the things that I've used before to help secure data is by using virtual desktop infrastructure, or VDI. Typically what a lot of companies will do is they'll have employees VPN into the company and they gain access to a lot of resources within the company. They can also download data to their own computer, which could be problematic, because now data exists outside your network.
With virtual desktop infrastructure you would set up a bank of virtual machines. Maybe this is a server right here, and it's got a bunch of virtual machines that people can remote into. Now they're doing all of their work on these virtual machines. If they download some sort of data, it gets downloaded to the virtual machine. It never gets removed, or never goes outside of the local network, so this is a great way to make sure that data remains local.
When we set up proper metadata and tag our more classified information — our internal, confidential or restricted information — we can also do classification blocking. This allows us to analyze things like email and other systems to make sure that if any sensitive data gets put into emails, we can stop that data from exiting our infrastructure before it ever gets sent.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →