TechKnowSurge
CompTIA Security+ 3.3 ISC2 CISSP 2.6 NIST 800-53 MP-7 NIST CSF PR.DS-01
VideoSecurityFree

Data Loss Prevention

Data Loss Prevention (DLP) encompasses the tools and controls organizations use to keep sensitive data from leaving or being mishandled within their environment. Key mechanisms include blocking removable media, restricting printing and remote desktop access, securing clipboard activity, deploying virtual desktop infrastructure, and applying classification-based controls to monitor and stop unauthorized data transfers.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data Loss Prevention (DLP) encompasses the policies, software, and technical controls organizations implement to protect sensitive data from unauthorized exposure, transfer, or loss. While data loss detection identifies when data appears in places it should not be, DLP goes further by actively blocking or mitigating those actions before harm occurs. DLP solutions are designed to enforce boundaries around an organization's most sensitive information, whether that data is at rest, in motion, or in use across the network. Several practical controls fall under the DLP umbrella. Blocking removable media prevents employees from copying sensitive files onto USB drives or other external storage devices, ensuring data cannot physically leave the facility. Print blocking restricts the ability to produce physical copies of confidential documents, and limiting or disabling Remote Desktop Protocol reduces the risk of unauthorized network access and the data exposure that can follow. Clipboard management is another consideration, as clipboard contents can inadvertently expose sensitive information and may require privacy controls or automatic clearing policies. Virtual Desktop Infrastructure (VDI) is a particularly effective DLP approach for remote and distributed workforces. Rather than allowing employees to VPN into the corporate network and download files to personal machines, VDI provides access to centrally hosted virtual machines where all work occurs. Any data downloaded or created within those sessions remains on the virtual machine inside the corporate network, never reaching an endpoint outside organizational control. This significantly reduces the risk of data leaving the environment through remote access scenarios. Classification-based blocking adds another layer of protection by tagging sensitive or restricted data with metadata that DLP systems can recognize. When classified data is detected in outbound channels such as email, the system can automatically block transmission before it ever leaves the infrastructure. Together, these controls form a layered DLP strategy that addresses the multiple vectors through which sensitive data can be lost, misused, or exposed.

What you'll learn

What's covered

Data Loss Prevention (DLP)

Aligned to

CompTIA Security+
3.3 Compare and contrast concepts and strategies to protect data.
ISC2 CISSP
2.6 Determine data security controls and compliance requirements.
NIST 800-53
MP-7 Media Use
NIST CSF
PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected.

Key terms

Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Virtual Machine
VM
A software emulation of a physical computer that runs an operating system and applications.
Virtual Desktop Infrastructure
VDI
A virtualization technology in which desktop operating systems run as virtual machines on centralized servers and are delivered to end-user devices over a network. VDI simplifies desktop management, improves security, and allows users to access their desktop environment from any device.
Removable Media Blocking
A DLP control that prevents the use of external storage devices to stop sensitive data from being copied or transported outside the organization.
Print Blocking
A DLP control that restricts users from printing sensitive documents to prevent physical data leakage.
Clipboard Management
A DLP control that monitors or restricts clipboard activity to prevent sensitive data from being exposed or transferred via copy-and-paste operations.
Classification-Based Filtering
A DLP control that uses data classification labels or metadata to detect and block sensitive information from leaving the organization through channels such as email.

Topics

Data Loss Prevention Cybersecurity Removable Media Controls Data Exfiltration Virtual Desktop Infrastructure Data Classification Endpoint Security

Transcript

Data loss prevention

Data loss protection are mechanisms we have in place to help protect our data, whereas data loss detection just detects if data is where it's not supposed to be. Data loss prevention takes steps to mitigating issues or preventing actions from loss.

Data loss prevention are the mechanisms we put into place to help protect our more sensitive data. Data loss prevention is any mechanisms or controls we put in place to help protect our data from being lost, but a lot of times it's associated with software. There's specific DLP software that helps manage our data and make sure that it doesn't get put into places that it shouldn't belong.

Blocking the ways data leaves

One of the dangers is when our users use removable media to store certain sensitive data, so one of the things we could do is block the use of any external media and resources. Then we don't have the sensitive data even being stored on them, and it can't leave the grounds, it can't leave the facility, it can't get lost track of.

Another step that we could take is print blocking. We could set up print blocking so people can't use printers to print out certain documents and certain data.

Another thing that could be a danger for our systems is remote desktop protocol. If we allow people to remote desktop into our network, they have access to all the resources on the network. We may want to block remote desktop protocol so it can't be used on our network.

Here's the clipboard on my machine. I have several slides that I copied on here. This is a concern, because the clipboard can expose certain sensitive information, so we need to be concerned about possibly clearing the clipboard, or setting certain privacy controls on our clipboard to make sure that it's not exposing sensitive data.

Virtual desktop infrastructure

One of the things that I've used before to help secure data is by using virtual desktop infrastructure, or VDI. Typically what a lot of companies will do is they'll have employees VPN into the company and they gain access to a lot of resources within the company. They can also download data to their own computer, which could be problematic, because now data exists outside your network.

With virtual desktop infrastructure you would set up a bank of virtual machines. Maybe this is a server right here, and it's got a bunch of virtual machines that people can remote into. Now they're doing all of their work on these virtual machines. If they download some sort of data, it gets downloaded to the virtual machine. It never gets removed, or never goes outside of the local network, so this is a great way to make sure that data remains local.

Classification blocking

When we set up proper metadata and tag our more classified information — our internal, confidential or restricted information — we can also do classification blocking. This allows us to analyze things like email and other systems to make sure that if any sensitive data gets put into emails, we can stop that data from exiting our infrastructure before it ever gets sent.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →