ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.12: Data leakage prevention

Every system, network and other device that handles, holds or sends sensitive information is to be covered by measures that stop data leaking. Purpose: spot and stop people or systems disclosing or taking out information without authorization. Guidance: to reduce leakage risk, consider identifying and classifying the information to protect, for example personal data, price models or product design material; monitoring leakage channels such as email, file transfer, mobile devices and portable storage; and acting to stop leakage, for instance by quarantining emails with sensitive content. DLP tools should find and watch sensitive information exposed to disclosure, including unstructured data on user systems; detect its disclosure, for example when it is uploaded to cloud services the organization does not trust or emailed; and stop user actions or network traffic that would expose it, such as copying database entries into a spreadsheet. Decide whether to restrict copying, pasting or uploading data to services, devices and media outside the organization, and if so use DLP or configure existing tools so users can view and work on remote data without moving it outside the organization's control. Where export is needed, let the data owner approve it and hold users accountable. Deal with screenshots and photographs of screens through terms of use, training and auditing. Protect sensitive information in backups by encrypting it, limiting access and physically securing the backup media. DLP should also be considered against an adversary's intelligence gathering on confidential or secret information of geopolitical, human, financial, commercial, scientific or other value, including actions that mislead the adversary by substituting false information, such as reverse social engineering or honeypots. Other information: DLP tools identify data, monitor its use and movement and act to stop leaks, for instance warning users or blocking transfers to portable storage; because DLP monitors staff and external communications, privacy, data protection, employment and interception law must be considered before deployment; access control and document management policies (5.12, 5.15) support it.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 67 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

FedRAMP High · 6 controls

  • AC-22 Publicly Accessible Content
  • AC-4 Information Flow Enforcement
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • SC-7 Boundary Protection
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))

FedRAMP Moderate · 6 controls

  • AC-22 Publicly Accessible Content
  • AC-4 Information Flow Enforcement
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • SC-7 Boundary Protection
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • ISM-0343 Blocking writes to removable media
  • ISM-0565 Blocking emails with inappropriate markings
  • ISM-1187 Checking manual exports for unsuitable markings
  • ISM-1237 Outbound web content filtering
  • ISM-1535 Preventing export of AUSTEO, AGAO and REL data
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-RS.MI-01 Incidents are contained

PCI DSS 4.0 · 5 controls

  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations
  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 5.2.1 5.2.1 Anti-malware deployed on all system components

SOC 2 · 5 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches

ISO 27701:2019 · 3 controls

  • 7.4.2 Limit processing
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls
  • ASD37-13 Control removable storage media (Very Good)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • NS-2 Secure cloud services with network controls

CIS Controls v8 · 2 controls

  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-9.6 Block Unnecessary File Types

ISO/IEC 42001:2023 · 2 controls

  • 8.4 AI system impact assessment
  • A.7 Data for AI systems

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • AUCDR-IS-3 Securely manage information assets over their lifecycle

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 8.12 Data leakage prevention

ISO/IEC 27011:2024 · 1 control

  • 27011-8.12 Data Leakage Prevention for Telecoms

ISO/IEC 38500:2024 · 1 control

  • 5.9 Data and decisions

NIST SP 800-172 · 1 control

  • 3.1.3e Employ Secure Information Transfer Solutions
  • 22.1.24.C.03 22.1.24.C.03 Detect and block unauthorised offshore data transfers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 67 it maps to, and the evidence behind each claim, over MCP and REST.