Every system, network and other device that handles, holds or sends sensitive information is to be covered by measures that stop data leaking. Purpose: spot and stop people or systems disclosing or taking out information without authorization. Guidance: to reduce leakage risk, consider identifying and classifying the information to protect, for example personal data, price models or product design material; monitoring leakage channels such as email, file transfer, mobile devices and portable storage; and acting to stop leakage, for instance by quarantining emails with sensitive content. DLP tools should find and watch sensitive information exposed to disclosure, including unstructured data on user systems; detect its disclosure, for example when it is uploaded to cloud services the organization does not trust or emailed; and stop user actions or network traffic that would expose it, such as copying database entries into a spreadsheet. Decide whether to restrict copying, pasting or uploading data to services, devices and media outside the organization, and if so use DLP or configure existing tools so users can view and work on remote data without moving it outside the organization's control. Where export is needed, let the data owner approve it and hold users accountable. Deal with screenshots and photographs of screens through terms of use, training and auditing. Protect sensitive information in backups by encrypting it, limiting access and physically securing the backup media. DLP should also be considered against an adversary's intelligence gathering on confidential or secret information of geopolitical, human, financial, commercial, scientific or other value, including actions that mislead the adversary by substituting false information, such as reverse social engineering or honeypots. Other information: DLP tools identify data, monitor its use and movement and act to stop leaks, for instance warning users or blocking transfers to portable storage; because DLP monitors staff and external communications, privacy, data protection, employment and interception law must be considered before deployment; access control and document management policies (5.12, 5.15) support it.
This control maps to 67 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 8.12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 67 it maps to, and the evidence behind each claim, over MCP and REST.