IT AI Skill

Data Loss Prevention

Prevent sensitive data exfiltration through DLP policies, data classification, monitoring of data flows, and automated enforcement. Use when discovering and classifying sensitive data, defining DLP policies, monitoring email/file/cloud data transfers, enfor...

Data Loss Prevention (DLP) & Data Governance

Protect sensitive data from unauthorized access, transfer, and exposure through comprehensive DLP strategies.

Workflow

1. Data Discovery & Classification

  1. Comprehensive data inventory:
  1. Classification scheme implementation:
  1. Continuous discovery monitoring:

2. DLP Policy Definition & Enforcement

  1. Policy framework design:
  1. Email DLP policies:
  1. Endpoint DLP controls:
  1. Cloud DLP enforcement:

3. Data Flow Monitoring & Anomaly Detection

  1. Real-time data flow analysis:
  1. Automated alerting and response:
  1. Investigation and forensics:

4. Data Encryption & Protection

  1. Encryption enforcement:
  1. Data masking and redaction:
  1. Data lifecycle management:

5. User Training & Culture

  1. Data handling training:
  1. Violation management:

Templates & Frameworks

Data Classification Policy

DATA CLASSIFICATION FRAMEWORK
==============================

LEVEL 1 — PUBLIC
  Definition: Information approved for public release
  Examples: Marketing materials, press releases, public website content
  Handling: No special controls required
  Distribution: Unlimited

LEVEL 2 — INTERNAL
  Definition: Business information for internal use only
  Examples: Internal policies, org charts, meeting notes
  Handling: Standard access controls, no external sharing without approval
  Distribution: All employees, contractors with NDA

LEVEL 3 — CONFIDENTIAL
  Definition: Sensitive business or personal data
  Examples: Customer PII, employee records, financial data, trade secrets
  Handling: Encryption at rest and in transit, RBAC, audit logging, need-to-know access
  Distribution: Authorized personnel only

LEVEL 4 — RESTRICTED
  Definition: Highly sensitive data with legal/regulatory requirements
  Examples: PHI (health data), PCI (payment cards), cryptographic keys
  Handling: Maximum encryption, dedicated systems, strict access controls, continuous monitoring
  Distribution: Minimal authorized personnel, documented business need required

DLP Policy Matrix

DLP POLICY MATRIX
=================

Channel | Data Type   | Action    | Exception Process | Notify
--------|-------------|-----------|-------------------|--------
Email   | PII         | Encrypt   | Manager approval  | Sender + Security
Email   | PCI         | Block     | VP approval       | Sender + Security + Compliance
Web     | Credentials | Block     | None              | User + Security
Endpoint| Trade Secrets| Quarantine| CTO approval     | User + Legal
Cloud   | PHI         | Block + Alert| HIPAA officer| User + Compliance
USB     | Level 3+    | Block     | CISO approval     | User + Security
Print   | Level 3+    | Watermark| Manager approval  | User

Integration Points

Edge Cases

Output

DLP Dashboard

DLP MONITORING — Real-Time
===========================

DATA INVENTORY:
  Total repositories scanned: 47
  Sensitive data repositories: 23
  Unclassified data remaining: 12 (26% — target: <10%)
  Last full scan: 2025-04-15

VIOLATION STATISTICS (Last 30 Days):
  Total events: 1,247
  Blocked: 89 (7.1%)
  Quarantined: 43 (3.4%)
  Encrypted (auto): 312 (25%)
  Warnings issued: 803 (64.4%)

TOP VIOLATION CATEGORIES:
  1. Email with unencrypted PII: 312 events
  2. USB transfer attempts: 187 events
  3. Cloud upload of confidential docs: 134 events
  4. Print jobs with sensitive data: 98 events

RISK ALERTS:
  🔴 3 users with >10 violations in 30 days — escalated to managers
  ⚠ 1 large outbound data transfer flagged for investigation (500MB to unknown destination)
  ✓ Auto-encryption rate: 94% (target: >90%)

Trigger Phrases

"DLP policy", "data loss prevention", "data classification", "sensitive data discovery", "prevent data leak", "data exfiltration", "data governance", "data lifecycle", "PII protection", "encryption enforcement", "data masking", "compliance scanning", "data inventory", "data retention policy", "DLP monitoring"