Know
What is Data Loss Prevention?
Controls that identify sensitive data and help prevent unauthorized disclosure, transfer, or use. In practice, data loss prevention should be understood in the context of the identities, systems, applications, data, trust relationships, and business processes it affects. The useful question is not only what the term means, but how it changes attacker capability or defensive control.
Why it matters
Controls that identify sensitive data and help prevent unauthorized disclosure, transfer, or use. Its value depends on correct implementation, monitoring, and integration with surrounding controls rather than simply enabling a product feature.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
MITRE and NIST connect data theft to defensive data-loss controls
MITRE ATT&CK defines exfiltration as adversary behavior for stealing data, while NIST describes DLP as the ability to identify, monitor, and protect data in use, in motion, and at rest against unauthorized use or transmission.
The pair makes the attack-and-control relationship clear: defenders need to understand both how data leaves and how policy, classification, and telemetry can constrain that movement.
Understand the mechanics
How it works
- 1
The organization defines the security objective that Data Loss Prevention is expected to enforce.
- 2
Policy, identities, assets, data flows, and exceptions are configured so the control can make consistent decisions.
- 3
The control produces enforcement actions, telemetry, or both.
- 4
Teams monitor effectiveness, investigate exceptions, and tune the control as systems and threats change.
Practice
What to watch for
- Coverage gaps or unmanaged assets outside the control
- Policy exceptions that are old, broad, or poorly owned
- High-risk alerts repeatedly suppressed without remediation
- Configuration drift or telemetry gaps that prevent validation of expected behavior
Perform
What to do
- 1
Confirm whether the control or capability behaved as designed.
- 2
Identify affected assets, users, policies, and exceptions.
- 3
Correct high-risk configuration or coverage gaps and verify the change.
- 4
Document the lesson and update standards, monitoring, or training when the issue is systemic.
How to reduce the risk
- Classify sensitive data and know where it resides.
- Limit access and sharing to business need.
- Monitor unusual transfer, download, and egress patterns.
- Apply encryption, retention, and DLP controls appropriate to risk.
Business impact
- Data breach
- Regulatory exposure
- Intellectual-property loss
- Customer trust damage
What different roles should do
Security / IT
- Define ownership, coverage, policy, and telemetry for the capability.
- Test that the control works against realistic failure modes.
Leadership / Risk
- Track coverage, exceptions, and material gaps.
- Fund remediation based on business impact rather than tool deployment alone.
Framework & standards context
- NIST Cybersecurity Framework (CSF) 2.0
Source transparency
Authoritative sources
Last reviewed: 2026-09-02