Skip to content
BCN-T3-DAT-001Tier 3 · Best PracticesData Protection

No Data Loss Prevention Coverage

No technical control detecting or preventing sensitive data leaving approved channels.

Remediation SLA
90 days
Tier
3 · Best Practices
Domain
Data
Escalation
Reviewed at quarterly planning; may be formally deferred

What this finding is

There is no capability detecting sensitive data moving through email, collaboration platforms, endpoints, or cloud storage to unapproved destinations. Includes deployments running in monitor-only mode indefinitely, where alerts are generated but no policy is enforced and no one reviews them.

Why it is Tier 3

DLP addresses inadvertent disclosure and low-sophistication insider exfiltration, both real and both common. It is Tier 3 because DLP does not stop a determined attacker — encrypted channels and staged exfiltration defeat it — and because deployment requires substantial tuning to avoid disrupting legitimate work. The value is genuine but the returns are gradual, which is exactly the Tier 3 profile.

Most common misclassification

Presented as preventing breach. DLP addresses accidental and casual disclosure; positioning it as an anti-exfiltration control leads to over-investment here relative to Tier 1 work.

How to detect it

  1. 1Test whether a benign marker file resembling regulated data can be emailed or uploaded externally without detection.
  2. 2Check coverage across channels — email, endpoint, cloud storage, and collaboration platforms are usually addressed unevenly.
  3. 3Determine whether existing deployments enforce policy or merely log, and whether the logs are reviewed.
  4. 4Confirm detection rules match the data types you actually hold rather than the vendor's defaults.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Start with the channel carrying the highest volume of sensitive data — usually email or a single collaboration platform.
  2. 2Deploy in monitor mode first, tune against real traffic, then enforce; enforcing untuned policy generates disruption and erodes support for the programme.
  3. 3Align detection rules with the classification scheme from BCN-T2-DAT-003 rather than with generic patterns.
  4. 4Route alerts to an owner with a defined triage process, since unreviewed alerts provide no control value.
  5. 5Extend to further channels once the first is enforcing cleanly.

How to verify the fix

A benign marker file matching a defined sensitive data type is blocked or alerted on when sent through each covered channel, and the alert reaches the triage owner.

Mappings

Attacker techniques

  • T1048Exfiltration Over Alternative Protocol
  • T1567Exfiltration Over Web Service

Compliance mappings

  • ISO/IEC 27001:2022
    A.8.12 — data leakage prevention
  • GDPR
    Art. 32 — security of processing
  • SOC 2
    CC6.7 — transmission of information

Tools that surface this

Purview DLPGoogle Workspace DLPendpoint DLP agents