No Data Loss Prevention Coverage
No technical control detecting or preventing sensitive data leaving approved channels.
- Remediation SLA
- 90 days
- Tier
- 3 · Best Practices
- Domain
- Data
- Escalation
- Reviewed at quarterly planning; may be formally deferred
What this finding is
There is no capability detecting sensitive data moving through email, collaboration platforms, endpoints, or cloud storage to unapproved destinations. Includes deployments running in monitor-only mode indefinitely, where alerts are generated but no policy is enforced and no one reviews them.
Why it is Tier 3
DLP addresses inadvertent disclosure and low-sophistication insider exfiltration, both real and both common. It is Tier 3 because DLP does not stop a determined attacker — encrypted channels and staged exfiltration defeat it — and because deployment requires substantial tuning to avoid disrupting legitimate work. The value is genuine but the returns are gradual, which is exactly the Tier 3 profile.
Most common misclassification
How to detect it
- 1Test whether a benign marker file resembling regulated data can be emailed or uploaded externally without detection.
- 2Check coverage across channels — email, endpoint, cloud storage, and collaboration platforms are usually addressed unevenly.
- 3Determine whether existing deployments enforce policy or merely log, and whether the logs are reviewed.
- 4Confirm detection rules match the data types you actually hold rather than the vendor's defaults.
How to remediate it
Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.
- 1Start with the channel carrying the highest volume of sensitive data — usually email or a single collaboration platform.
- 2Deploy in monitor mode first, tune against real traffic, then enforce; enforcing untuned policy generates disruption and erodes support for the programme.
- 3Align detection rules with the classification scheme from BCN-T2-DAT-003 rather than with generic patterns.
- 4Route alerts to an owner with a defined triage process, since unreviewed alerts provide no control value.
- 5Extend to further channels once the first is enforcing cleanly.
How to verify the fix
A benign marker file matching a defined sensitive data type is blocked or alerted on when sent through each covered channel, and the alert reaches the triage owner.
Mappings
Compliance mappings
- ISO/IEC 27001:2022A.8.12 — data leakage prevention
- GDPRArt. 32 — security of processing
- SOC 2CC6.7 — transmission of information