Glossary

Dsecurity

Data loss prevention

Controls that detect sensitive patterns in a file and block or log the transfer.

How it works

DLP scans for account numbers, health ids, or labels. It can stop an upload to a personal link. It false-positives on test data. A bypass needs an audit row.

An employee attaches a sheet of customer ids to a public link tool. DLP blocks the upload and pages security. A personal mail of the same sheet that the proxy does not see gets through. The control covers only the doors it sits on.

How it differs

DLP is not encryption. It classifies and blocks. The file can still sit unencrypted on the laptop.

A scan that only reads filenames misses a ZIP of the real data.

Scan contents, not only names.

On the ticket

  • The practical close is a log line: time, actor, byte count, result.
  • Without that line the transfer is a story.
  • With it, the next person can see whether this door did what the ticket claimed.
  • If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
  • On a real ticket, write down the door, the byte count, and the clock.
  • For dlp, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
  • A progress bar is not that record.
  • A 200 response that arrives before the complete call is not that record.
  • If a retry is allowed, say how many and whether it resumes.
  • If a person must approve the send, name the person.
  • Partners who receive dlp files should match on hash or size before they import.
  • A same-length corrupt file passes a size check and fails a hash.
  • Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
  • When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.

Related

Sources

  1. NIST SP 800-53 Rev. 5

    Control families for audit and access