DLP controls may operate on stored data, network and cloud communications, email, and endpoint actions such as copying, printing, uploading, or moving files to removable media.
Detection can use labels, exact data matching, patterns, document fingerprints, context, or behavior. Responses range from warning and logging to encryption, quarantine, approval, or blocking. Reliable outcomes depend on knowing which data matters and understanding legitimate business use.
Key points
Data at restDiscover and assess information in repositories, endpoints, databases, and cloud storage.
Data in motionInspect or govern supported email, web, network, API, and cloud transfers.
Data in useMonitor supported endpoint and application actions involving sensitive information.
Important limitationDLP produces both false positives and false negatives. It can miss encrypted or transformed content, unsupported channels, photographs, novel data, and activity that policy incorrectly permits.
Operational cautionOverly broad blocking disrupts work and encourages bypass; policies need owners, exceptions, tuning, and investigation procedures.