5.3.4. Data Loss Prevention (DLP)
💡 First Principle: DLP policies actively monitor and, when necessary, block attempts to share or move sensitive content in ways that violate policy — like emailing a credit-card-number-containing spreadsheet to a personal email address — catching risky actions at the moment they're attempted, rather than only discovering the exposure after the fact.
DLP relies on the same sensitive information types and classifiers from data classification (5.3.1) to actually recognize sensitive content within an email, document, or upload attempt, then applies the configured response — which can range from a gentle policy tip educating the user, to an outright block, to a silent admin notification for investigation.
⚠️ Exam Trap: DLP is a real-time, preventive control acting at the moment of an attempted action (like sending an email) — it is not primarily a reporting tool that reviews content after the fact, though it does generate incident reports for review.
Reflection Question: An employee attempts to attach a spreadsheet containing customer credit card numbers to a personal webmail message. At what point does a properly configured DLP policy intervene, and what are the possible outcomes?