Data Loss Prevention

Data loss prevention (DLP) is a set of technologies and policies that identify, monitor, and protect sensitive information to stop it from leaving an organization through unauthorized channels. DLP inspects data in three states, at rest in storage, in motion across the network, and in use on endpoints, and it acts when protected content, say a credit card number or source code, heads somewhere it should not go.

To make those decisions, DLP relies on content inspection such as pattern matching and keywords, context about who is moving the data and to where, and increasingly machine learning for less structured material. Here is the part teams learn the hard way. DLP is only as good as the data classification behind it, so without clear rules on what counts as sensitive and how it may be handled, the tool either floods analysts with false positives or waves real leaks straight through, which is why classification has to come first.

Why does DLP matter for the CISSP exam?

DLP is treated as a data protection control in Domain 2: Asset Security, worth 10 percent of the exam. Know the deployment points, the detection methods, and its heavy dependence on accurate classification.

See NIST SP 800-171.