Data Leakage Prevention - ISO 27001 Annex A Control

ISO 27001 Annex A 8.12

Most data leaks are accidents - the controls have to handle accidents as well as intent.

ISO 27001 Annex A 8.12 - Data Leakage Prevention

Data leakage covers all the ways sensitive information can leave the organisation - email to the wrong recipient, cloud storage configured too openly, removable media taken home, screenshots posted to chat tools, and the more deliberate exfiltration paths used in attacks. Most leaks are accidents rather than malicious; the controls need to address both.

Technical data loss prevention (DLP) tools can detect and block sensitive content in email, web traffic, and endpoint activity. They depend on classification working - the system can only protect what it can identify as sensitive. Implementing DLP works best where information is already classified and labelled in line with the wider classification scheme under A.5.12.

Procedural and cultural controls sit alongside the technical ones. Staff need to know what they can and cannot do with information at each classification level, and what to do when something goes wrong. Reporting near misses without blame helps the organisation learn from incidents that did not escalate.

The DLP that helps most is the one tuned to the actual flows of the organisation - what it normally sends to suppliers, what staff legitimately email home, what gets shared with which partners. A DLP that flags every external email becomes background noise that staff click through. A DLP tuned to find the unusual patterns provides real protection.

Email autofill is one of the largest single causes of accidental data leakage. The wrong client name in autofill, the right person at the wrong company, the address that has not been used in years. Tools that flag external recipients before sending and confirm unfamiliar contacts cut off the most common path.

Practical Compliance Guidance

Data leakage prevention is described in the IMS1 Manual in Section 8.2 alongside the Information Security Policy. 

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists.
PP-8-100 Information Security Policy Procedure Contains the Information Security Policy including the data handling rules that DLP enforces. 

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

For organisations handling significant volumes of sensitive data, yes - the volume of email and web traffic makes manual control infeasible. For smaller organisations, the default rules in modern email and cloud platforms (external sharing alerts, attachment warnings) may be sufficient. The choice should reflect the scale and the sensitivity.
DLP rules typically use classification labels or content patterns to identify sensitive content. Without consistent classification under A.5.12 and labelling under A.5.13, the DLP can only rely on content matching, which is less reliable. Classification and DLP work best together.
Through the incident management process under A.5.24-A.5.27. Personal data leakage is also assessed against UK GDPR breach notification thresholds, which require notification to the ICO within 72 hours where the threshold is met. The personal data register and incident process should both be configured for this.

Further Resources

payment logos