Data Leakage Prevention - ISO 27001 Annex A Control
ISO 27001 Annex A 8.12
Most data leaks are accidents - the controls have to handle accidents as well as intent.
ISO 27001 Annex A 8.12 - Data Leakage Prevention
Data leakage covers all the ways sensitive information can leave the organisation - email to the wrong recipient, cloud storage configured too openly, removable media taken home, screenshots posted to chat tools, and the more deliberate exfiltration paths used in attacks. Most leaks are accidents rather than malicious; the controls need to address both.
Technical data loss prevention (DLP) tools can detect and block sensitive content in email, web traffic, and endpoint activity. They depend on classification working - the system can only protect what it can identify as sensitive. Implementing DLP works best where information is already classified and labelled in line with the wider classification scheme under A.5.12.
Procedural and cultural controls sit alongside the technical ones. Staff need to know what they can and cannot do with information at each classification level, and what to do when something goes wrong. Reporting near misses without blame helps the organisation learn from incidents that did not escalate.
The DLP that helps most is the one tuned to the actual flows of the organisation - what it normally sends to suppliers, what staff legitimately email home, what gets shared with which partners. A DLP that flags every external email becomes background noise that staff click through. A DLP tuned to find the unusual patterns provides real protection.
Email autofill is one of the largest single causes of accidental data leakage. The wrong client name in autofill, the right person at the wrong company, the address that has not been used in years. Tools that flag external recipients before sending and confirm unfamiliar contacts cut off the most common path.
Practical Compliance Guidance
Data leakage prevention is described in the IMS1 Manual in Section 8.2 alongside the Information Security Policy.
| alphaZ document | How to use it |
|---|---|
| ISO 27001 Toolkit | The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists. |
| PP-8-100 Information Security Policy Procedure | Contains the Information Security Policy including the data handling rules that DLP enforces. |
Note - all the above files can be downloaded with an alphaZ subscription.
