ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.12 Data leakage prevention

ISO 27001 Annex A 8.12 Data leakage prevention

What is ISO 27001 Annex A 8.12 – Data Leakage Prevention?

ISO 27001 Annex A 8.12 focuses on preventing the unauthorized disclosure, transfer, copying, or extraction of information from an organization.

Data leakage can happen intentionally or accidentally.

Examples include:

  • An employee emailing a confidential customer file to a personal email address
  • Uploading company documents to an unauthorized cloud-storage service
  • Copying sensitive information to a USB drive
  • Sharing confidential information through public links
  • Uploading source code to an external AI or collaboration tool without authorization
  • Sending customer PII to the wrong recipient
  • Downloading large amounts of customer data
  • Copying production data into an uncontrolled development environment
  • Sharing screenshots containing sensitive information
  • An attacker extracting information after compromising an account

Simple Explanation

Know what information must be protected, where it can go, who can send it, and how to detect or prevent unauthorized movement.


Why is Data Leakage Prevention Important?

Organizations can lose sensitive information without experiencing a traditional “hack.”

A legitimate employee account can be used to:

  • Download customer records
  • Copy source code
  • Export financial information
  • Send confidential documents
  • Upload data to an external service
  • Share files publicly

The account may be valid, but the information transfer may not be authorized.

Example

A support employee downloads 50,000 customer records to investigate an issue.

The employee then stores the file on a personal Google Drive.

There may have been:

  • No malware
  • No compromised password
  • No firewall attack
  • No unauthorized login

Yet sensitive information has still leaked.

Simple Principle

A valid user does not automatically have the right to move sensitive information anywhere they want.


What Does Annex A 8.12 Require?

The organization should implement appropriate measures to prevent data leakage based on:

  • Information classification
  • Business requirements
  • Risk
  • Data sensitivity
  • User roles
  • Access requirements
  • Technology environment
  • Remote working
  • Cloud services
  • Regulatory requirements
  • Customer requirements
  • Third-party relationships

The organization should consider how sensitive information can leave its controlled environment and implement appropriate preventive and detective measures.

ISO 27001 does not require every organization to deploy an enterprise DLP product.

The control should be implemented proportionately to the organization’s risks.


What is Data Leakage?

Data leakage occurs when information is exposed, transferred, copied, shared, or made available to an unauthorized person, system, location, or organization.

Examples:

ScenarioPossible Leakage
Employee emails confidential file externallyYes
Public cloud-storage linkYes
Source code copied to personal repositoryYes
Customer data uploaded to unauthorized SaaSYes
Lost unencrypted laptopPotential leakage
Sensitive screenshot posted publiclyYes
Wrong email recipientYes
Unauthorized database exportYes

Data leakage can be:

Accidental

Example:

Employee sends the wrong customer spreadsheet to another customer.

Intentional

Example:

Employee deliberately copies confidential company information before leaving.

Malicious

Example:

Compromised account downloads thousands of customer records.

Technical

Example:

Misconfigured cloud storage exposes customer files publicly.


Data Leakage vs Data Breach

These terms are related but not identical.

Data leakage generally refers to unauthorized exposure, transfer, disclosure, or loss of information.

A data breach may be a security incident involving unauthorized access, disclosure, alteration, loss, or other compromise of protected information, depending on the applicable legal or contractual definition.

Organizations should use their applicable legal, regulatory, and contractual definitions when determining whether an incident constitutes a reportable breach.


Common Data Leakage Channels

A startup should identify how information can leave the organization.

Email

  • Personal email
  • External recipients
  • Wrong recipient
  • Unapproved attachments

Cloud Storage

  • Personal Google Drive
  • Dropbox
  • OneDrive
  • Public links
  • Unapproved file-sharing services

Messaging Platforms

  • Slack
  • Microsoft Teams
  • WhatsApp
  • Other collaboration platforms

USB and Removable Media

  • USB drives
  • External HDDs
  • External SSDs
  • Memory cards

Web Uploads

  • File-sharing websites
  • Personal cloud storage
  • External forms
  • Unapproved applications

Source Code

  • Personal GitHub repositories
  • Unauthorized repositories
  • External development platforms

Printing

  • Confidential documents
  • Unattended printouts
  • Unauthorized copies

Screenshots and Photography

  • Customer information
  • Security dashboards
  • Source code
  • Credentials
  • Internal documents

AI Tools

Employees may accidentally paste:

  • Customer information
  • Source code
  • Contracts
  • Credentials
  • Internal architecture
  • Security reports

into unauthorized AI services.

Organizations should establish rules for using AI services according to their information-security and data-protection requirements.


Activities Required to Implement Annex A 8.12

1. Identify Sensitive Information

Start with information classification.

Examples:

  • Customer PII
  • Financial information
  • Payment information
  • Employee information
  • Source code
  • Security information
  • Credentials
  • Business strategy
  • Contracts
  • Intellectual property

This connects directly with A.5.12 – Classification of Information.


2. Identify Where Sensitive Data Exists

Create a data inventory or data-flow map.

Example:

Customer
   ↓
Application
   ↓
Production Database
   ↓
Backup
   ↓
Analytics
   ↓
Support
   ↓
Development / Testing
   ↓
Third Parties

For each location, ask:

How can this information leave the environment?


3. Identify Data Leakage Channels

Create a simple leakage-channel register.

ChannelExample RiskControl
EmailExternal disclosureEmail security/DLP
USBData copyingDevice controls
Cloud storagePublic sharingCASB/DLP/access control
Git repositorySource-code leakageRepository controls
BrowserUnauthorized uploadWeb controls
PrintingPhysical disclosurePrinter controls
MessagingSensitive information sharingPolicy/monitoring
AI toolsSensitive prompt/data uploadAI usage policy
ScreenshotsVisual disclosurePolicy/technical controls

4. Define Information Handling Rules

Employees should understand what they can and cannot do with sensitive information.

For example:

Confidential Customer Data

Allowed:

  • Approved business applications
  • Authorized employees
  • Approved support processes
  • Approved storage locations

Not allowed:

  • Personal email
  • Personal cloud storage
  • Public links
  • Personal USB drives
  • Unauthorized applications

5. Apply Access Restrictions

Data leakage prevention starts with access control.

Users should only receive access to information required for their role.

Relevant controls include:

  • A.5.15 Access Control
  • A.5.18 Access Rights
  • A.8.2 Privileged Access Rights
  • A.8.3 Information Access Restriction

The less unnecessary information a user can access, the less information they can accidentally or intentionally leak.


6. Control External Sharing

Cloud applications make information sharing extremely easy.

Examples:

Internal File
     ↓
Share Button
     ↓
Anyone With Link
     ↓
Potential Data Leakage

Organizations should define appropriate rules for:

  • External sharing
  • Public links
  • Guest users
  • External collaboration
  • File downloads
  • File exports
  • Sharing sensitive information

7. Control Removable Media

Where sensitive information can be copied to removable media, consider:

  • USB restrictions
  • Approved USB devices
  • Encryption
  • Device controls
  • Authorization
  • Logging
  • Malware protection
  • Secure disposal

This connects with A.7.10 – Storage Media.


8. Monitor High-Risk Data Transfers

Depending on risk, monitor activities such as:

  • Large downloads
  • Bulk exports
  • External file sharing
  • Uploads to unauthorized destinations
  • Sensitive email attachments
  • Unusual data transfers
  • Source-code exports
  • Database exports

Monitoring should be proportionate to risk and should also consider privacy and applicable employment/legal requirements.


9. Implement DLP Technology Where Appropriate

For organizations with higher data-leakage risks, DLP solutions can help identify and control sensitive information movement.

Potential DLP areas include:

  • Endpoint DLP
  • Email DLP
  • Cloud DLP
  • SaaS DLP
  • Network DLP
  • Browser controls
  • USB/device controls

However:

DLP software is a tool, not the control by itself.

An effective program also requires:

  • Data classification
  • Policies
  • Access control
  • User awareness
  • Monitoring
  • Incident response
  • Review

10. Configure Detection Rules

Example DLP rules:

RuleExample Action
Credit-card pattern sent externallyAlert/block
Large customer database exportAlert
Confidential document shared publiclyAlert/block
Source code uploaded to personal repositoryAlert/block
Sensitive file copied to USBAlert/block
PII sent to unauthorized domainAlert
Bulk download from CRMAlert

These are examples, not mandatory ISO 27001 settings.


11. Define Response Procedures

When a possible leakage event occurs:

Detect
  ↓
Validate
  ↓
Assess Information
  ↓
Determine Impact
  ↓
Contain
  ↓
Investigate
  ↓
Collect Evidence
  ↓
Notify Appropriate Parties
  ↓
Recover
  ↓
Learn and Improve

Relevant controls include:

  • A.5.24 Incident Management Planning and Preparation
  • A.5.25 Assessment and Decision on Information Security Events
  • A.5.26 Response to Information Security Incidents
  • A.5.27 Learning from Information Security Incidents
  • A.5.28 Collection of Evidence

Startup Example

Example: 60-Person SaaS Company

The startup stores customer information in:

  • AWS
  • PostgreSQL
  • CRM
  • Google Workspace
  • Support platform
  • Analytics platform

Employees also use:

  • Slack
  • GitHub
  • Laptops
  • Mobile devices
  • AI tools

Risk

A developer exports customer information to investigate a production issue and uploads the file to a personal cloud-storage account.

Poor Model

Production
    ↓
Full Export
    ↓
Developer Laptop
    ↓
Personal Cloud

Better Model

Production
    ↓
Minimum Required Data
    ↓
Masked Data Where Appropriate
    ↓
Approved Development Environment
    ↓
Controlled Access
    ↓
Secure Deletion

Where technical DLP is appropriate:

Sensitive Data
      ↓
Attempted External Upload
      ↓
DLP Detection
      ↓
Alert / Block
      ↓
Security Review

Data Leakage Prevention Matrix

A startup can maintain a simple matrix:

InformationChannelRiskPreventive ControlDetective Control
Customer PIIEmailHighDLP/access rulesEmail monitoring
Source codeGitHubHighRepository restrictionsAudit logs
Financial dataCloud storageHighSharing restrictionsActivity monitoring
Employee recordsUSBMedium/HighUSB restrictionsEndpoint logs
Security reportsAI toolsHighAI usage policyCASB/DLP where applicable
Customer ticketsSupport platformMediumRBACAccess logs

Data Leakage Risk Assessment

ScenarioLikelihoodImpactRiskTreatment
Customer PII emailed externallyMediumHighHighDLP + policy
Source code copied to personal repoMediumHighHighRepository controls
Public cloud linkMediumHighHighSharing restrictions
USB data copyingLow/MediumHighMedium/HighDevice controls
Wrong email recipientMediumMediumMediumUser awareness + controls
Unauthorized AI uploadEmergingHighHighAI usage rules + controls

Risk ratings should be based on the organization’s own risk methodology.


Data Leakage Prevention for Remote Workers

Remote working increases the number of locations from which information can be accessed.

Consider:

  • Company-managed endpoints
  • Device encryption
  • Screen locking
  • MFA
  • Secure Wi-Fi
  • VPN where appropriate
  • Cloud access controls
  • External sharing restrictions
  • USB controls
  • Secure printing
  • Privacy screens where appropriate
  • Employee awareness
  • Lost-device reporting

This connects with A.6.7 – Remote Working and A.7.9 – Security of Assets Off-Premises.


Data Leakage Through Email

Email is one of the most common accidental leakage channels.

Example:

Employee
   ↓
Attaches Customer Database
   ↓
Wrong Recipient
   ↓
Email Sent
   ↓
Potential Data Leakage

Possible controls include:

  • DLP
  • External-recipient warnings
  • Attachment restrictions
  • Sensitive-data detection
  • Encryption where appropriate
  • User confirmation for external recipients
  • Security awareness

Data Leakage Through Cloud Storage

Cloud collaboration creates another important risk.

Example:

Confidential File
      ↓
Google Drive
      ↓
"Anyone With Link"
      ↓
External Access

Appropriate controls can include:

  • Restrict public links
  • Restrict external sharing
  • Require approved accounts
  • Review guest users
  • Monitor sensitive file sharing
  • Apply DLP rules where appropriate
  • Periodically review sharing permissions

Data Leakage Through Source Code

For technology companies, source code is a critical information asset.

Potential leakage routes include:

  • Personal repositories
  • Public repositories
  • Unapproved SaaS tools
  • Developer laptops
  • USB devices
  • Screenshots
  • Logs
  • CI/CD artifacts

This connects strongly with A.8.4 – Access to Source Code.


Data Leakage Through AI Tools

Modern organizations should specifically consider AI-assisted work.

Employees may copy:

Customer Data
Source Code
Contracts
Security Reports
Credentials
Internal Architecture

into an AI service.

Organizations should establish rules covering:

  • Which AI tools are approved
  • What information can be entered
  • What information must not be entered
  • Enterprise vs personal accounts
  • Customer-data handling
  • Source-code handling
  • Confidential information
  • Security credentials
  • Review and monitoring requirements

A simple rule for employees can be:

Do not enter confidential, customer, personal, credential, or proprietary information into an AI service unless the organization has explicitly approved that use.


Data Leakage Prevention and Data Masking

A.8.11 and A.8.12 work together.

A.8.11

Mask sensitive information.

A.8.12

Prevent unauthorized leakage of information.

Example:

Production Customer Data
        ↓
A.8.11 – Mask Sensitive Fields
        ↓
Approved Test Environment
        ↓
A.8.12 – Prevent Unauthorized Export

Audit Evidence for Annex A 8.12

An auditor may request:

Governance

  • Data Leakage Prevention Policy
  • Information Security Policy
  • Data Classification Policy
  • Acceptable Use Policy
  • Data Handling Procedure
  • Remote Working Policy
  • AI Usage Policy

Technical Controls

  • DLP configuration
  • Email DLP settings
  • Endpoint DLP
  • Cloud DLP
  • CASB controls
  • USB restrictions
  • Cloud-sharing restrictions
  • Browser controls
  • Repository controls

Monitoring

  • DLP alerts
  • Security logs
  • File-sharing reports
  • Bulk-export alerts
  • Cloud activity reports
  • Endpoint events

Operational Evidence

  • Data leakage incidents
  • Investigation records
  • Incident-response tickets
  • Corrective actions
  • User training
  • Periodic reviews

ISO 27001 Annex A 8.12 Audit Checklist

QuestionYes/NoEvidence
Is sensitive information identified?Data inventory
Is information classified?Classification records
Are data leakage risks assessed?Risk assessment
Are important leakage channels identified?Leakage-channel register
Are external sharing rules defined?Policy
Is access to sensitive information restricted?Access matrix
Are removable media risks addressed?Device/media controls
Are cloud-sharing permissions controlled?Cloud configuration
Are high-risk data transfers monitored?Logs/reports
Is DLP technology used where appropriate?DLP configuration
Are employees trained?Training records
Are AI data-sharing risks addressed?AI usage policy
Are data leakage incidents reported and investigated?Incident records
Are DLP rules periodically reviewed?Review records
Are exceptions documented and approved?Exception register

Common Mistakes

1. Buying DLP Software and Stopping There

DLP technology without classification, policies, ownership, and response processes will not provide a complete control environment.


2. No Data Classification

If the organization does not know what information is sensitive, it becomes difficult to protect it effectively.


3. Allowing “Anyone With the Link”

Public cloud-sharing links can create unnecessary exposure.


4. Ignoring SaaS Applications

Data can leak through:

  • CRM
  • Support systems
  • HR platforms
  • Analytics
  • Collaboration tools
  • AI services

5. Ignoring Developers

Source code, customer data, credentials, and production exports can be highly sensitive.


6. Ignoring Accidental Leakage

Not every incident involves a malicious employee.

Wrong recipients and accidental sharing are common scenarios organizations should consider.


7. Blocking Everything

Overly aggressive DLP can disrupt legitimate business operations.

Controls should be risk-based and practical.


8. No Incident Response

Detecting a potential leakage event is only the beginning.

The organization needs a process for:

Detect → Assess → Contain → Investigate → Respond → Learn


9. No Evidence

A policy saying “employees must not leak information” is not enough.

Auditors will look for evidence that controls are actually implemented.


Practical Startup Implementation Model

A startup can use the following approach:

Step 1 – Identify

Identify sensitive information.

Step 2 – Classify

Determine sensitivity and handling requirements.

Step 3 – Map

Identify where information is stored and where it can go.

Step 4 – Restrict

Apply least privilege and appropriate access controls.

Step 5 – Prevent

Use policies and technical controls to prevent inappropriate transfers.

Step 6 – Detect

Monitor important leakage scenarios.

Step 7 – Respond

Investigate and contain suspected leakage.

Step 8 – Review

Improve controls based on incidents, changes, and risk.

Identify → Classify → Map → Restrict → Prevent → Detect → Respond → Improve


Startup Minimum Viable DLP

A small startup does not necessarily need an expensive enterprise DLP platform on day one.

A practical starting point can be:

Governance

  • Information Classification Policy
  • Data Handling Policy
  • Acceptable Use Policy
  • AI Usage Policy
  • Data Leakage Prevention Procedure

Access

  • MFA
  • Least privilege
  • Role-based access
  • Restricted external sharing

Endpoint

  • Device encryption
  • Endpoint protection
  • Screen lock
  • USB controls where appropriate

Cloud

  • Restricted public links
  • Controlled external sharing
  • Access reviews
  • Audit logging

Development

  • Source-code access controls
  • Repository restrictions
  • Secret scanning
  • Controlled production-data usage

Monitoring

  • Security alerts
  • Cloud audit logs
  • DLP capabilities where justified
  • Bulk-export monitoring

Response

  • Data leakage incident procedure
  • Investigation process
  • Evidence collection
  • Corrective actions

Policy vs. Process vs. Evidence

LayerExample
PolicySensitive information must not be shared through unauthorized channels
ProcessEmployees follow an approved process for external data sharing
Technical ControlDLP blocks or alerts on prohibited transfers
EvidenceDLP logs, approvals, alerts, incident records
ReviewPeriodic review of leakage risks and DLP rules

A strong ISO 27001 implementation connects all five.


Relationship With Other ISO 27001 Controls

A.8.12 does not operate in isolation.

A.5.10 – Acceptable Use

Defines acceptable use of information and assets.

A.5.12 – Classification of Information

Determines which information requires stronger protection.

A.5.14 – Information Transfer

Addresses secure transfer of information.

A.5.15 – Access Control

Defines access-control requirements.

A.5.18 – Access Rights

Manages user access rights.

A.5.19–5.22 – Supplier Security

Addresses information risks involving suppliers.

A.5.34 – Privacy and Protection of PII

Addresses protection of personal information.

A.7.9 – Assets Off-Premises

Addresses physical assets outside organizational premises.

A.7.10 – Storage Media

Addresses storage media handling.

A.8.1 – User Endpoint Devices

Protects endpoints from which data may be copied or transferred.

A.8.3 – Information Access Restriction

Restricts access to information.

A.8.4 – Access to Source Code

Protects source code from unauthorized access.

A.8.11 – Data Masking

Reduces exposure of sensitive information.

A.8.15 – Logging

Provides records that can support detection and investigation.

A.8.16 – Monitoring Activities

Supports monitoring of relevant security events.


A.8.12 vs A.8.11

ControlPrimary Question
A.8.11 Data MaskingHow can we hide sensitive information when the original is not required?
A.8.12 Data Leakage PreventionHow can we prevent unauthorized information from leaving the organization?

Example:

Mask customer data before giving it to developers → A.8.11

Prevent developers from uploading customer data to personal cloud storage → A.8.12


A.8.12 vs A.5.14

ControlFocus
A.5.14 Information TransferProtect information during authorized transfer
A.8.12 Data Leakage PreventionPrevent unauthorized disclosure or extraction

Example:

Sending a confidential contract to an approved customer through an approved secure channel:

A.5.14

Employee uploading the same contract to a personal cloud account:

A.8.12


A.8.12 vs A.8.3

ControlFocus
A.8.3Restrict access to information
A.8.12Prevent unauthorized leakage/extraction

Access restriction reduces the number of people who can access sensitive information.

DLP helps address what happens when someone attempts to move or disclose information.


Questions an Auditor May Ask

1. What information is considered sensitive?

Show your classification framework.

2. What are your major data-leakage risks?

Show your risk assessment.

3. How can employees transfer sensitive information?

Explain email, cloud, USB, messaging, repositories, AI tools, and other relevant channels.

4. How do you prevent unauthorized external sharing?

Show policies and technical controls.

5. Do you use DLP?

If yes, demonstrate it.

If no, explain the risk-based justification and alternative controls.

6. Can employees share company files publicly?

Show cloud-sharing configuration.

7. How do you control source-code leakage?

Show repository access and monitoring.

8. How do you handle AI tools?

Show AI usage/data-handling requirements.

9. What happens when potential data leakage is detected?

Show the incident-response workflow.

10. How do you know the controls are working?

Show:

  • Alerts
  • Logs
  • Reviews
  • Incidents
  • Testing
  • Management reporting

Useful Resources

Organizations implementing Annex A 8.12 may maintain:

  1. Data Leakage Prevention Policy – [Insert Draft Document Link]
  2. Data Handling Policy – [Insert Draft Document Link]
  3. Information Classification Policy – [Insert Draft Document Link]
  4. Data Transfer Procedure – [Insert Draft Document Link]
  5. External Data Sharing Procedure – [Insert Draft Document Link]
  6. DLP Configuration Standard – [Insert Draft Document Link]
  7. Data Leakage Risk Assessment – [Insert Draft Document Link]
  8. Data Leakage Channel Register – [Insert Draft Document Link]
  9. Cloud Sharing Review Checklist – [Insert Draft Document Link]
  10. AI Usage and Data Protection Policy – [Insert Draft Document Link]
  11. Data Leakage Incident Procedure – [Insert Draft Document Link]
  12. DLP Review Checklist – [Insert Draft Document Link]
  13. Data Leakage Audit Checklist – [Insert Draft Document Link]

Startup-Focused Quick Summary

For a startup, begin by answering five questions:

1. What information would hurt us if leaked?

Customer data, source code, credentials, financial information, contracts, employee data, etc.

2. Where does that information exist?

Cloud databases, SaaS platforms, laptops, repositories, email, backups, analytics, etc.

3. How could it leave?

Email, cloud sharing, USB, downloads, screenshots, repositories, AI tools, vendors, etc.

4. What controls prevent it?

Access control, classification, policies, endpoint controls, cloud controls, DLP, monitoring, user awareness.

5. What happens if it occurs?

Detect → Assess → Contain → Investigate → Respond → Learn.


Startup-Focused Final Takeaway

ISO 27001 Annex A 8.12 is not simply about installing a Data Loss Prevention (DLP) product.

It is about understanding:

What information is sensitive → Where it exists → Who can access it → Where it can go → How unauthorized movement is prevented or detected.

For a modern SaaS startup, data leakage can happen through:

Email + Cloud Storage + Endpoints + Source Code + APIs + Vendors + Messaging + AI Tools + Human Error

A practical implementation can start small and mature as the organization grows.

Simple Startup Model

Know your sensitive data. Limit who can access it. Control where it can go. Detect unusual movement. Respond quickly when something goes wrong.

One-Line Summary

ISO 27001 Annex A 8.12 requires organizations to implement appropriate measures to prevent unauthorized disclosure, transfer, copying, or extraction of information, using a combination of classification, access control, policies, technical controls, monitoring, and incident response.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *