Skip to content

Data Loss Prevention Policy

Data loss prevention POLICY

Version history

Version Number Date Description Created By Approved By
0.1 23/Apr/2024 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Purpose

The purpose of this policy is to detect and prevent the unauthorized transmission or disclosure of tecciance confidential / sensitive information.

This document also extends and provides specificity to the tecciance Information Security Policy regarding data loss prevention (DLP) and digital rights management. This shall also serve as the authority for future development of additional operational procedures, standards and guidance that may become necessary to enhance protection of tecciance.

Scope

The scope of the DLP program shall include tecciance’s data originating or accessed from, or transiting through tecciance information systems, to include tecciance owned and operated mobile devices (cell phones, tablets, etc.) and home-based devices (e.g., “telework” devices and systems) regardless of physical location.

This is applicable to boundaries and scope of tecciance Infrastructure where tecciance data resides, and the infrastructure can fall under the scope of data leakage.

Policy

Data Loss Prevention

The Chief Technology Officer (CTO) shall establish a Data Loss Prevention (DLP) program to prevent data loss and manage digital rights. The DLP program shall focus on identifying, developing, implementing, and managing controls and processes that enable and leverage digital rights management protections to help prevent the loss of data.

Regarding DLP program functions, the CTO shall:

  • Develop, implement, and oversee a DLP governance structure.

  • Identify and maintain sensitive information characteristics to enable information labelling and tracking.

  • Coordinate with business owners and technology team to develop, operate, and maintain processes to review and adjudicate detected possible data leakage.

  • Evaluate protections’ effectiveness.

  • Create, capture, and use performance metrics to improve procedures, processes, and controls.

  • Ensure awareness through outreach and training.

  • The CTO shall help to define, build, implement and maintain a DLP solution that enables information labelling and the detection of and prevention of confidential / sensitive data leakage.

  • The DLP solution shall be capable of detecting and preventing leakage from the tecciance network to the Internet or other external entities outside the tecciance boundary, between network enclaves within the enterprise network, from endpoint and mobile devices and from cloud solutions to include encrypted traffic at a minimum.

Information Classification

Information classification identifies, in broad terms, characteristics that will be used to prevent the loss of sensitive data. Classification is recurring and data classifications will change over time.

The CTO shall help to:

  • Develop a data classification scheme that is consistent with the data classification policy of tecciance.

  • Define data characteristics.

  • Protect data classes (not individual data elements).

  • Identify information owners (IO) and users.

  • Utilize DLP data discovery scans to gather data characteristics, wherever possible.

  • Define and identify approved storage systems.

  • Catalog data locations and approved transmission, storage and use locations.

DLP Discovery

Data discovery identifies what the data is, where it resides and how it is utilized at tecciance. This information is used to define data characteristics, data types and data classifications further. Discovery results also assist with the identification of sensitive data. Meta data that results from the data discovery is integrated into the DLP policy.

DLP Monitoring

Monitoring shall occur on a continuous basis and information gathered shall be used to refine data characteristics and classifications. The CTO shall develop and implement DLP controls and procedures for monitoring information in-use, in transit and at rest for indicators of compromise and policy violations. An organization needs to monitor user activity and safeguard confidential data while it is at rest, in use, and in motion.

DLP Protection

tecciance shall put in place controls to minimize loss of data. These controls address the common data use cases: in-use, in-motion, at-rest, and possible loss modes including but not limited to destruction, disappearance, leakage, and theft.

Response to Indicators of Compromise or Violation of Policy

Indicators of compromise and violation of policy and procedures shall be treated as and reported as an information security incident. Incident reporting shall conform to procedures outlined in tecciance Incident Response Policy and Procedure.

The CTO shall, as needed, develop additional procedures that facilitate effective reporting and remediation of data loss incidents. Additionally, the CTO shall develop metrics to measure the effectiveness of the incident response procedures. Information transmissions and downloads that violate tecciance policy and procedures shall be blocked. Sensitive information discovered on unapproved storage devices and on approved devices in violation of policy shall be removed from those devices moved to approved and appropriate devices.

Awareness

An effective DLP program depends upon an informed user community. Awareness is an element of the DLP program. DLP awareness training will be offered in two ways:

  • Stand-alone classes on DLP will be developed, and

  • DLP capabilities will be interwoven into other tecciance training initiatives as appropriate.

The CTO, in conjunction with HR, shall develop an awareness plan. The awareness plan shall define communication methods used by the tecciance to inform all users of tecciance DLP and digital rights management initiatives and requirements. The CTO shall develop, disseminate, and distribute DLP awareness training content and materials. Training content and materials shall address both management and users.

Terms & Definitions

Terms

Definitions

DLP

Data loss prevention (DLP) is a set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.  

Data Owner

An individual or entity that has approved management responsibility for controlling the production, development, maintenance, use and security of information is referred to as a Data Owner. 

CTO

Chief Technology Officer

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

DLP and monitoring cover uploads to generative-AI services and knowledge-index ingest, not only email and USB.