Since the 2022 revision, Data Loss Prevention (DLP) is an explicit control in ISO 27001 (control 8.12). Yet many SMEs struggle with it: DLP sounds like expensive enterprise software, while auditors mainly want to see that you actually control data leakage through everyday channels. This article shows how to implement DLP pragmatically and make it auditable, without buying a heavy tool.
What does ISO 27001 require for DLP?
Control 8.12 asks you to take measures to prevent or detect unauthorised disclosure and extraction of sensitive information. Importantly, the standard prescribes no specific software. It is about the outcome — control over where sensitive data can leak — and about demonstrable evidence.
Start with data flows, not the tool
DLP without insight into your data is mopping with the tap running. First map:
- Which data is sensitive (personal data, customer data, source code, contracts).
- Where it lives (SaaS, email, endpoints, cloud storage).
- Through which channels it can leave your organisation (email, USB, downloads, SaaS sharing, AI tools).
Link this analysis to your risk register and your Annex A controls. That shows DLP is risk-driven.
Practical measures that count
For an SME, a handful of measures already deliver a lot of resilience — and audit evidence:
- Email: rules against sending attachments with sensitive patterns externally; warnings on external sharing.
- SaaS & cloud: restrict sharing settings (no “anyone with the link”), review external shares periodically.
- Endpoints: restrict or log USB storage, enforce disk encryption.
- AI tools: a policy for what may and may not be pasted into external AI services.
- Classification: a simple label scheme (public/internal/confidential) that drives measures.
What the auditor wants to see
Not necessarily an expensive DLP suite, but evidence: the policy, the configured rules (screenshots/exports), an overview of data flows, and proof that you review incidents and external shares periodically. A logged, repeatable approach weighs more than an unused tool.
Common mistakes
- Buying a tool without a policy — you miss the rationale and the reviews.
- Blocking everything — too strict leads to workarounds; balance with the business.
- Set once and forget — DLP rules age; schedule periodic evaluation.
Getting started
Start small: one data-flow analysis, three concrete rules, and a DLP paragraph in your policy. For most SME audits that is already a solid base. Want to know where your organisation stands with ISO 27001? Take the free readiness scan or review ISO 27001 certification.