ISO 27001A.8 — Data leakage prevention
A.8.12
Data leakage prevention
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Apply measures to reduce the risk of unauthorized disclosure and extraction of information.
Points of focus
- Identify high-risk exfil channels
- Control egress and sharing
- Monitor anomalous exports
- Train on handling rules
Implementation notes
Block public buckets by policy. Restrict external sharing defaults. Alert on bulk PII exports from admin tools. For regulated customers, evaluate DLP on email/endpoints proportionate to risk. Assign a named owner in the SoA, tie operating evidence to dlp/casb policy screenshots, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show sharing defaults, bucket policies, and one alert investigation. Explain residual risk accepted.
Evidence auditors typically request:
- DLP/CASB policy screenshots
- Sharing restriction settings (Drive/Slack)
- Egress firewall rules
- Investigation tickets for anomalous exports
Common gaps
- Unlimited personal email forwarding
- Public S3 buckets
- No alerts on bulk customer exports
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.12 | This control |
| SOC 2 | CC6.7 | Related SOC 2 themes (CC6.7) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.312(e) | Related HIPAA themes (§164.312(e)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.12)
Frequently Asked Questions
Risk-based — many SaaS startups start with IAM, sharing controls, and monitoring before full DLP suites.
Technical DLP rarely stops screenshots; combine with policy and least privilege.
Masking reduces useful data if leaked; DLP tries to stop the leak path.
Even without owned data centers, data leakage prevention still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with dlp/casb policy screenshots, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.