Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.8.12 Data Leakage Prevention

Control Objective

Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information.

Policy Statement

anDREa mitigates the risk of unauthorized data exfiltration, disclosure, or accidental sharing of its sensitive assets through a defensive, layered security architecture. While centralized, automated Data Loss Prevention (DLP) software suites are not actively deployed, data integrity is maintained by combining strict access controls, robust encryption baselines, network segregation, and managed collaboration environments.


Layered Defense-in-Depth Mechanisms

To safeguard information assets classified as High / Confidential under A.05.12 - Classification of information, anDREa relies on the following structural security controls to minimize data exposure:

  • Identity & Access Governance: System boundaries are hardened via Role-Based Access Control (RBAC) and explicit need-to-know limitations, ensuring that only authenticated and authorized personnel can reach data repositories (see A.05.15 - Access control).
  • Cryptographic Safeguards: Data is rendered unreadable to unauthorized actors via mandatory encryption standards. This includes full-disk encryption at rest for endpoints and cryptographic transport protocols for data in transit (see A.08.24 - Use of cryptography).
  • Endpoint Protection: Corporate and BYOD hardware configurations are managed centrally to prevent data spillover onto unencrypted media or unauthorized local storage pools (see A.08.01 - User end point devices.
  • Network Isolation and Perimeters: Production platform environments, virtual machines, and databases are protected using dedicated cloud firewalls and strict network routing tables to block unauthorized external ingress and egress (see A.08.20 - Networks security, A.08.21 - Security of network services, and A.08.22 - Segregation of networks).
  • Containerized Collaboration Spaces: To control file-sharing parameters, corporate Google Shared Drives are restricted within the administrator console based on their intended audience. Drives are explicitly designated as either Internal Only (blocking external sharing) or Available for Externals where cross-organization collaboration is contractually validated.
  • Remote Security Handbooks: Specific data exfiltration boundaries for teleworking and international travel are detailed under A.06.07 - Remote working and A.07.09 - Security of assets off-premises.