Train workforce members to be aware of causes for unintentional data exposure. Example topics
include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to
unintended audiences.
The organization enhances data security awareness by training employees on best practices for handling sensitive data securely, demonstrating the risks of portable device loss, guiding secure document sharing, and raising awareness about public sharing pitfalls. Regular security drills and open incident reporting channels further reinforce the importance of safeguarding data.
Data Loss Prevention (DLP) policies can be used to protect sensitive data from accidental or intentional disclosure. Policies can alert, for example, when they detect sensitive data (such as personal identification numbers or credit card numbers) in email or another data system to which they would not belong.
The organization defines DLP policies related to endpoints in a risk-based manner, taking into account the data classification of the processed data.