KU SEC 06 - Data Loss Prevention Policy


Data Loss Prevention (DLP) Policy (Simplified)

Table of Contents

1. Overview

The Data Loss Prevention (DLP) Policy safeguards Kean University data from unauthorized sharing, storage, or exposure. It requires approved platforms, safe data handling, and monitoring to prevent data loss, leaks, or misuse. This policy supports compliance with FERPA, GLBA, HIPAA, GDPR, CCPA, and NIST CSF standards.

2. Who Must Follow This Policy?

This policy applies to anyone who creates, accesses, stores, or sends Kean University data, including:

  • Faculty and staff
  • Students with system or data access
  • Contractors, consultants, interns, and student workers
  • Third‑party vendors and partners

3. What Systems and Data Are Covered?

Systems & Services

  • University‑managed devices (laptops, desktops, mobile devices)
  • BYOD devices accessing Kean data
  • On‑premises servers and cloud services (SaaS, PaaS, IaaS)
  • Email, messaging, collaboration, and file‑sharing platforms

Data Types

All data classifications, including:

  • Public
  • Internal
  • Confidential
  • Restricted (FERPA, GLBA, HIPAA, research data)

Data Transfer Methods Covered

  • Cloud file storage or sharing
  • Email and messaging attachments
  • Uploads/downloads on the web
  • USB drives and removable media
  • Copy/paste and printing
  • API‑based data transfers

4. Key DLP Requirements

Expand Key DLP Requirements

4.1 Use of File‑Sharing Services

  • Personal cloud/file‑sharing services may not be used to store or share Kean data.
  • Only Kean‑approved tools may be used (e.g., OneDrive for Business, SharePoint, Kean‑managed SFTP).

4.2 Approved Platforms

  • Kean IT maintains a list of approved platforms.
  • Confidential and Restricted data must remain on platforms that enforce:
    • Encryption
    • Access control
    • Logging

4.3 Technical Controls

  • DLP tools may monitor or block:
    • Uploads to personal cloud platforms
    • Unauthorized data transfers via email or web
    • Data copied to removable media
  • Automated systems may block or quarantine suspicious activity.

4.4 Monitoring & Logging

  • DLP alerts and events are logged through SIEM tools.
  • Kean IT investigates alerts based on risk.

4.5 Training & Awareness

  • Annual training on secure file‑sharing and data handling is required.
  • Training covers phishing defense and safe handling of Restricted data.

4.6 Data Handling

  • Confidential and Restricted data must be encrypted at rest and in transit.
  • Data may only be shared externally when authorized and when proper agreements are in place.

4.7 Reporting Suspected Data Loss

  • Possible data loss, exposure, or unauthorized storage must be reported immediately.
  • All DLP incidents follow the Incident Response Plan.

4.8 Review of DLP Controls

  • Kean IT reviews DLP controls, alerts, and exceptions annually or after major incidents.

5. Roles & Responsibilities

Expand Roles & Responsibilities

Employees, Contractors, and Students

  • Use only approved file‑sharing tools.
  • Follow all DLP requirements.
  • Report suspected violations immediately.

Managers & Supervisors

  • Ensure team compliance.
  • Ensure required training is completed.
  • Escalate issues to Kean IT as needed.

Kean IT – Information Security

  • Maintain the list of approved services.
  • Configure and operate DLP tools.
  • Investigate alerts and enforce controls.
  • Manage DLP exceptions.

Kean IT – Risk Management

  • Ensure DLP risks are included in the enterprise risk register.
  • Support risk reviews for exceptions.

Internal Audit

  • Audit DLP controls and compliance.

Vendors & Partners

  • Must follow Kean University DLP requirements when handling Kean data.

6. Enforcement

Failure to comply with this policy may result in warnings, mandatory training, system‑access restrictions, HR actions, vendor contract enforcement, or required regulatory reporting.

7. Exceptions

Exceptions must follow the Exception Management Policy and must be:

  • Submitted in writing
  • Risk‑assessed
  • Approved by Information Security (and CIO for high‑risk)
  • Logged in the Exception Register
  • Reviewed quarterly

DLP‑specific exceptions may not exceed 90 days without reevaluation and cannot exceed 12 months total.

  • RC01 – Policy Governance Standard
  • KU SEC 10 – Cybersecurity & IT Governance Standard
  • Data Classification Policy
  • Information Security Policy
  • Access Management Policy
  • Acceptable Use Policy
  • Incident Response Plan
  • Exception Management Policy

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.