組織は、不満を抱いた従業員がファイルをアップロードして大量の PII データを盗み出したことを発見しました。組織がこのリスクを軽減するために検討すべきコントロールは次のうちどれですか?
正解:D
DLP stands for data loss prevention, which is a set of tools and processes that aim to prevent unauthorized access, use, or transfer of sensitive data. DLP can help mitigate the risk of data exfiltration by disgruntled employees or external attackers by monitoring and controlling data flows across endpoints, networks, and cloud services. DLP can also detect and block attempts to copy, print, email, upload, or download sensitive data based on predefined policies and rules.