Phase 3: Policy & Controls

Develop comprehensive DLP policies, configure detection rules, and establish incident response procedures

Duration: 4-6 months
Team: 5-7 members

Phase Overview

The Policy & Controls phase translates your data discovery findings into actionable protection measures. This phase involves creating comprehensive DLP policies, configuring detection rules aligned with PDPA requirements, establishing incident response procedures, and developing user training programs.

Key Objective

Create enforceable policies and technical controls to prevent data loss

Success Criteria

Approved policies, configured DLP rules, and trained user community

Deliverables

Policy documents, DLP rules, incident response playbook, training materials

Key Activities

1. Develop DLP Policies

Create comprehensive data protection policies aligned with PDPA and business requirements.

Tasks:

  • Define acceptable use policies for sensitive data
  • Create data sharing and transfer policies
  • Document data retention and disposal policies
  • Establish email and removable media policies
  • Get legal and compliance review and approval

Policy Templates: Access ready-to-use Policy Templates aligned with PDPA requirements.

2. Configure Detection Rules

Set up technical controls using data patterns and classification rules.

Tasks:

  • Configure content inspection rules using Sri Lankan data patterns
  • Set up context-based rules (sender, receiver, classification)
  • Define actions (block, alert, encrypt, quarantine)
  • Configure exception handling and workflow approvals
  • Test rules thoroughly in monitor mode before enforcement

3. Establish Incident Response

Create processes for responding to and managing DLP incidents.

Tasks:

  • Define incident severity levels and escalation procedures
  • Create incident response playbooks for common scenarios
  • Establish incident investigation and remediation workflow
  • Set up PDPA breach notification procedures
  • Define roles and responsibilities for incident response team

4. Develop User Training

Create comprehensive training program to educate users on data protection.

Tasks:

  • Create awareness materials on data protection and PDPA
  • Develop role-specific training modules
  • Create quick reference guides and FAQs
  • Set up Data Champions program for departmental support
  • Schedule initial training sessions for all staff

Data Champions: Learn about our Data Champions Program to build internal expertise.

5. Deploy Endpoint Controls

Implement DLP agents on user endpoints to monitor and control data.

Tasks:

  • Configure endpoint DLP agents for laptops and desktops
  • Set up USB/removable media controls
  • Configure clipboard and screen capture controls
  • Deploy cloud application controls (CASB integration)
  • Test endpoint controls in pilot group

6. Configure Network Controls

Set up network-level DLP controls to monitor data in transit.

Tasks:

  • Deploy email DLP gateway for outbound scanning
  • Configure web gateway DLP for HTTP/HTTPS traffic
  • Set up FTP and file transfer monitoring
  • Configure SSL/TLS inspection where appropriate
  • Integrate with SIEM for centralized logging

DLP Policy Framework

Data Handling Policy

Guidelines for creating, storing, sharing, and disposing of sensitive data

Download Template →

Email Security Policy

Rules for sending sensitive data via email, including encryption requirements

Download Template →

Removable Media Policy

Controls for USB drives and external storage devices

Download Template →

Incident Response Policy

Procedures for reporting and handling data loss incidents

Download Template →

Phase Deliverables

DLP Policy Suite

Complete set of approved data protection policies

Configured DLP Rules

Technical controls deployed and tested in monitor mode

Incident Response Playbook

Step-by-step procedures for handling DLP incidents

Training Materials

User awareness and training content for all roles

Data Champions Network

Trained departmental representatives ready to support rollout

Baseline Metrics

Initial data loss risk metrics for measuring improvement

Resources & Templates

Ready for Phase 4?

With policies approved and controls configured, you're ready to begin pilot deployment.