← Home

OPEN-ACCESS RESOURCE · PDF, 10 PAGES

DLP Proof Kit: from test trace to board report

Preview of the DLP Proof Kit: egress channel matrix and board report templateOpen access · 10-page PDF

The essentials in 30 seconds

  • 7 templates to fill in plus pre-audit checkpoints, in a 10-page PDF.
  • For CISOs, DLP leads and compliance teams preparing an ISO 27001 (8.12), NIS2, UK NIS or DORA review, or a management review.
  • The templates are filled in by hand or in your spreadsheet: you do not need Enforcis to use them.
  • Three pages are below, readable with no form. The full PDF is sent by email.

What is in the kit

Template What it is for
01 · Egress channel matrix Map the routes by which data can leave your organisation, and the control meant to act on each one.
02 · Test scenario sheet Write each scenario and its expected result before you run it.
03 · Campaign log Log each replayed scenario, dated, in the same format at every campaign.
04 · Microsoft Purview™ validation matrix Apply the tests to the 5 Purview locations, after 4 checks to make first.
05 · Gap register and action plan Rank the gaps by data sensitivity and ease of the action, fix, then retest.
06 · Board report template One page for leadership: blocking rate, open channels, time to fix, decisions requested.
07 · Mapping to your frameworks Link each piece of evidence to ISO 27001, NIS2, DORA and GDPR.
+ · Pre-audit checkpoints Eight boxes to tick before the audit or the committee.

Preview, page 2: “How do you know it works?”

That is the question the auditor asks on reaching control 8.12 in your Statement of Applicability. In other words, it is also the question behind NIS2 Article 21(2)(f), behind DORA for financial entities, and the one your CFO asks in committee. A console screenshot shows that a rule exists. It does not show that a file was stopped.

This kit brings together the templates we recommend for moving from configuration to proof: a dated test trace, per channel, obtained with synthetic data, then followed by corrective action and, where needed, a retest.

What declares, what demonstrates

Type of evidence Examples What it demonstrates
Policy Data leakage prevention policy, classification rules Intent and scope
Configuration Export of DLP rules, mail filters, egress controls That controls exist
Logs Alerts, blocks, incidents handled That the tool reacts to some real events, the ones it saw
Test traces Controlled exfiltration scenarios, replayed and dated, per channel, with synthetic data How the controls reacted to the scenarios actually tested, within the scope and at the time of the test
Action plan Gaps found, priority, owner, fix date, retest Continual improvement (ISO 27001, clause 10)

A simplified reading grid: 3 states per tested scenario

State What it means and what to do
Blocked The transmission of the synthetic data was blocked. Check separately that the event was logged and that the alert reached the SOC with the expected context.
Detected, not blocked The transmission got past the control, but an alert was observed. Decide whether this channel warrants blocking and record how long the alert took to be picked up.
Not detected The data was observed getting through with no alert identified. Fix as a priority, according to the sensitivity of the data and of the channel.

The examples in this kit are typical scenarios, not customer cases.

Preview, template 01: egress channel matrix

List the routes by which data can leave your organisation and, for each one, the control that is meant to act. This list forms the basis of your coverage matrix. Coverage is only established as scenarios are actually tested. Without a written pass criterion, the assessment has nothing to measure against.

Egress channel Actions to test (examples)
Endpoint: removable media Copy a synthetic file to a USB stick, then to an encrypted external drive
Endpoint: printing, clipboard Print a “Confidential” document; copy and paste into an unauthorised application
Mobile endpoint Same actions off the corporate network, working remotely without VPN
Outbound email Send to a personal address; ZIP attachment, then password-protected ZIP; Bcc; image or scanned PDF
Encrypted web (HTTPS) Upload to a file transfer service; destination not categorised by the proxy; TLS inspection coverage
DNS Exfiltration through queries to an external domain
Personal cloud storage Sync to a personal Dropbox or OneDrive; sharing through a public link
Collaboration tools File posted in a Teams or Slack channel open to external guests
Business SaaS applications Bulk download from a business application
Generative AI assistants Pasting sensitive content into Copilot, Gemini or a web form
Out of scope Same file from an unenrolled device or an unmanaged browser

In the PDF, each row also has columns for the control meant to act, the pass criterion, the date of the last test and the result (blocked; detected, not blocked; not detected).

Preview, template 07: mapping to your frameworks

The same traces serve several files. No tool makes you compliant: these documents provide elements of evidence of effectiveness, on the scenarios actually tested, for one specific risk: data leakage.

Framework What you will be asked for Kit templates
ISO 27001 · A 8.12 (data leakage prevention) Measures applied to systems, networks and devices, and tangible evidence that they are effective 01, 02, 03
ISO 27001 · A 5.12 (classification) Classified information, with labels that the tools actually use 01, 04
ISO 27001 · 9.1, 9.3, 10 How you evaluate effectiveness; measurement results in management review; gaps addressed 03, 06, 05
NIS2 · Art. 21(2)(f) Policies and procedures to assess the effectiveness of measures: dated test results, a history over several months 02, 03, 05
NIS2 · Art. 21(2)(a) and Art. 20 Channels linked to the risk analysis; management bodies that approve the measures and oversee their implementation 01, 06
DORA · Art. 5, 9, 10, 13 An accountable management body; protection and prevention; detection of anomalous activities; learning and evolving 06, 03, 05
DORA · Art. 24 and 25 A risk-based testing programme; scenario-based tests, alongside audits and TLPT 02, 03
GDPR / UK GDPR · Art. 32 A process for regularly testing, assessing and evaluating the effectiveness of security measures 03, 05

NIS2 is an EU directive (Directive (EU) 2022/2555): Article 21 sets the measures, and each Member State transposes it into national law. In the United Kingdom, the applicable framework is the Network and Information Systems Regulations 2018 (UK NIS). Check the text that applies to each of your entities before making any decision. This kit is not legal advice.

Get the full kit (10 pages)

The PDF adds the scenario sheet, the campaign log, the Microsoft Purview matrix, the gap register, the board report template and the pre-audit checkpoints.

Get the DLP Proof Kit by email

    Next step

    Rather see a campaign than fill in the templates by hand?

    A 30-minute demo: a campaign replayed across the channels covered by the demo scenario, on our demo environment. What gets out of your own network, on the scenarios tested, is what a pilot on a limited production scope shows you.

    How your egress controls actually behave, observed scenario by scenario.

    With synthetic payloads, we run controlled campaigns on the configured paths and observe how your controls actually behave, scenario by scenario.