DLP
DLP Controls
Technische und organisatorische DLP-Maßnahmen — inkl. GenAI-Spezifika für Prompt Data Leakage und Model Exfiltration.
Note: This page is an original compilation of practical implementation guidance for DORA. It serves exclusively for internal structuring and planning and does not claim completeness or legal bindingness. No legal advice is provided.
🖥️ Endpoint DLP
- · USB-Sperre für klassifizierte Daten
- · Clipboard-Monitoring (Copy-Paste verhindern)
- · Druckkontrolle für vertrauliche Dokumente
- · Screen-Capture-Blockade
- · Device Control (keine privaten Geräte)
- · Browser-Plugin für KI-Prompt-Überwachung
🌐 Network DLP
- · Deep Packet Inspection für Datenexfiltration
- · SSL/TLS-Entschlüsselung (Decryption Proxy)
- · Cloud Access Security Broker (CASB)
- · Data-in-Motion-Überwachung
- · Anomalie-Erkennung für Datenabflüsse
- · API-Traffic-Analyse für KI-Dienste
☁️ Cloud DLP
- · SaaS-Datenklassifizierung (M365, Google Workspace)
- · Shadow-IT-Erkennung inkl. Shadow-AI
- · API-basierte DLP für Cloud-Anwendungen
- · Datenresidenz-Prüfung
- · Automatische Verschlüsselung bei Cloud-Upload
- · KI-Dienst-Whitelist (erlaubte KI-APIs)
📧 Email DLP
- · Mail-Inhaltsprüfung (Attachment, Body, Header)
- · Automatic Quarantine bei Policy-Verstoß
- · Encryption für externe Empfänger
- · BCC-Regeln für Führungskräfte
- · DMARC/SPF/DKIM-Validierung
- · KI-generierte E-Mail-Erkennung
🤖 GenAI Prompt DLP
- · Prompt-Inhaltsprüfung auf vertrauliche Muster
- · PII/API-Key/Passwort-Erkennung in Prompts
- · Quellcode-Erkennung vor API-Send
- · Data-Classification-Awareness-Popup
- · Prompt-Logging für Forensik
- · Sandbox-Umgebung für KI-Tests
🧠 GenAI Output DLP
- · Output-Validierung auf Trainingsdaten-Ähnlichkeit
- · PII-Redaction in KI-Outputs
- · Memorization-Tests (Garak)
- · Differential Privacy-Metriken
- · Content-Watermarking (C2PA)
- · Synthetic-Content-Kennzeichnung