Data Leakage Prevention Adoption Model & DLP Maturity Level Assessment
Mohammed A. Alsuwaie, Babak Habibnia, Pavel Gladyshev · 2021
Data is the most valuable resource organizations possess. Nowadays, intentional and unintentional data leakages to unauthorized entities have dramatically increased in the private and government sectors for different reasons and purposes. Data leak poses a severe threat to the data security of these organizations. In the private sector, such leakage can damage the reputation of a business and weaken its competitiveness, while a leakage in the government sector can severely impact its public and diplomatic relationships and even threaten national security. Therefore, private and government sectors have recently strived to adopt the Data Leakage Prevention (DLP) program to enhance data security and minimize data leakage. However, some organizations limit their DLP programs to DLP technology implementation. DLP technology represents only a part of the whole process and does not include other essential elements such as planning, policy, process, data ownership and classification, data access control, training, and awareness. A comprehensive adoption of these elements might prevent data leakage. This research paper aims to provide a model for DLP adoption and address the most critical elements of the DLP Adoption Model, which are correlated with the DLP Maturity Level Assessment, the “DLP Maturity Level Grid,” to measure the success of the model.