implement data loss prevention

Designs, implements, and evaluates technical controls, policies, and monitoring that prevent unauthorized disclosure, exfiltration, or modification of sensitive data across storage, processing, and transfer paths — including data discovery and classification, DLP rules, encryption/tokenization, access controls, secure connectors, and transfer protocols, plus integrity verification. Enforces data boundary and sovereignty constraints and operationalizes continuous data integrity monitoring, secure integration, and compliance controls to detect and mitigate leakage or tampering.

implementdatalossprevention

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
1.48
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$197K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.

data breach preventiondata securityregulatory compliance

This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.

data protection regulationsprivacy complianceregulatory data protection requirements

This work addresses the critical gap that while AI-generated SQL queries may be semantically correct, they often violate data privacy and security policies, and current database systems lack fine-grained data flow control. The paper proposes Data Flow Control (DFC), a framework that embeds tuple-level security policies directly into the database infrastructure for the first time. DFC employs a declarative policy language to specify constraints and formalizes the security of aggregate predicates using provenance monomials. Through the Passant query rewriting layer, DFC enables optimizer-agnostic, cross-DBMS-compatible policy enforcement with zero runtime overhead, without materializing provenance data. Experiments demonstrate that Passant incurs near 0% performance overhead across DuckDB, Umbra, PostgreSQL, DataFusion, and SQL Server, outperforming existing approaches by several orders of magnitude, thereby shifting data security from prompt engineering to native infrastructure guarantees.

AI AgentsData Flow ControlData Safety

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

This work addresses the vulnerability of data-driven security policies in software-defined networks (SDNs) to overreacting to anomalous traffic, which can lead to misclassification and degrade the performance of machine learning–based intrusion detection systems. To mitigate this issue, the authors propose Safeguard, a novel mechanism that introduces a set of allow rules derived from known benign traffic. These rules operate in conjunction with data-driven policies, enabling coordinated enforcement at the network edge to prevent unintended responses while simultaneously applying firewall rules against confirmed malicious traffic. By integrating this dual-layer approach, Safeguard effectively alleviates overblocking, significantly enhancing the robustness and accuracy of SDN security policies. Experimental evaluation through a prototype implementation demonstrates the efficacy of the proposed mechanism in dynamic SDN environments.

Data-driven PolicyIntrusion DetectionNetwork Security

Latest Papers

What's happening recently
View more

This study addresses the sequential decision-making challenge firms face under stringent regulatory regimes when balancing compliance costs against data value in cross-border data flows. The authors propose a regime-anchored decision support system that translates regulatory requirements into computable minimal compliance mappings and models weekly corporate decisions via a finite-horizon Markov decision process, treating compliance as a hard constraint rather than a penalty term. Innovatively integrating masked deep reinforcement learning with counterfactual path advantage analysis, the framework enables efficient optimization and interpretable decision-making while supporting transferability across jurisdictions. Experimental results demonstrate that the learned policies outperform baseline approaches, exhibit high interpretability and auditability, and uncover key behavioral patterns such as an “absorb–adjust” effect and dynamic shifts in localization boundaries.

compliance decisionscross-border data flowsdata governance

This work addresses the compliance challenges in federated data processing arising from heterogeneous cross-organizational access policies, regulatory discrepancies, and long-running workflows. To tackle these issues, the paper proposes a compliance-aware federated data processing framework that uniquely integrates large language models (LLMs) with a “policy-as-code” approach. This integration enables the automatic translation of natural language descriptions of legal and organizational compliance requirements into executable machine-interpretable policies. An orchestration engine then enforces these policies dynamically across end-to-end workflows. Evaluation of the prototype system demonstrates that the proposed method effectively harmonizes multi-source compliance rules, significantly enhancing both compliance assurance and deployment feasibility in federated environments.

Access PoliciesCompliance ManagementFederated Data Processing

This study addresses the challenge faced by small and medium-sized organizations in leveraging large language models (LLMs) for automated gap analysis between their security policy documents and compliance standards such as ISO/IEC 27002:2022, primarily due to limited access to high-compute resources. To bridge this gap, the work presents the first end-to-end benchmarking framework tailored for low-resource environments, integrating document parsing, control alignment, and semantic retrieval techniques to evaluate lightweight LLMs that operate without GPU acceleration or substantial memory. Experimental results demonstrate that these resource-efficient models maintain high accuracy and consistency across multiple real-world compliance assessment tasks comparing organizational policies against ISO/IEC 27002:2022, thereby facilitating the practical deployment of lightweight AI solutions in cybersecurity governance.

automated compliance checkingcybersecurity complianceinformation security governance

This work addresses the prevalent issue of over-privileged access control policies that violate the principle of least privilege, often leading to security misconfigurations. To mitigate this, the authors propose a novel method that automatically refines policy rules by analyzing historical access logs and rewriting permission rules in the Amazon Cedar policy language. The approach ensures that system functionality remains unchanged while significantly tightening granted permissions. This study presents the first automated realization of the least privilege principle in practice, demonstrating its effectiveness in two real-world scenarios: it substantially reduces the scope of permitted access, thereby enhancing security, without disrupting normal system operations.

access control policyaccess logleast privilege

Hot Scholars

AM

Animesh Mukherjee

Professor of Computer Science, IIT Kharagpur, FNAE, Distinguished Member, ACM
Language dynamicsComplex systems and networksweb social media
SZ

Savvas Zannettou

Assistant Professor at Delft University of Technology
Computational Social ScienceArtificial IntelligenceHate SpeechMisinformation
HY

Hongzhi Yin

Professor and ARC Future Fellow, University of Queensland
Recommender SystemGraph LearningSpatial-temporal PredictionEdge Intelligence
JY

Junchi Yan

FIAPR & ICML Board Member, SJTU (2018-), SII (2024-), AWS (2019-2022), IBM (2011-2018)
Computational IntelligenceAI4ScienceMachine LearningAutonomous Driving
AR

Alain Ryser

PhD Student, ETH
Computer ScienceMedical Data ScienceMachine Learning