Digital Rights Management (DRM)

Protection that travels with content: the file is encrypted and a policy, checked each time it is opened, controls who may view, edit, print, copy or forward it, even after distribution.

Digital Rights Management protects the content rather than where it is stored. The file is encrypted, and a policy or licence, checked when someone tries to open it, decides whether that person may view, edit, print, copy or forward it, and for how long. Rights can usually be revoked after the file has been sent. Applied to business documents rather than media and entertainment, the same approach is commonly called Information Rights Management (IRM). The ISC2 outline names DRM among the data protection methods under objective 2.6.

DRM is easily confused with the two other methods named beside it. Data Loss Prevention tries to stop sensitive data leaving through the channels it monitors, but generally has no further control once a file has left them. A Cloud Access Security Broker enforces policy on traffic between users and cloud services. DRM is designed to keep working after the file has left, because protection is tied to encryption and to an identity check at each open. Its limits are practical: users need a compatible client, and anyone allowed to view content can still photograph the screen.

Exam relevance: a scenario is likely to describe sensitive files that must stay controlled after being shared outside the organisation. Candidates are expected to choose DRM for control after distribution and DLP for stopping data at the boundary.