HTML5
The term HTML5 is essentially a buzzword that refers to a set of modern web technologies. This includes the HTML Living Standard, along with JavaScript APIs to enhance storage, multimedia, and hardware access.
https://developer.mozilla.org/en-US/docs/Glossary/HTML5
Over the past 10 years HTML is now used for ~95% of websites (https://w3techs.com/technologies/history_overview/markup_language/ms/y) of which HTML5 is used by ~91% of websites (https://w3techs.com/technologies/details/ml-html5)
Using Cybersecurity controls to block access to online resources based upon Categorisation, Deny Lists, Firewall rules etc is not effective as Data Loss Prevention technologies.
The use of this upload method demonstrates it is trivial for anyone that has access to a web browser and the internet, to easily move sensitive/confidential data outside of organisations.
The likelihood of such a Data Loss risk event occurring must be considered.
The impact of a Data Loss risk event will depend on the content and amount of information that has been uploaded via HTML5 method.
Use DLP-TEST to assess: -
- Coverage of DLP Technologies to detect data being uploaded via the HTML5 method.
- Capability of DLP Technologies to accurately detect sensitive/confidential data being uploaded via the HTML5 method.
- Ability of DLP technologies to ignore data being uploaded that is NOT sensitive or confidential.