Skip to main content
Table of Contents
< All Topics
Print

Data-centric Security

Initial Publication Date: 07 June 2024

Abstract

Data-centric security is crucial for protecting sensitive information, ensuring compliance with data privacy regulations, and enabling secure collaboration. Organizations must adopt this approach to safeguard their most valuable asset—data—maintain customer trust and adapt to the evolving data landscape.

Data-centric security emphasizes the protection of data itself rather than traditional system, network and perimeter defenses. This approach embeds security controls directly at the data source, applies granular access controls, and continuously monitors data usage. It addresses the challenges posed by cloud computing, remote work, AI-generated data and IoT by ensuring consistent data protection across diverse environments.

Key benefits include enhanced data privacy and transparency, improved incident resilience, and regulatory compliance. Treating data as a valuable asset, as defined by “Infonomics,” involves managing, measuring, and monetizing information to unlock its full potential.

However, implementing data-centric security presents challenges such as accurate data classification, encryption key management, and integration with legacy systems. Future trends highlight a shift towards data safety, increased adoption of inside-out security models, and the integration of AI/ML for enhanced security capabilities.

This report lays out the steps, tools, workflows, and policies necessary to implement a data-centric security strategy while highlighting the business benefits associated with developing a robust and diverse data portfolio.

Authors:

Gary Zimmerman

Principal Consulting Analyst

[email protected]

 

 

Executive Summary

Introduction

Data-centric security focuses on safeguarding data itself rather than relying solely on traditional network or perimeter defenses. This approach embeds security controls directly at the data source, employs granular access controls, and continuously monitors and audits data usage. Key principles include protecting data throughout its lifecycle, applying risk-based security measures, and leveraging automation to ensure consistent protection.

Importance of Data-Centric Security

In the era of cloud computing, remote work, mobile access, and IoT, the traditional network perimeter is increasingly difficult to define and defend. Data is also harder to control and growing immensely thanks to generative AI. Data now resides in various environments and needs to be accessed by multiple stakeholders, making data-centric security crucial for maintaining protection across these diverse and often unsecured environments.

Key Benefits

  1. Data Privacy and Transparency: Enhanced controls like encryption and access restrictions protect customer data privacy, building trust. Automated auditing provides visibility into data handling, demonstrating responsible data use.
  2. Incident Resilience: Data-centric protections, such as encryption, mitigate the impact of data breaches, helping retain customer trust.
  3. Regulatory Compliance: Automated auditing, data loss prevention (DLP), and classification features help organizations comply with regulations like GDPR, proving a commitment to proper data practices.

Why Data-Centric Security?

With the dissolution of traditional network perimeters, the focus has shifted to securing the data itself wherever it lives. This approach involves moving access decisions closer to the data, ensuring only authorized users can access it, and making data encryption seamless and user-friendly. Concepts like “zero trust” emphasize continuous verification and robust data protection strategies to counter sophisticated cyber threats.

Data as a Valuable Asset

Data drives innovation, improves decision-making, enhances customer experience, generates new revenue streams, and provides a competitive advantage. Treating data as an asset, or “Infonomics,” involves managing, measuring, and monetizing information to unlock its full potential.

Challenges and Future Trends

Implementing data-centric security poses several challenges, such as accurately identifying and classifying data, managing encryption keys, balancing security with usability, and integrating with legacy systems. Future trends include a shift towards data safety over traditional data security, increased adoption of inside-out security models, application-level data protection, and the integration of AI/ML for enhanced data security capabilities.

Conclusion

Data-centric security is essential for protecting an organization’s most valuable asset—data. It ensures compliance with data privacy regulations, enables secure collaboration, and supports agile business needs. Organizations must embrace this approach to safeguard sensitive data, maintain customer trust, and adapt to the evolving data landscape.

Introduction

Data-centric security refers to a security approach that focuses on protecting data itself, as opposed to traditional network or perimeter-focused security. The key principles of data-centric security are:

  • Protecting data at the source: Security controls are embedded where the data lives, such as databases, servers, applications, etc. This allows security to persist even as data moves.
  • Granular access controls: Fine-grained access controls are applied to specific data objects, limiting access to only authorized users. Things like encryption, tokenization, and rights management help control access.
  • Monitoring and auditing usage: Activity monitoring provides visibility into how data is being accessed and used. Data usage audits can identify suspicious access patterns.
  • Data lifecycle management: Policies and procedures are implemented to secure data throughout its lifecycle – from creation, storage, use, sharing, to destruction.
  • Risk-based approaches: The level of security applied is proportional to data sensitivity and criticality. Higher risk data gets stronger protection.
  • Automation: Automating security processes like classification, encryption, auditing etc. ensures consistent data-centric protection.

The goal is to make data itself more secure, rather than relying solely on perimeter defenses. Data-centric security provides persistent protection that follows data wherever it goes.

In the era of cloud computing, remote work, mobile access, and the Internet of Things (IoT), data-centric security has become increasingly important because the traditional network perimeter is no longer a single, easily defined or defended boundary. Data now resides in cloud services, third-party servers, mobile devices, and often needs to be accessed by employees, partners, customers, and sometimes the public. Data-centric security helps ensure that protection is consistently maintained even as the data moves through these varied and potentially unsecured environments.

Data-centric security can positively impact brand trust in several ways:

  • Data Privacy: With data-centric controls like encryption and access restrictions, brands can better protect customer data privacy. This honors the customer relationship and builds trust.
  • Data Transparency: Automated data auditing provides brands with definitive visibility into how data is handled. This enables transparency if questions arise, demonstrating responsible data use.
  • Data Incident Resilience: If a brand suffers a data breach or cyberattack, data-centric protections like encryption mitigate the impact. Less data exposure retains more customer trust.
  • Regulatory Compliance: Features like DLP, classification, and automated auditing help prove brands comply with regulations like GDPR. Compliance demonstrates commitment to proper data practices.
  • Restored Trust: If an incident occurs, automated data security shows the brand took steps to protect data. This helps restore trust faster after a breach.
  • Data Value Focus: Data-centric security keeps the focus on data’s value, not just technology. This values-focused approach builds customer confidence.
  • Competitive Differentiator: Strong data stewardship via data-centric security differentiates brands that want to lead in trust. It signals authentic commitment.

Data-centric security is an approach that ensures the protection of data through its entire lifecycle, thereby reducing the risk of data breaches and ensuring compliance with data protection regulations. It fosters brand trust by helping validate brands as ethical data stewards committed to the customer and it demonstrates that trust and relationships are priorities, not just transactions. This approach is increasingly important in a world where data is a critical asset and is regularly shared and stored across a myriad of platforms and devices

Why Data-Centric Security?

Data is Becoming the New Perimeter

I know, I know… For years TechVision Research has called Identity the new perimeter. But Identity (the actor) is only a part of a robust security posture. Data (the resource) can be considered the new perimeter because traditional security measures, such as strong network perimeters, firewalls, and intrusion detection systems, are no longer sufficient to protect against sophisticated cyber threats. The focus has shifted to securing the data itself, as it is the primary target for cybercriminals. This approach involves moving access decisions closer to the data itself, ensuring that only authorized users have access, and making data encryption seamless and user-friendly. The concept of a “zero-trust network” emphasizes that security should not rely solely on perimeter defenses but should also include robust data protection strategies. This shift is driven by the increasing frequency and sophistication of cyberattacks, such as ransomware and double extortion, which target valuable and sensitive data. Therefore, securing the data itself has become paramount in safeguarding organizational assets and maintaining regulatory compliance.

This concept of “data as the new perimeter” fundamentally changes traditional security strategies in several ways:

  • Shifting from Network-Centric to Data-Centric Security: Traditional security approaches focused heavily on securing the network perimeter with firewalls, intrusion detection/prevention systems, and other network-based controls. However, with the rise of cloud computing, remote work, and the dissolution of the traditional network perimeter, this approach is no longer sufficient. The “data as the new perimeter” concept shifts the focus to securing the data itself, regardless of its location or the network it traverses.
  • Emphasizing Identity and Access Management: While data centric security is about securing the data wherever it lives, Identity and Access Management (IAM) is all about identifying who and what can access the data at a granular level. With data distributed across multiple environments and accessed from various locations, controlling who has access to sensitive data becomes paramount. IAM solutions, including Privileged Access Management (PAM), become critical components of the security strategy. Robust authentication, authorization, and access controls based on user identities and roles are essential for protecting data. The combination of securing the data and unambiguously identifying all resources are key elements of modern security.
  • Adopting Data-Centric Security Controls: Traditional perimeter-based security controls are inadequate for protecting data. Organizations must adopt data-centric security controls such as data encryption, data loss prevention (DLP), and data access governance. These controls ensure that data remains protected and accessible only to authorized entities, regardless of its location or the network it traverses.
  • Increasing Focus on Visibility and Analytics: With data dispersed across multiple environments, gaining visibility into data access, usage, and movement becomes crucial. Security analytics and monitoring tools that provide insights into data flows, user behavior, and potential threats are essential for detecting and responding to data breaches or misuse.
  • Embracing Zero Trust Principles: The “data as the new perimeter” concept aligns with the principles of the zero-trust security model, which assumes that no user or device should be trusted by default, regardless of their location or network. Every access request must be verified, authenticated, and continuously monitored based on the principle of least privilege.

By taking a data-centric security approach, organizations can better protect their most valuable assets – data – in today’s distributed and perimeter-less environments

Data is becoming the most valuable asset for digital enterprises

Why is data so valuable? Because it:

  • Drives Innovation: Data enables organizations to gain insights, identify new opportunities, and drive innovation in products, services, and business models. By analyzing data, enterprises can uncover patterns, trends, and customer preferences, allowing them to develop innovative solutions that meet evolving market demands.
  • Improves Decision Making: Data provides a factual basis for informed decision-making across all aspects of an organization. With access to accurate and timely data, businesses can make data-driven decisions that optimize operations, reduce costs, mitigate risks, and drive growth.
  • Enhances Customer Experience: Data allows enterprises to deeply understand customer behavior, preferences, and needs. This enables personalized experiences, targeted marketing, and tailored offerings, leading to increased customer satisfaction, loyalty, and revenue.
  • Generates New Revenue Streams: Data itself can be monetized as a product or service. Enterprises can leverage their data assets to create new revenue streams by selling data, insights, or data-driven products and services to third parties.
  • Enables Competitive Advantage: In today’s data-driven economy, the ability to effectively collect, analyze, and act on data is a key competitive differentiator. Organizations that excel at data management and analytics can gain a significant advantage over competitors by making better-informed decisions and responding more quickly to market changes.
  • Improves Security and Compliance: Data plays a crucial role in identifying and mitigating security threats, as well as ensuring compliance with regulations. By analyzing data patterns, enterprises can detect potential breaches, fraud, and other risks, enabling proactive measures to protect their assets and maintain regulatory compliance.

Leveraging data has become a critical success factor in today’s digital economy, and Infonomics is an approach leading enterprises are using to develop this valuable asset class.

Treating Data as an Asset, Infonomics

The concept of infonomics, treating information as a formal business asset, was first coined by Douglas B. Laney in the 1990s while he was an analyst at Gartner. Laney recognized that organizations were generating massive amounts of data but failing to properly value, manage and monetize this information asset. In the early 2000s, he began developing methods for quantifying the value of information assets and applying principles of asset management to data. His 2011 book “Infonomics” outlined the discipline in detail, including the three pillars of monetizing, managing and measuring information assets. Over the next decade, infonomics gained traction as more businesses realized the immense potential value locked in their data and the need for formal strategies to capitalize on it. By the 2020s, leading organizations across industries are adopting infonomics practices to drive revenue growth, cost savings and competitive advantages through their data.

Infonomics is the theory and discipline of treating information as an actual asset that can be monetized, managed, and measured like any other asset class. The core philosophy revolves around three key principles:

Manage Information

Just as companies rigorously manage physical and financial assets, they should establish formal practices to govern their information supply chains and lifecycles from acquisition to archival. This involves applying asset management principles like those used for other assets, leveraging frameworks like information supply chain management and knowledge management.

You Manage Information as an Asset by:

  • Establishing information supply chains and ecosystems to govern the flow of information
  • Applying asset management standards and approaches like those used for physical assets
  • Improving information management maturity through policies and best practices

Measure Information

To fully capitalize on information as an asset, its value must be quantified and accounted for as it would on the balance sheet. Economic principles can be adapted to calculate the cost, market value, and economic impact of information assets. Measuring information assets enables better investment decisions and highlights their importance to the business.

To properly value and account for information, organizations need to quantify it as an asset class. This can be done by:

  • Recognizing information’s economic properties that qualify it as an asset
  • Determining ownership and property rights over information assets
  • Adapting accounting principles to measure the intrinsic and business value of information
  • Applying economic concepts like pricing models to information assets

Appendix 1 describes the data classification measures defined in Infonomics. It helps you quantify the value of data.

Monetize Information

Organizations should look for ways to generate economic value from their information assets, beyond just selling raw data. This can involve using information to improve processes, products, and services, enable new data-driven offerings, or enhance decision-making capabilities. Some prime methods include analytics, information brokering, and packaging information into products.

Information can generate revenue streams and competitive advantages when properly monetized. Sample methods include:

Indirect Monetization

  • Improving process performance or effectiveness
  • Reducing risk/improving compliance
  • Developing new products or markets
  • Digitalizing current products or services
  • Building and solidifying partner relationships
  • Assetizing data on the balance sheet via special corporate structures
  • Publishing branded indices to promote data products/services

Direct Monetization

  • Bartering/trading data for non-cash commercial considerations
  • Licensing data through brokers or data markets
  • Selling insights, analysis, reports
  • Enhancing products or services with data
  • “Inverted” data monetization via referral/reseller arrangements
  • Collateralizing data to secure loans

By following the principles of Infonomics to manage, measure and monetize information systematically, organizations can quantify and unlock the full potential of their data and treat it as the valuable asset it is.

Data has undoubtedly become the most valuable asset for digital enterprises, fueling innovation, driving decision-making, and enabling competitive advantages. However, the proliferation of data across distributed environments, cloud platforms, and remote workforces has also increased the risk of data breaches and unauthorized access. This is where data-centric security becomes crucial.

Data is constantly in motion and distributed across various environments

The constant motion and distribution of data across various environments is significantly impacting security through:

  • Increased Attack Surface: With data dispersed across multiple clouds, on-premises systems, devices, and geographies, the potential attack surface expands exponentially. More entry points and data stores mean more vulnerabilities that cybercriminals can potentially exploit to gain unauthorized access to sensitive information.
  • Lack of Visibility and Control: As data moves between different environments, it becomes challenging to maintain visibility into where sensitive data resides and who has access to it at any given time. This lack of visibility makes it difficult to implement effective access controls and data protection measures.
  • Data Replication and Sprawl: The need to replicate and distribute data for availability, performance, and backup purposes leads to data sprawl, with multiple copies of the same data existing across various locations. This increases the risk of data exposure and makes it harder to secure all instances of sensitive information.
  • Compliance and Regulatory Challenges: The distribution of data across different jurisdictions and environments can create compliance challenges, as organizations must adhere to varying data privacy and security regulations based on the location and type of data.
  • Increased Complexity: Managing security across a distributed data landscape requires coordinating multiple security tools, policies, and processes across different environments, which can lead to increased complexity, inconsistencies, and potential gaps in security posture.

To address these challenges, organizations must adopt a data-centric security approach that focuses on securing the data itself, regardless of its location or the environment it traverses.

Additionally, embracing the principles of zero trust security, which assumes that no user, device, or environment should be trusted by default, can help organizations better secure their distributed data assets by enforcing strict access controls and continuously validating trust levels based on contextual factors.

By adopting a data-centric, zero trust approach to security, organizations can better protect their sensitive data assets in today’s highly distributed and dynamic data environments.

Traditional security models are inadequate for protecting data

Traditional security models are increasingly inadequate for protecting data due to several limitations:

  • Lack of Granularity and Context: Traditional access control models, such as Discretionary Access Control (DAC), often lack the granularity needed to enforce fine-tuned access permissions. They typically do not incorporate contextual information, such as the user’s location, time of access, or device security posture, which are crucial for making informed access control decisions in dynamic environments.
  • Static and Rigid Policies: Traditional security models rely on static policies that are defined at the time of system configuration and rarely updated. This rigidity makes it difficult to adapt to changing access requirements, such as those in collaborative projects or multi-tenant cloud environments, leading to potential unauthorized access or data breaches.
  • Expanded Attack Surface: The proliferation of IoT devices, cloud computing, and edge computing has dramatically expanded the attack surface. Traditional perimeter-based security models, which focus on securing the network boundary, are insufficient for protecting data that is constantly in motion and distributed across various environments. These models fail to address the complexities and vulnerabilities introduced by modern IT deployments.
  • Insider Threats and Lateral Movement: Traditional security models often assume that threats originate from outside the network, granting broad access to users once they are inside the perimeter. This approach fails to address insider threats and the risk of lateral movement by attackers who have breached the perimeter defenses, leading to significant security gaps.
  • Inadequate for Modern Threats: Traditional security measures, such as firewalls and basic authentication, are not robust enough to protect against sophisticated cyber threats like ransomware, phishing, and advanced persistent threats (APTs). These measures often result in false positives and negatives, creating a “confidence crisis” where users cannot be sure of their security status.
  • Complexity and Management Overhead: Managing security across a distributed data landscape with traditional models can be complex and resource intensive. The need to coordinate multiple security tools and policies across different environments increases the risk of inconsistencies and potential security gaps.

Traditional security models that rely on perimeter-based defenses and implicit trust within the network are increasingly inadequate for protecting sensitive data in today’s distributed and cloud-based environments. With the rise of remote work, cloud adoption, and the proliferation of mobile devices, the traditional network perimeter has dissolved, creating a diverse landscape of endpoints that need to be secured. Legacy security controls are ill-equipped to handle the complexities of modern data flows, the risks of data exposure through unsecured channels, and the challenges of authentication and identity management in remote scenarios. Furthermore, traditional models often lack the scalability, performance, and advanced threat detection capabilities required to keep pace with the ever-evolving cyber threat landscape. Using a data-centric approach to security counteracts the shortcomings.

Organizations are recognizing the need to shift towards data-centric security approaches, including Zero Trust and Secure Access Service Edge (SASE), which move access decisions closer to the data and prioritizes the protection of data itself, regardless of its location or the devices and users accessing it, through continuous verification, granular access controls, and cloud-native security services.

Regulatory Compliance and Data Privacy

The data privacy regulatory landscape is rapidly evolving and becoming increasingly complex. With a proliferation of new state laws in the U.S., strengthening of existing regulations, increased enforcement activity, and global developments will significantly impact businesses’ privacy compliance obligations in 2024 and beyond. Traditional security measures are not equipped for this shifting landscape.

Proliferation of State Privacy Laws in the U.S.

In 2023, eight U.S. states (Florida, Texas, Oregon, Montana, Iowa, Delaware, Tennessee, and Indiana) passed comprehensive consumer data privacy laws, joining the ranks of California, Virginia, Colorado, Connecticut, and Utah.

In 2024, the laws in Montana, Texas, Florida, and Oregon are going into effect, substantially increasing the number of states with data privacy regulations.

Several other states like Maryland, New Hampshire, Nebraska, and Kentucky also enacted new privacy laws in 2024 that will take effect in 2025.

This proliferation of state laws is making privacy compliance increasingly fragmented and complex for businesses operating across multiple states.

Strengthening of Existing Laws

In addition to new state laws, existing privacy regulations like the CCPA in California are being strengthened through amendments and new rules issued by regulatory bodies like the California Privacy Protection Agency (CPPA). The CPPA issued new proposed regulations in late 2023 that expand requirements around mobile app privacy policies, the definition of sensitive data, and consumer rights to file complaints.

Increased Enforcement Activity

Enforcement of privacy laws by state attorneys general and the FTC is expected to ramp up significantly in 2024 as more state laws take effect and “right-to-cure” provisions sunset. The FTC has indicated AI regulation will be a major focus area, issuing guidance and launching investigations related to privacy and AI.

Global Privacy Developments

Internationally, new comprehensive privacy laws advanced in the UK, India, Indonesia, and Brazil in 2023, continuing the global trend toward stronger data protection regulations.

The EU’s new Trans-Atlantic Data Privacy Framework went into effect in 2023 to facilitate data transfers to the U.S. but has already faced legal challenges like previous frameworks.

Data-centric security enhances data privacy by providing persistent protection, granular access controls, data discovery and classification, lifecycle management, regulatory compliance support, and secure collaboration capabilities. This data-centric approach ensures sensitive data remains private regardless of its location or who accesses it.

Insider Threats and Third-Party Risks

Insider threats and third-party risks that pose significant challenges to data security:

Insider Threats:

Malicious Insiders: Disgruntled employees or contractors with legitimate access can intentionally steal, expose, or sabotage sensitive data for personal gain or to harm the organization.

Negligent Insiders:  Employees can unintentionally compromise data through careless actions like falling for phishing scams, misconfiguring systems, or failing to follow security protocols.

Credential Theft: Cybercriminals can target insiders to steal their credentials, enabling unauthorized access to systems and data.

Third-Party Risks

Supply Chain Attacks: Threat actors can target an organization indirectly by compromising less-secure third-party vendors or partners in their supply chain, using them as entry points (island hopping).

Data Exposure: Third-party vendors often require access to an organization’s sensitive data or systems to provide services, increasing the risk of data exposure if the vendor’s security is compromised.

Lack of Visibility: Organizations may have limited visibility into the security practices and access controls implemented by their third-party vendors, making it difficult to assess and mitigate risks effectively.

By adopting a data-centric security approach that focuses on securing the data itself, organizations can better protect against insider threats and third-party risks, while maintaining visibility and control over their sensitive data assets, regardless of their location or the environment they traverse.

Data-Centricity and Zero Trust

Data-centric security and zero trust are complementary approaches that together provide a robust and comprehensive security strategy. Here’s a comparison of the two:

Data-Centric Security:

  • Focuses on protecting the data itself, regardless of its location or the user/application accessing it
  • Employs techniques like encryption, tokenization, data masking, and granular access controls to secure sensitive data
  • Ensures data remains protected throughout its lifecycle, from creation to disposal
  • Provides persistent protection for data, even when it leaves the organizational boundaries
  • Aligns with data privacy regulations and enables secure data sharing and collaboration

Zero Trust:

  • Assumes no user, device, or network is inherently trusted by default
  • Implements strict access controls and continuously verifies user identities and contexts before granting access
  • Follows the principle of least privilege, only allowing the minimum necessary access
  • Reduces the attack surface by minimizing implicit trust zones and limiting lateral movement
  • Scrutinizes every access attempt, whether from inside or outside the network perimeter

While zero trust focuses on securing access and not implicitly trusting any user or device, data-centric security ensures that even if access is gained, the data itself remains protected and unusable without proper authorization. The two approaches complement each other:

  • Zero trust verifies user identities and contexts before granting access to data/resources
  • Data-centric security protects the data itself through encryption, access controls, and monitoring

Together, they create a layered defense that mitigates risks from both external threats and insider threats, while enabling secure data sharing and collaboration. The convergence of zero trust and data-centric principles is essential for addressing modern cyber threats and protecting sensitive data in today’s distributed and collaborative environments.

Data-centric Security and AI/ML

There is a strong and symbiotic relationship between data-centric security and artificial intelligence/machine learning (AI/ML) systems:

  • Data is the Fuel for AI/ML: AI and ML models rely heavily on large volumes of data for training and inference. As organizations increasingly adopt these technologies, ensuring the security and integrity of the data that powers AI/ML systems become paramount.
  • AI/ML Expands the Attack Surface: The integration of AI/ML into business processes and the need to provide these systems with broad data access introduces new attack vectors and expands the potential surface for data breaches and misuse.
  • Data-Centric Security Enables Secure AI/ML Adoption: By focusing on securing the data itself through measures like encryption, tokenization, data masking, and granular access controls, data-centric security approaches allow organizations to harness the power of AI/ML while mitigating the associated data risks.
  • AI/ML Enhances Data-Centric Security Capabilities: Conversely, AI and ML can augment data-centric security capabilities by enabling advanced threat detection, automated data classification, fine-tuned access policies, and powerful risk intelligence through analysis of massive datasets.
  • Continuous Monitoring and Adaptation: The rapid evolution of AI/ML technologies necessitates continuous monitoring and adaptation of data security measures to address emerging threats and risks associated with these advanced systems.
  • Regulatory Compliance: As AI/ML systems process and generate sensitive data, data-centric security measures are essential for ensuring compliance with data privacy regulations like GDPR, CCPA, and industry-specific requirements.
  • Ethical Considerations: Data-centric security plays a crucial role in addressing ethical concerns around AI/ML, such as privacy, bias, and responsible development, by ensuring the secure and transparent handling of data used in these systems.

The relationship between data-centric security and AI/ML is deeply intertwined. Data-centric security enables secure AI/ML adoption by protecting the data fueling these systems, while AI/ML capabilities can enhance data-centric security measures. This symbiotic relationship is critical for organizations to harness the power of AI/ML while mitigating associated data risks and ensuring regulatory compliance and ethical development.

Achieving Data-Centric Security

To achieve data-centric security, organizations need to implement a comprehensive approach that focuses on protecting data throughout its lifecycle, regardless of where it resides or how it is accessed. Here are the key steps and components required:

  • Data Discovery: Identify and locate all sensitive / valuable data assets across the organization’s systems, databases, cloud environments, and endpoints. Use data discovery tools to scan and classify data based on sensitivity levels and regulatory requirements.
  • Data Classification: Establish a data classification scheme that categorizes data based on its sensitivity and importance to the organization. Implement processes and tools for automatically classifying data and applying appropriate labels or tags.
  • Access Management: Define and enforce granular access controls and policies that govern who can access specific data assets based on their roles, responsibilities, and the principle of least privilege. Implement robust authentication and authorization mechanisms, such as multi-factor authentication and role-based access controls.
  • Data Protection: Encrypt sensitive data both at rest (in storage) and in transit (during transmission) using strong encryption algorithms and key management practices. Implement data masking, tokenization, or other obfuscation techniques to protect sensitive data from unauthorized access or exposure.
  • Data Monitoring and Auditing: Continuously monitor and audit all activities related to sensitive data, including access attempts, modifications, and data movements. Establish processes for detecting and responding to potential data breaches or unauthorized access incidents.
  • Data Governance: Develop and enforce data governance policies and procedures that define data ownership[1], data handling practices, and data retention and disposal rules. Implement data lineage and data provenance tracking to understand the flow and transformations of data throughout its lifecycle.
  • Integration and Automation: Integrate data-centric security solutions with existing security tools, such as data loss prevention (DLP), security information and event management (SIEM), and identity and access management (IAM) systems. Leverage automation and orchestration to streamline data protection processes and reduce the risk of human error.
  • Training and Awareness: Provide regular training and awareness programs to educate employees on data security best practices, policies, and their responsibilities in protecting sensitive data.

By implementing these components, organizations can establish a robust data-centric security posture that prioritizes the protection of sensitive data assets, regardless of their location or the systems and applications that handle them. It is important to note that achieving data-centric security is an ongoing process that requires continuous monitoring, updating, and adaptation to evolving threats and regulatory requirements.

Tools, Processes, and Policies for Success

To achieve success in data-centric security, organizations need to implement a comprehensive set of tools, processes, and policies. Key tools include data discovery and classification solutions to identify and categorize sensitive / valuable data assets, and data loss prevention (DLP) tools to monitor and protect data flows. Robust processes are required for data governance, including establishing clear policies for data handling, access controls based on sensitivity levels, and procedures for monitoring network activity and responding to threats. Effective data-centric security also necessitates implementing security controls like encryption, multi-factor authentication, and role-based access controls to protect data at rest and in transit. Maintaining a data-centric security strategy involves continuous monitoring, regular policy reviews, and updates to align with evolving business needs, regulatory changes, and technological advancements. This section highlights the tools, workflows, and policies that can help you be successful.

Tools

Data discovery and classification tools

Data discovery and classification tools are software solutions designed to automatically identify, categorize, and label sensitive data across an organization’s various data repositories. These tools play a crucial role in data governance, security, and compliance efforts. Here are the functions provided by data discovery and classification tools:

Data Discovery:

  • Scan and analyze structured data (databases, data warehouses), unstructured data (files, documents, emails), and semi-structured data (logs, JSON, XML) across on-premises, cloud, and SaaS environments.
  • Utilize techniques like pattern matching, machine learning, and optical character recognition (OCR) to detect sensitive data elements like personally identifiable information (PII), financial data, intellectual property, and more.
  • Provide visibility into where sensitive data resides, enabling organizations to understand their data landscape and associated risks.
  • Modern data discovery tools will highly leverage AI

Data Classification:

  • Automatically classify and label discovered data based on predefined policies, regulatory requirements (GDPR, HIPAA, PCI-DSS), and custom rules.
  • Assign classification levels or sensitivity labels (e.g., public, internal, confidential, restricted) to data based on its content and context.
  • Allow organizations to define their own classification taxonomies, information types, and data handling procedures based on business needs.

Key Capabilities:

  • Automated Discovery and Classification: Continuously scan data repositories and classify data without manual intervention, ensuring up-to-date visibility.
  • Customizable Policies and Rules: Define custom policies, rules, and data types to identify organization-specific sensitive data like intellectual property or industry-specific data.
  • Data Cataloging and Metadata Management: Create or interface with a centralized data catalog with metadata, classifications, and data lineage information for better data governance.
  • Risk Assessment and Prioritization: Identify high-risk data exposures, concentrations of sensitive data, and prioritize remediation efforts based on risk levels.
  • Integration with Data Security Solutions: Integrate with data loss prevention (DLP), access control, encryption, and other security solutions to enforce data protection policies.
  • Reporting and Auditing: Generate detailed reports on data classifications, exposures, and policy violations for compliance audits and risk assessments.

By implementing data discovery and classification tools, organizations can gain comprehensive visibility into their sensitive data, enforce data handling policies, reduce the risk of data breaches, and maintain compliance with various data protection regulations.

Some leading enterprise data governance tools include Microsoft Information Protection (MIP), Symantec (Veritas) Data Insight, Varonis Data Classification Engine, IBM Guardium Data Protection, Informatica Enterprise Data Catalog, and Fortra Classification Suite

These tools help organizations inventory their data assets, discover and classify data based on pre-defined taxonomies, and apply appropriate metadata and labels to the data.

Data Loss Prevention (DLP) Tools:

a DLP tool is a comprehensive security solution that combines data discovery, classification, monitoring, policy enforcement, incident response, reporting, and centralized management capabilities to protect an organization’s sensitive data assets across its entire IT infrastructure, including cloud environments.

Effective DLP tools should offer a comprehensive set of features for data discovery, classification, monitoring, protection, policy enforcement, reporting, and centralized management across the organization’s data assets.

Automated Data Discovery and Classification

  • Ability to automatically discover, inventory, and classify sensitive data across the organization’s systems, networks, endpoints, and cloud services using techniques like pattern matching, machine learning, and data fingerprinting.
  • Support for data classification across various file types, databases, and applications.

Comprehensive Data Monitoring

  • Monitor data in any state (at rest, in use, or in motion) across endpoints, networks, cloud services, and applications like email, web, messaging, and file sharing.
  • Analyze user behavior and data activity context to detect potential policy violations or suspicious actions.
  • Ability to monitor and inspect encrypted/SSL traffic.

Advanced Policy Enforcement and Incident Response

  • Enforce data handling policies by taking automated actions like blocking data transfers, encrypting data, quarantining files, or alerting administrators.
  • Provide incident-based user training and awareness to prevent future policy violations.
  • Integrate with security information and event management (SIEM) systems for incident reporting and response.

Centralized Management and Reporting

  • Central management server or console to configure policies, manage agents, and provide a unified view of the DLP deployment across the organization.
  • Generate detailed reports on data usage, policy violations, potential data leaks for auditing and compliance purposes.

Automation and Integration

  • Automated policy enforcement, remediation actions, and incident response workflows.
  • Integration with other security tools like data classification, encryption, access management, and cloud access security brokers (CASBs).

Cross-Platform and Cloud Support

  • Support for various operating systems (Windows, macOS, Linux) and deployment models (on-premises, cloud, hybrid).
  • Integration with cloud services and cloud-based DLP capabilities.

The latest DLP tools leverage advanced technologies like machine learning, data fingerprinting, and automation to provide comprehensive data discovery, classification, monitoring, protection, and reporting capabilities across an organization’s entire IT infrastructure, including cloud environments.

Some leading enterprise DLP tools include Symantec Data Loss Prevention, Palo Alto Networks Enterprise DLP, Forcepoint DLP, Cisco Cloudlock, and Microsoft Purview Adaptive Protection

DLP tools not only help classify data, but also monitor and control the flow of sensitive data, both within the organization and across the network perimeter.

Do you need both Data Discovery Data Loss tools?

Data discovery and classification tools, along with Data Loss Prevention (DLP) tools, have overlapping functionalities in identifying and classifying sensitive data within an organization. However, they differ in their primary objectives and capabilities.

Data Discovery and Classification Tools

The primary function of data discovery and classification tools is to locate and identify various data sources across an organization’s systems, databases, and cloud environments. These tools use techniques like pattern matching, machine learning, and predefined rules to classify the discovered data based on its sensitivity level or content type (e.g., personally identifiable information, financial data, intellectual property).

Key capabilities include:

  • Discovering known and unknown data sources
  • Classifying data based on sensitivity and risk profile
  • Mapping and visualizing data sources within the organization

Data Loss Prevention (DLP) Tools

DLP tools are designed to detect and prevent unauthorized access, transmission, or exfiltration of sensitive data. They rely on the data classification provided by data discovery tools to enforce policies and rules for protecting sensitive information.

Key capabilities include:

  • Monitoring data in motion (network traffic, emails, etc.) and data at rest (databases, file shares)
  • Applying predefined policies and rules based on data classification
  • Blocking or quarantining unauthorized data transfers
  • Generating alerts for potential data leaks or policy violations

Overlap in Functionality

While data discovery and classification tools focus on identifying and classifying data, DLP tools leverage this classification to enforce data protection policies. The two work in tandem, with data discovery providing the foundation for DLP tools to effectively monitor and secure sensitive data.

The overlap lies in the data classification aspect, where both types of tools employ techniques to identify and label sensitive data based on its content and context. However, DLP tools take this classification a step further by actively monitoring and preventing data loss incidents based on the assigned sensitivity levels.

Additionally, some DLP solutions may include basic data discovery and classification capabilities, blurring the lines between the two categories. However, dedicated data discovery and classification tools often offer more advanced and specialized features for comprehensive data mapping and risk assessment.

So, while data discovery and classification tools identify and classify sensitive data, DLP tools operationalize this information to actively protect against data loss incidents, making them complementary components of an organization’s overall data security strategy.

Cloud Access Security Brokers (CASB):

Cloud Access Security Brokers (CASBs) are security solutions that act as a gatekeeper between an organization’s users and cloud services, providing visibility, data security, threat protection, and control over cloud usage. CASBs sit between an organization’s on-premises infrastructure and cloud providers to monitor and control cloud access and usage. They enforce security policies like authentication, encryption, malware detection, and data loss prevention (DLP) for cloud applications and services. CASBs provide visibility into all cloud apps used (sanctioned and unsanctioned), enabling risk assessment and governance of cloud usage.

Key Capabilities of CASB Tools

  • Single sign-on and adaptive access control based on user, device, location, etc.
  • Data encryption and DLP to prevent unauthorized sharing of sensitive data.
  • Malware detection and threat prevention by analyzing user behavior and traffic.
  • Shadow IT discovery and risk assessment of unsanctioned cloud apps.
  • Compliance monitoring and reporting for regulations like GDPR, HIPAA, etc.

Some of the leading enterprise CASBs include Microsoft Defender for Cloud Apps, Broadcom Symantec CloudSOC CASB, Netskope CASB, Forcepoint CASB, Lookout CASB, Skyhigh Security CASB, and Palo Alto Networks CASB

CASBs have become essential for securing cloud adoption and ensuring regulatory compliance as organizations migrate more workloads and data to the cloud. They provide the necessary visibility, control, and data protection for safe cloud enablement.

CASB solutions can integrate with data classification tools to extend data-centric security policies and controls to cloud-based applications and data repositories.

Enterprise Data Governance Tools

Enterprise data governance tools help organizations establish and enforce data policies, standards, and processes across the entire data lifecycle. These tools typically provide the following capabilities:

  • Data lineage and impact analysis to understand data flow and dependencies.
  • Data quality monitoring and remediation to ensure data accuracy and completeness.
  • Access control and data masking for sensitive data protection and compliance.
  • Metadata management to capture and maintain data definitions and glossaries.
  • Workflow management for data-related processes like approvals and certifications.

Some leading enterprise data governance tools include Collibra, Informatica Axon, IBM Watson Knowledge Catalog, and Alation.

Enterprise Data Catalog Tools

A data catalog tool is a software application that provides a centralized repository and inventory of an organization’s data assets, along with their associated metadata. It serves as a comprehensive data management solution, enabling data discovery, governance, and collaboration. Here are the key aspects of a data catalog tool:

Data Discovery and Search:

  • Allows users to easily search, browse, and locate relevant data assets across the organization’s data landscape.
  • Utilizes metadata such as data descriptions, tags, classifications, and technical details to facilitate data discovery.
  • Provides a user-friendly interface for exploring and understanding available data resources.

Metadata Management:

  • Captures and maintains metadata from various data sources, including databases, data lakes, and applications.
  • Supports the collection of technical metadata (data types, schemas), operational metadata (data lineage, data flows), and business metadata (data definitions, glossaries).
  • Enables crowdsourcing and collaboration for enriching metadata with user-generated content like descriptions, ratings, and comments.

Data Governance and Compliance:

  • Enforces data governance policies and standards by leveraging metadata for data classification, access control, and data quality management.
  • Supports data lineage tracking and impact analysis for regulatory compliance and auditing purposes.
  • Facilitates data stewardship by assigning data owners, stewards, and defining roles and responsibilities.

Data Cataloging and Inventory:

  • Provides a comprehensive inventory of an organization’s data assets, including databases, data lakes, files, and reports.
  • Automatically scans and catalogs data sources, extracting relevant metadata and profiling data assets.
  • Maintains relationships and connections between different data assets, enabling data lineage visualization.

Integration and Collaboration:

  • Integrates with various data sources, data management tools, and analytics platforms for seamless data access and sharing.
  • Enables collaboration and knowledge sharing among data producers, data stewards, and data consumers through annotations, discussions, and workflows.
  • Supports self-service analytics by empowering users to find, understand, and access data independently.

By implementing a data catalog tool, organizations can establish a single source of truth for their data assets, improve data visibility and accessibility, enforce data governance and compliance, and foster collaboration and data democratization across the enterprise.

Some of the leading enterprise data governance tools include Informatica Enterprise Data Catalog, Apache Atlas, AWS Glue Data Catalog, Microsoft Azure Data Catalog, and IBM Knowledge Catalog.

Data catalogs play a crucial role in data management and data-driven decision-making by making data more accessible, trustworthy, and valuable.

Data Lineage Tools

Data lineage tools are software applications that help organizations track and visualize the flow of data across various systems, databases, and applications. These tools provide a comprehensive view of how data moves through the entire data ecosystem, from its origin to its final destination. Here are some key points about data lineage tools:

  • Data lineage tools automatically map and document the journey of data, showing its sources, transformations, and destinations.
  • They provide end-to-end visibility into data pipelines, enabling users to understand data dependencies and relationships.
  • Data lineage tools help organizations ensure data quality, enforce data governance, and maintain regulatory compliance.

Key Capabilities of Data Lineage Tools

  • Automated data lineage discovery and mapping across databases, data warehouses, ETL tools, and BI platforms.
  • Visual representation of data flows, transformations, and dependencies through interactive diagrams and graphs.
  • Impact analysis to understand the ripple effect of changes to data sources or transformations.
  • Integration with data catalogs and metadata management tools for enhanced data governance.
  • Support for column-level lineage to track individual data elements and their transformations.

Some leading enterprise data governance tools include:

  • Commercial Tools: Dataedo, MANTA, Collibra Data Lineage, Octopai, Informatica Metadata Manager, Alation, IBM InfoSphere, Lumada Data Catalog, and Secoda.
  • Open-Source Tools: Apache Atlas, OpenMetadata, OpenLineage (with Marquez), and SQLFlow.

When selecting a data lineage tool, enterprises should consider factors such as the tool’s integration capabilities, scalability, user-friendliness, support for various data sources and formats, and the ability to meet specific data governance and compliance requirements.

These data lineage tools help organizations gain visibility into their data assets, understand data transformations, identify data dependencies, and ensure data quality and compliance. They are essential for effective data governance, troubleshooting, and decision-making based on reliable and trustworthy data.

Processes and Workflows

Data security risk assessments

Data security risk assessments are a systematic process that organizations use to identify, analyze, and evaluate the risks associated with unauthorized data access and loss. It is a comprehensive evaluation of an organization’s data landscape to identify potential threats, vulnerabilities, and risks related to the collection, processing, storage, and sharing of sensitive data. Its primary objective is to safeguard sensitive information like personally identifiable information (PII), financial data, and intellectual property by understanding and mitigating potential risks.

Steps in a Data Security Risk Assessment

  • Identification of Data Assets: Listing and categorizing all data assets, emphasizing sensitive and critical data.
  • Risk Identification: Pinpointing potential risks and threats to the data assets, both external (hackers, malware) and internal (employee mishandling, system malfunctions).
  • Vulnerability Assessment: Evaluating weaknesses and gaps in current security measures, systems, and policies that can be exploited.
  • Risk Analysis and Evaluation: Estimating the potential impact and likelihood of identified risks, helping prioritize risks based on severity and probability.
  • Implementation of Controls: Proposing and applying security measures like encryption, firewalls, access controls, and regular audits to mitigate identified risks.
  • Monitoring and Review: Continuously monitoring the effectiveness of implemented controls and making necessary adjustments.

Data security risk assessments are crucial for organizations to protect sensitive data, maintain compliance, and make informed decisions about data security strategies and investments.

Incident response and breach notification processes

Incident response and breach notification processes are critical components of an organization’s cybersecurity strategy. Here are the key points regarding these processes:

Incident Response Process

The incident response process outlines the steps an organization takes to identify, contain, eradicate, and recover from a security incident or data breach. The typical phases include:

  • Preparation: Establish an incident response plan, assemble a response team, provide training, and acquire necessary tools and resources.
  • Identification: Detect and analyze the security incident to determine its scope, impact, and severity.
  • Containment: Implement short-term measures to prevent the incident from spreading or causing further damage.
  • Eradication: Identify and eliminate the root cause of the incident, such as removing malware or closing security vulnerabilities.
  • Recovery: Restore systems and data to a secure and operational state and validate the effectiveness of the remediation efforts.
  • Lessons Learned: Conduct a post-incident review, document findings, and update the incident response plan accordingly.

Breach Notification Process

In the event of a data breach involving sensitive information, organizations must follow a breach notification process to comply with regulatory requirements and inform affected individuals. The key steps include:

  • Detection and Assessment: Identify the nature and scope of the data breach, including the types of data involved and the number of individuals affected.
  • Internal Notifications: Inform relevant internal stakeholders, such as the security team, legal counsel, and executive leadership, about the breach.
  • External Notifications: Notify affected individuals, regulatory authorities, and other relevant parties (e.g., credit card companies) in accordance with applicable laws and regulations.
  • Breach Response: Implement measures to mitigate the impact of the breach, such as offering credit monitoring services or resetting compromised credentials.
  • Incident Investigation: Conduct a thorough investigation to determine the root cause of the breach and implement preventive measures.
  • Ongoing Monitoring: Monitor for any further signs of compromise and provide updates to affected parties as necessary.

Effective incident response and breach notification processes are essential for minimizing the impact of security incidents, maintaining regulatory compliance, preserving customer trust, and protecting an organization’s reputation. Regular testing, training, and updating of these processes are crucial for ensuring their effectiveness.

Security awareness and training programs

Security awareness and training programs are essential for organizations to educate their employees on cybersecurity best practices and mitigate the risks associated with human error or negligence. Here are the key points about security awareness and training programs:

Security awareness training aims to equip employees with the knowledge and skills required to identify and respond to potential security threats, such as phishing attacks, social engineering tactics, and data breaches. It covers various topics, including password management, safe internet usage, data handling, physical security, and compliance with industry regulations and organizational policies.

An effective security awareness program should include the following components:

  • Educational Content: A mix of written materials, interactive online modules, videos, gamification, and simulations tailored to different learning styles and roles within the organization.
  • Continuous Reinforcement: Regular reminders, refreshers, and updates on emerging threats and best practices to keep security top-of-mind for employees.
  • Simulated Attacks: Phishing simulations, social engineering tests, and other assessments to evaluate employees’ adherence to security protocols and identify areas for improvement.
  • Employee Engagement: Mechanisms for employees to report suspicious activities, seek guidance, and provide feedback on the training program.
  • Compliance Training: Specific training modules addressing regulatory requirements, such as GDPR, HIPAA, or PCI DSS, relevant to the organization’s industry.
  • Metrics and Reporting: Tracking and reporting on key performance indicators (KPIs) to measure the program’s effectiveness and identify areas for enhancement.

Implementing a comprehensive security awareness and training program is crucial for organizations to build a robust cybersecurity posture and cultivate a security-conscious workforce. Regular updates, reinforcement, and employee engagement are key to ensuring the program’s long-term effectiveness.

Policies and Governance

Policies and governance are the foundation of data-centric security. By implementing robust policies and governance around data security, organizations can protect their sensitive data assets, maintain customer trust, and avoid the significant financial and reputational consequences of data breaches or non-compliance. What follows in this section are the critical policies that should be established and enforced as part of your security strategy.

Data classification and handling policies

Data classification and handling policies establish a framework for categorizing and managing an organization’s data assets based on their sensitivity levels and potential impact if compromised. These policies typically include the following key elements:

  • Data Classification Levels: Define clear criteria for classifying data into different sensitivity levels, such as public, internal, confidential, and highly confidential/restricted. Classification is based on factors like legal/regulatory requirements, potential impact of unauthorized disclosure or loss, and the need for confidentiality, integrity, and availability.
  • Data Types and Examples: Provide examples and guidance on the types of data that fall under each classification level. Common examples include public information, internal policies, personal data, financial records, intellectual property, and highly sensitive research data.
  • Data Handling Procedures: Outline specific procedures and controls for handling data at each classification level throughout its lifecycle (creation, storage, transmission, disposal). This includes access controls, encryption requirements, secure transfer protocols, physical security measures, and approved storage locations.
  • Roles and Responsibilities: Define roles like data owners, data stewards/custodians, and data users, along with their respective responsibilities for classifying, protecting, and managing data assets. Data owners are typically responsible for assigning classifications and defining protection requirements.
  • Labeling and Marking: Require data to be clearly labeled or marked with its appropriate classification level. This aids in proper handling and prevents accidental misuse or disclosure.
  • Data Sharing and Access Controls: Establish guidelines for sharing data internally and externally based on classification levels. Define access control measures, such as need-to-know principles, user authentication, and authorization processes.
  • Monitoring and Auditing: Implement processes for monitoring compliance with the policy and conducting regular audits. This helps identify potential violations, assess the effectiveness of controls, and drive continuous improvement.
  • Training and Awareness: Require employees and relevant stakeholders to receive training on the data classification policy and their responsibilities in handling sensitive data. Promote a culture of data security and accountability within the organization.
  • Policy Review and Updates: Establish procedures for periodic review and updates to the policy to align with changes in regulations, business needs, or technological advancements.

By implementing a comprehensive data classification and handling policy, organizations can effectively manage their data assets, mitigate risks associated with data breaches or mishandling, and maintain compliance with relevant regulations and industry standards.

Access control and data sharing policies

Access control and data sharing policies are crucial for ensuring the security and proper management of an organization’s data assets. Here are the key elements of these policies:

Access Control Policies

Access control policies define who can access what data and under what conditions within an organization. The main elements include:

  • User Identification and Authentication: Establish processes to uniquely identify and authenticate users before granting data access.
  • Role-Based Access Control (RBAC): Implement RBAC to link access rights to user roles, ensuring users only have access required for their job functions. Avoid shared accounts.
  • Principle of Least Privilege: Grant users the minimum level of access necessary to perform their duties, limiting potential damage from compromised accounts.
  • Multi-Factor Authentication: Implement advanced MFA methods like biometrics or one-time passwords for added security.
  • Access Authorization: Define clear processes for requesting, granting, changing, and revoking access rights, with segregation of duties.
  • Inactive Account Management: Regularly review and disable inactive accounts to mitigate unauthorized access risks.
  • Monitoring and Auditing: Continuously monitor user access patterns, conduct audits, and maintain audit trails for accountability.

Data Sharing Policies

Data sharing policies outline the framework for sharing data within and outside an organization while ensuring data security and compliance. Key elements include:

  • Purpose and Intended Use: Clearly define the purpose, types of data to be shared, and organizations involved.
  • Data Classification: Classify data based on sensitivity levels to determine appropriate access controls and sharing procedures.
  • Sharing Models: Specify models like open access, external repositories, or managed access via Data Access Committees.
  • Access Criteria: Provide guidelines on conditions for access, such as recognition requirements, collaborations, exclusive periods, or benefit sharing.
  • Data Security: Establish procedures for secure data transmission, storage, access controls, and compliance with regulations.
  • Roles and Responsibilities: Define roles like data owners, stewards, and consumers, and their respective responsibilities.
  • Consent and Privacy: Ensure data sharing aligns with consent models and privacy regulations like GDPR or HIPAA.
  • Review and Updates: Regularly review and update policies to adapt to changes in regulations, technology, or business needs.

Effective access control and data sharing policies are crucial for protecting sensitive data, enabling secure collaboration, and maintaining regulatory compliance while maximizing the utility of an organization’s data assets.

Data retention and disposal policies

Data retention and disposal policies outline the guidelines and procedures for how an organization manages the lifecycle of its data assets. Here are the key elements of effective data retention and disposal policies:

Data Retention Policy

  • Data Classification: Categorize data based on sensitivity levels (e.g. public, internal, confidential) to determine appropriate retention periods.
  • Retention Periods: Specify retention timeframes for different data types based on legal/regulatory requirements, business needs, and the data’s value to the organization.
  • Storage Locations: Define approved storage locations (e.g. cloud, on-premises) for retaining data during its lifecycle, considering security, accessibility, and cost factors.
  • Access Controls: Establish procedures for granting and managing access to retained data based on roles, permissions, and the principle of least privilege.
  • Data Owners: Assign data owners or stewards responsible for managing the retention and disposal of specific data types within their respective business units or functions.
  • Backup and Archiving: Outline requirements for backing up and archiving data to ensure availability, recoverability, and compliance with retention periods.
  • Monitoring and Auditing: Implement processes for monitoring data retention practices, conducting periodic audits, and ensuring adherence to the policy.

Data Disposal Policy

  • Disposal Criteria: Define criteria for determining when data should be disposed of, such as reaching the end of its retention period or becoming obsolete.
  • Disposal Methods: Specify secure methods for permanently destroying or deleting data, depending on its format (e.g., physical shredding for paper records, secure data wiping for electronic records).
  • Data Sanitization: Establish procedures for sanitizing storage media (e.g., hard drives, tapes) before disposal or repurposing to prevent data leaks.
  • Disposal Approvals: Require approvals from designated authorities (e.g., data owners, legal, compliance) before disposing of certain data types, especially those containing sensitive or critical information.
  • Disposal Logging: Maintain detailed logs of data disposal activities, including the data disposed, disposal methods used, and personnel involved, for audit and compliance purposes.
  • Third-Party Vendors: Define requirements and oversight procedures for third-party vendors involved in data disposal processes, ensuring they adhere to the organization’s security and compliance standards.
  • Exceptions and Legal Holds: Outline processes for handling exceptions to the disposal policy, such as legal holds or investigations that require data to be retained beyond its normal retention period.

By implementing comprehensive data retention and disposal policies, organizations can effectively manage their data assets throughout their lifecycle, ensure compliance with legal and regulatory requirements, minimize risks associated with data breaches or mishandling, and optimize storage and operational costs.

Vendor and third-party risk management policies

Vendor and third-party risk management policies are essential for organizations to mitigate the risks associated with engaging external vendors or third parties. These policies outline the guidelines, procedures, and controls for identifying, assessing, monitoring, and mitigating risks throughout the vendor lifecycle. Here are the key elements of effective vendor and third-party risk management policies:

  • Vendor Identification and Classification: Establish processes to identify and maintain an inventory of all third-party vendors, suppliers, and service providers the organization works with. Classify vendors based on the level of risk they pose, considering factors such as the type of service/product provided, access to sensitive data, and criticality to business operations.
  • Risk Assessment and Due Diligence: Define criteria and procedures for conducting due diligence and risk assessments on potential and existing vendors. Assessments should evaluate the vendor’s financial stability, security controls, compliance with regulations, data handling practices, and overall risk profile.
  • Vendor Selection and Contracting: Outline the vendor selection process, including requirements for security controls, data protection measures, and compliance obligations that vendors must meet. Specify contractual clauses and provisions related to vendor risk management, such as the right to audit, data ownership, and termination procedures.
  • Ongoing Monitoring and Assessments: Establish processes for continuous monitoring of vendor performance, security posture, and compliance through regular risk assessments, audits, and reviews. Define key performance indicators (KPIs) and metrics to measure and evaluate vendor risk and performance.
  • Incident Response and Breach Notification: Outline procedures for responding to and reporting vendor-related security incidents, data breaches, or other adverse events. Specify requirements for vendors to notify the organization promptly in case of incidents and provide necessary information for investigation and remediation.
  • Roles and Responsibilities: Clearly define the roles and responsibilities of various stakeholders, such as vendor managers, risk managers, legal, IT, and business units, in the vendor risk management process. Establish a governance structure for oversight, decision-making, and escalation of vendor-related risks.
  • Training and Awareness: Implement training programs to educate employees on the vendor risk management policy, their roles and responsibilities, and best practices for secure vendor interactions. Promote a culture of vendor risk awareness across the organization.
  • Policy Review and Updates: Establish processes for regular review and updates to the vendor risk management policy to ensure it remains aligned with evolving business needs, regulatory changes, and emerging threats.

By implementing a comprehensive vendor and third-party risk management policy, organizations can effectively identify, assess, and mitigate the risks associated with vendor relationships, protect sensitive data and systems, maintain compliance with regulations, and ensure business continuity and resilience.

A summary list of high-level policies, standards, and best practices for data-centric security can be found in appendix 2. This information can be used as a checklist as you develop the specific policies for your enterprise.

Challenges to Implementing Data-centric Security

Data-centric security aims to protect data throughout its lifecycle, regardless of its location or format. However, implementing data-centric security poses several challenges.

Transitioning to a data-centric model

  • Data Discovery and Classification: Accurately identifying and classifying all sensitive data across the enterprise is a fundamental requirement but also a significant challenge. Organizations may struggle to develop a comprehensive data classification framework and maintain it as data proliferates across different environments.
  • Key Management: Implementing robust encryption as part of a data-centric approach requires secure distribution and management of encryption keys. Ensuring only authorized parties have access to the keys across complex IT environments and when sharing data externally becomes increasingly difficult.
  • Balancing Security and Usability: Implementing strong data protection measures like encryption and access controls must be balanced against the need for data accessibility and usability for legitimate business operations. Overly restrictive controls can hinder productivity and adoption.
  • Integrating with Legacy Systems: Many organizations have legacy applications and systems not designed for data-centric security principles. Integrating modern data protection techniques into these older environments can be technically challenging.
  • Lack of Centralized Control: Effective data-centric security requires centralized management and visibility into data access and usage across the entire distributed data environment. Achieving this centralized oversight can be difficult, especially in large enterprises.
  • Cultural and Organizational Resistance: Transitioning to a data-centric mindset often requires a significant cultural shift within an organization, which can face resistance from teams accustomed to traditional perimeter-based security models.
  • Compliance Challenges: Ensuring data-centric security measures align with and support compliance across various data privacy regulations like GDPR, HIPAA, and CCPA adds complexity to implementation efforts.
  • Evolving Threat Landscape: As cyber threats continue evolving, organizations must continuously update and enhance data-centric protections to address new attack vectors and tactics used by threat actors.

Overcoming these challenges requires robust data governance, employee training, adoption of appropriate security technologies, and a comprehensive strategy tailored to the organization’s needs and environment.

Data-centric security and existing frameworks

Data-centric security can be integrated with existing security frameworks and infrastructure. This is one of the key advantages and benefits of adopting a data-centric approach to security. Here’s how data-centric security can be layered on top of an organization’s current security measures:

  • Complementing Existing Controls: Data-centric security solutions are designed to complement and enhance traditional perimeter and endpoint security controls, not replace them entirely. Measures like firewalls, antivirus, and access management remain important, while data-centric security adds an additional layer of protection focused specifically on the data itself.
  • Integration with Legacy Systems: Many organizations have complex IT environments with legacy applications and systems. Data-centric security platforms can typically integrate with these older systems through APIs, agents, or other integration methods. This allows organizations to extend data protection to their entire infrastructure without requiring wholesale replacements.
  • Gradual Implementation: The implementation of data-centric security can be done gradually and in phases, integrating with different parts of the existing security infrastructure over time. This allows for a smooth transition without major disruptions to ongoing operations.
  • Centralized Management: Data-centric security solutions often provide a centralized management console that can unify and orchestrate data protection policies across the entire environment, including both new and legacy components. This centralized control simplifies administration and ensures consistent enforcement.
  • Automation and Scalability: By automating data discovery, classification, and protection processes, data-centric security solutions can scale to accommodate large, distributed environments while integrating with the organization’s current security tools and workflows.

While the specific integration approach may vary depending on the data-centric security solution and the organization’s existing infrastructure, the key principle is that data-centric security is designed to be additive and complementary, rather than requiring a complete overhaul of established security measures.

Conclusion

Data-centric security is an approach that emphasizes the protection of data itself, rather than solely focusing on securing networks, servers, or applications. Its importance lies in addressing the evolving security challenges organizations face in today’s digital landscape. Here’s a summary of the key points highlighting the significance of data-centric security:

Data is the prime target: With data being the most valuable asset for modern organizations, cybercriminals primarily target sensitive data like intellectual property, financial records, and personal information. Data-centric security acknowledges this reality and prioritizes safeguarding data from unauthorized access, theft, or misuse.

Addresses data proliferation: As data proliferates across various environments (on-premises, cloud, mobile devices), traditional perimeter-based security measures become inadequate. Data-centric security ensures that data remains protected regardless of its location or the systems it traverses.

Regulatory compliance: Many data privacy regulations, such as GDPR, HIPAA, and CCPA, mandate the protection of sensitive data. By implementing data-centric security measures like encryption, access controls, and data masking, organizations can demonstrate compliance and avoid potential legal and financial penalties.

Mitigates data breach risks: Even if perimeter defenses are breached, data-centric security measures like encryption and data masking can prevent unauthorized access to sensitive data, minimizing the impact of a data breach.

Supports secure collaboration: With remote work and data sharing becoming more prevalent, data-centric security enables secure collaboration by protecting data as it moves across different environments and users.

Scalability and agility: Data-centric security solutions can be deployed quickly and scale seamlessly across hybrid and multi-cloud environments, supporting agile business needs and data growth.

Visibility and control: By classifying and cataloging data based on sensitivity, organizations gain better visibility and control over their data assets, enabling them to apply appropriate security measures and manage data throughout its lifecycle.

Data-centric security is crucial for organizations to protect their most valuable asset – data – from various threats, maintain regulatory compliance, enable secure collaboration, and adapt to the evolving data landscape. It represents a fundamental shift in security strategy, focusing on the dependability and protection of data itself.

Future trends and challenges

Data-centric Security isn’t static as the attacks increase in sophistication and the volume of data to be secured grows exponentially. Here are some of the key future trends impacting data-centric security:

Shift Towards Data Safety Over Traditional Data Security: The focus is shifting from just “data security” (restricting data access) to “data safety” (enabling secure data sharing and collaboration). Data safety incorporates preventative controls into business processes to allow information sharing without compromising protection.

Increased Adoption of Inside-out Security Models: Traditional perimeter-based security (outside-in) measures are no longer sufficient in today’s distributed and interconnected environments. Inside-out security focuses on understanding user behaviors, data flows, and access patterns within the organization, enabling continuous monitoring, risk assessment, and implementation of strict access controls and data protection measures. Zero trust and data centric strategies are key.

Emphasis on Data Governance and Accountability: As more data privacy regulations emerge, effective corporate governance and accountability for data activities will become increasingly crucial. Organizations need to monitor data sharing during collaborations to prevent wrongful disclosure and ensure compliance.

Application-Level Data Protection: Since most business-critical data is generated and managed by applications, APIs, and micro-services, implementing controls to protect sensitive data at the application source and tracking data flows between applications will gain importance.

Automation and AI/ML for Data Security: To handle the growing volume and complexity of data, organizations will increasingly adopt automation and AI/ML capabilities for tasks like data discovery, classification, risk assessment, and policy enforcement.

Cloud Data Security: With more data moving to the cloud for collaboration, securing sensitive data in cloud environments and during cloud-to-cloud data transfers will be a key priority. Cloud data-centric security solutions will see faster adoption.

Scalable and Agile Deployment Models: Organizations will seek data-centric security solutions that can be deployed quickly and scale seamlessly across hybrid and multi-cloud environments, supporting agile business needs.

Integration with Existing Security Tools: Data-centric security solutions will need to integrate with an organization’s existing security stack, such as data loss prevention (DLP), security information and event management (SIEM), and identity and access management (IAM) tools.

Overall, the future of data-centric security will be shaped by the need for secure collaboration, compliance with evolving regulations, and the adoption of cloud and distributed computing models, driving the demand for comprehensive, integrated, and automated data protection solutions.

Closing Thoughts: Protecting Your Organization’s Most Valuable Asset – Data

In today’s digital age, data is the lifeblood of every organization. From customer information to intellectual property, sensitive data is constantly at risk of being compromised, leading to devastating consequences such as financial losses, reputational damage, and regulatory penalties.

Traditional security measures that focus solely on securing networks and applications are no longer sufficient. As data proliferates across various environments, including on-premises, cloud, and mobile devices, a new approach is needed – one that prioritizes the protection of data itself.

It’s time to embrace data-centric security, a comprehensive strategy that safeguards your organization’s most valuable asset throughout its entire lifecycle, regardless of its location or the systems it traverses.

By implementing data-centric security measures, you can:

  • Mitigate the risks of data breaches and unauthorized access to sensitive information
  • Ensure compliance with data privacy regulations like GDPR, HIPAA, and CCPA
  • Enable secure collaboration and data sharing across distributed teams and partners
  • Gain visibility and control over your data assets, enabling effective data governance
  • Adapt to the evolving data landscape and support agile business needs

Don’t wait until it’s too late. Act now and protect your organization’s future by making data-centric security a top priority. Embrace data-centric security and unlock the full potential of your data while minimizing risks and maintaining compliance. The time to act is now.

About TechVision

World-class research requires world-class consulting analysts, and our team is just that. Gaining value from research also means having access to research. All TechVision Research licenses are enterprise licenses; this means everyone that needs access to content can have access to content. We know major technology initiatives involve many different skills across an organization and limiting content to a few can compromise the effectiveness of the team and the success of the initiative. Our research leverages our team’s in-depth knowledge as well as their real-world consulting experience. We combine great analyst skills with real world client experiences to provide a deep and balanced perspective.

TechVision Consulting builds off our research with specific projects to help organizations better understand, architect, select, build, and deploy infrastructure technologies. Our well-rounded experience and strong analytical skills help us separate the “hype” from the reality. This provides organizations with a deeper understanding of the full scope of vendor capabilities, product life cycles, and a basis for making more informed decisions. We also support vendors in areas such as product and strategy reviews and assessments, requirement analysis, target market assessment, technology trend analysis, go-to-market plan assessment, and gap analysis.

TechVision Updates will provide regular updates on the latest developments with respect to the issues addressed in this report.

About the Author

Gary Zimmerman is an experienced executive known for helping companies deliver new offers and expand markets. Accomplishments include launching four companies, 20+ products, building high-performance organizations, and generating millions in sales.

His experience at AT&T, Neustar, Respect Network, and Sovrin allows him to provide a broad perspective on a variety of subjects including self-sovereign identity, blockchain, enterprise data management, and the data brokerage industry.  His experience in both enterprise and startup product development gives him a unique perspective on the application of new technologies.

Appendix 1

Infonomics proposes several key factors and valuation models to determine the value of a data asset within an organization:

Foundational (Non-Financial) Valuation Models. These models reflect the attributes most enterprises look to measure.

  • Intrinsic Value of Information (IVI): This measures the inherent quality of the data asset itself, considering factors such as:
    • Accuracy and completeness of the data
    • Reliability and trustworthiness of the data source
    • Exclusivity or scarcity of the data (how unique/rare it is)
    • Accessibility and ease of use
  • Business Value of Information (BVI): This evaluates how relevant and useful the data is for specific business processes and use cases, factoring in:
    • Timeliness and currency of the data
    • Alignment with key business objectives and metrics
    • Potential impact on operational efficiency and decision-making
  • Performance Value of Information (PVI): This empirically measures how the data asset impacts key performance indicators (KPIs) and drives business results over time.

Financial Valuation Models. These models reflect the attributes that leading enterprises measure when viewing data as an asset.

  • Cost Value of Information (CVI): This calculates the costs associated with acquiring, storing, managing, and potentially losing/replacing the data asset.
  • Market Value of Information (MVI): This estimates the potential revenue that could be generated by directly selling, trading, or monetizing the data externally, based on market demand and competitors’ pricing.
  • Economic Value of Information (EVI): This determines the overall economic value and contribution of the data asset to revenue generation, cost savings, or other financial benefits for the business.
  • Data Monetization Opportunities: Infonomics evaluates how data assets can be monetized, both directly (selling data products) and indirectly (using data to optimize processes, create new offerings, etc.), contributing to the overall valuation.
  • Data Risks and Liabilities: Potential risks like privacy violations, security breaches, or regulatory non-compliance associated with the data asset are also factored into the valuation.

The models can be applied in various ways, such as prioritizing information management initiatives, identifying data monetization opportunities, evaluating data lifecycle costs, and quantifying the potential and realized value of information assets to drive better data governance and decision-making.

Appendix 2

Here are some key policies, standards, and best practices for implementing a data-centric security approach:

Policies:

  1. Data classification and handling policies:
  • Establish clear guidelines for classifying data based on sensitivity, criticality, and regulatory requirements.
  • Define appropriate handling, storage, and processing procedures for each data classification level.
  1. Data access and authorization policies:
  • Implement granular access control policies that regulate who can access specific data assets based on user identity, role, and context.
  • Ensure least-privilege access and segregation of duties principles.
  • Define how the data can be used and manipulated.
  1. Data protection and encryption policies:
  • Mandate the use of strong encryption standards for data at rest and in transit.
  • Define key management and rotation processes to ensure the integrity of encryption keys.
  1. Data retention and disposition policies:
  • Establish guidelines for the retention and secure disposal of data based on its classification and regulatory requirements.
  1. Data breach response policy:
  • Define the procedures and responsibilities for detecting, responding to, and mitigating data breaches or unauthorized access attempts.

Standards:

  1. Data security standards:
  • Align with industry-accepted data security standards, such as NIST SP 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) or ISO/IEC 27001 (Information Security Management).
  • Ensure compliance with relevant data privacy regulations, such as GDPR, HIPAA, or PCI DSS.
  1. Cryptographic standards:
  • Adhere to recognized cryptographic standards, such as NIST SP800, AES, RSA, or FIPS 140-2, for data encryption and key management.
  1. Data discovery and classification standards:
  • Adopt standardized data classification taxonomies and labeling conventions.
  • Utilize industry-standard data discovery and classification tools and methodologies.
  1. Identity and access management standards (e.g., NIST SP 800-63, SAML, OpenID Connect): Utilize standard-based identity and access management practices to enforce data-level access controls.

Best Practices:

  1. Data mapping and inventory:
  • Continuously discover, classify, and map the organization’s data assets to maintain a comprehensive understanding of the data landscape.
  • Maintain a comprehensive inventory of all data assets, including their location, sensitivity, and regulatory requirements.
  1. Data-centric access controls:
  • Implement fine-grained, context-aware access controls that regulate access to specific data assets based on user identity, role, device posture, and other relevant factors.
  • Implement fine-grained, attribute-based access controls (ABAC) that consider user identity, device, location, and other contextual factors.
  • Regularly review and update access privileges based on the principle of least privilege.
  1. Data encryption and key management:
  • Ensure that data is encrypted at rest and in transit using strong, standardized algorithms, and establish robust key management practices.
  • Ensure that data is encrypted at rest and in transit, using industry-standard algorithms and key management processes.
  • Implement robust key management practices, including key rotation, secure storage, and access controls.
  1. Data monitoring and analytics:
  • Monitor user and application access to data assets, and implement analytics-driven anomaly detection to identify and respond to suspicious activities.
  • Monitor data access and usage patterns to detect anomalies and potential data breaches.
  • Leverage data security analytics and user and entity behavior analytics (UEBA) to identify and respond to threats.
  1. Data backup and recovery:
  • Implement secure data backup and recovery strategies to ensure the availability and integrity of critical data assets in the event of a security incident or data loss.
  1. Secure data lifecycle management:
  • Establish secure processes for data creation, storage, sharing, and disposal.
  • Regularly review and update data retention and disposition policies based on evolving business and regulatory requirements.
  1. Data governance and stewardship:
  • Establish clear data governance frameworks and assign data stewardship responsibilities to ensure the proper management and protection of data assets.
  1. Security awareness and training:
  • Educate employees on data-centric security best practices, such as secure data handling, the use of encryption, and reporting of potential data breaches.

By adopting these policies, standards, and best practices, organizations can effectively implement data-centric security as a core component of their inside-out security strategy, ensuring the protection of their most critical assets.

[1] While “data ownership” is the term of art, many data professionals prefer the term “data stewardship”. The enterprise (or the customer) owns the data. Stewardship on the other hand, is the ethical practice of responsibly managing and planning the use of resources; something we want people who are responsible for data to do.

Tags:

We can help

If you want to find out more detail, we're happy to help. Just give us your business email so that we can start a conversation.

Thanks, we'll be in touch!

Stay in the know!

Keep informed of new speakers, topics, and activities as they are added. By registering now you are not making a firm commitment to attend.

Congrats! We'll be sending you updates on the progress of the conference.