# What is Data-Centric Audit and Protection (DCAP)?

> Data-centric audit and protection (DCAP) is an older analyst-defined market category for capabilities that discover and classify data, govern access, monitor or audit data activity, and apply protective controls around the data itself.

- Canonical URL: https://yellowcube.eu/glossary/data-centric-audit-and-protection/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The label was intended to group security functions across structured, unstructured, and cloud repositories instead of treating each repository as an isolated control problem.

DCAP has no universal technical specification or mandatory feature set. Implementations and later market categories divide or recombine its functions differently, so an organization should evaluate concrete data stores, controls, evidence, integrations, and operating responsibilities rather than rely on the label.

### Key points

- **Knowledge of data:** Discover stores and sensitive content, associate classifications and owners, and maintain context about where governed data resides and who can reach it.
- **Audit and analysis:** Record access and administrative activity, relate events to data and identities, identify policy violations or unusual behavior, and preserve evidence appropriate to investigation and compliance needs.
- **Protection and governance:** Apply repository-supported controls such as access restrictions, masking, tokenization, encryption, quarantine, or policy workflows, with accountable approval and exception processes.
- **Important limitation:** A product described as DCAP may cover only selected repositories or capabilities, and the category itself is not an assurance standard. Claimed breadth does not establish complete discovery, effective enforcement, or accurate detection.

### Related terms

[Data discovery](<https://yellowcube.eu/glossary/data-discovery/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [Data security posture management (DSPM)](<https://yellowcube.eu/glossary/data-security-posture-management/>) · [Data security](<https://yellowcube.eu/glossary/data-security/>)

### Sources

[OGC Testbed-17: Data Centric Security Engineering Report](https://docs.ogc.org/per/21-020r1.html) · [NIST Data Classification Practices: Facilitating Data-Centric Security Management](https://csrc.nist.gov/pubs/pd/2021/07/22/data-classification-practices-datacentric-security/final) · [NIST SP 800-53 Rev. 5, Release 5.2.0](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

