It applies to data in physical and digital forms throughout collection, creation, storage, processing, transfer, sharing, archival, and disposal. The required safeguards depend on the data, purpose, environment, threats, and consequences of failure.
Data security combines governance, people, process, architecture, and technology. It supports privacy and data-protection objectives, but cannot by itself determine whether collecting or using data is lawful, fair, necessary, or appropriate.
Key points
Data understandingInventory important stores and flows, classify information in context, assign accountable owners, and identify authorized purposes, users, dependencies, and retention needs.
Layered safeguardsUse appropriate access control, encryption, isolation, secure configuration, physical protection, backups, deletion, and restrictions on copying, export, and third-party handling.
Operations and verificationMonitor meaningful events, test controls and recovery, manage vulnerabilities and changes, investigate anomalies, and measure whether safeguards work across the actual data lifecycle.
Important limitationEncryption, classification labels, a compliance result, or a security product does not equal data protection. Each covers selected risks, may be misconfigured or bypassed, and requires supporting controls and accountable operation.