Data is both a valuable business asset and a potential liability, requiring organizations to manage it carefully across its entire life cycle from creation to disposal. Understanding the costs, risks, and protective measures associated with data is foundational to sound information security practice.
Data Overview
Data is an asset to a company. Why else would we store the data and use the data if it didn't have any value to us? So data definitely has a value, otherwise we wouldn't have it.
Data has some sort of primary value to it — that is, we've created this data for some sort of purpose. Let's say we have a system where users are logging into our system and then filling out a profile. That filled-out profile has some sort of value to it; maybe it's so that they can start interacting with other people on our system. So it has that primary value that we can utilize for whatever its intended purpose is.
But it has a lot of other value potentially for our business as well. For instance, now that we have profile information of our customers, maybe we use it to do some sort of marketing and analytics, or use it to determine what our demographics are, or figure out how we're going to propel our marketing to the next level. So there's a lot of marketing and business analytics purpose to storing this data. We can also better support our customers with it. And if there's ever any legal action against this Pro, potentially that can prove that we've been operating in a certain way and show that we've been ethical in the way we're doing business. There are a lot of other reasons — this is just a few of the ones that I've thought of, but there are lots of other reasons why data can have a value to the company.
Storage has a cost to it as well. That data has to be stored on something, and we had to pay for whatever that something is, so there are storage costs to that. Also, if we're storing it, we probably are backing it up, and so there's storage for that backup cost, and we have to manage that backup.
It also can impact performance. If you have lots and lots and lots of data, then there becomes this manageability of all of that data as well — how do we manage this when you have so much data?
And then if that data were ever to be stolen, there could be some security ramifications from that. If we have customer records and that data is stolen, that could be a confidentiality breach, and we could have to go and notify those customers that we lost certain pieces of information, which could be devastating. Or if the information is altered or deleted, that could be problematic as well.
Depending on where you're collecting this data from and who the data subjects are, we could fall under a lot of different compliance, and so there's a liability from that perspective as well.
This is all to say that data can be an asset to the company and a liability at the same time. We need to weigh out the pros and cons of this data — how much of it is an asset and how much is a liability — and based off of that, do we keep it around and protect it, or do we get rid of it and delete it?
We're going to need to start guarding this data, making sure that it's secure, making sure that we're treating it correctly. Part of that approach is to realize that data has a life cycle. It has a beginning, where it's created. It has a middle, where we're going to manage it. And it has an end, where we're going to retire that data. With each one of those there are different steps that we have to take and think about as we're managing this data through this life cycle, and there are lots of different data protection techniques depending on which part of its life cycle this data is in.
At some point in time data is created, so we need to think about that process of how data is created, why it's created, and why we are storing it. We're going to think about how the data is entered and collected and compiled right at the beginning.
Then we have to go through the managing of this. We're going to store it, we're going to be using it, we'll have to share some of this data out potentially, we're going to possibly transfer, move or copy it, we're probably going to do some sort of backup to it, and maybe there's some sort of versioning on this data.
And then we have to retire the data. The retiring of the data is where we're going to archive or destroy this data.
Here's a little different view of the data life cycle. The only reason why I'm bringing this different view up is because this is one of the standards that are out there. I'm not as big of a fan here, because it just assumes that you're going to be taking certain steps, like sharing or archiving this data, when that's not necessarily the case. It shows a little more of a linear approach, when it's a little bit messier than that.
So in my model there are all the same approaches to this and how we utilize it — in fact I actually go a little more in depth — but in this case I don't necessarily assume that we're going to take every single step.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →