TechKnowSurge
ISC2 CISSP 2.1 NIST CSF ID.AM-07 CompTIA Security+ 4.2 CompTIA SecurityX 1.4 ISC2 CISSP 2.4 NIST CSF ID.AM-08 NIST 800-53 SI-12 CompTIA Security+ 3.3
VideoSecurityFree

Data Management

Data is both a valuable business asset and a potential liability, requiring organizations to manage it carefully across its entire life cycle from creation to disposal. Understanding the costs, risks, and protective measures associated with data is foundational to sound information security practice.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data is a core organizational asset, but its value is never one-dimensional. Beyond its primary purpose, such as enabling user profiles or powering a service, data supports business analytics, informs marketing strategy, improves customer support, and can serve as evidence of ethical conduct in legal proceedings. Recognizing all the ways data creates value is the first step toward managing it responsibly. However, data also carries measurable liabilities. Storage and backup infrastructure come with ongoing costs, and large data volumes introduce management and performance challenges. More critically, data exposure through theft, unauthorized modification, or accidental deletion can result in confidentiality breaches, mandatory breach notifications, and significant regulatory penalties depending on the nature of the data and the jurisdictions involved. Organizations must weigh these risks against the benefits and make deliberate decisions about what data to retain, protect, or permanently delete. A structured way to approach these decisions is through the data life cycle, which covers three broad phases: creation, active management, and retirement. During creation, data is entered, collected, or compiled, and the rationale for storing it should be established at that point. The management phase involves storing, using, sharing, transferring, copying, and versioning data, each of which carries its own security considerations. Finally, retirement involves archiving data that must be retained or securely destroying data that no longer serves a legitimate purpose. Effective data protection requires applying the right controls at each phase, rather than treating security as a single uniform practice applied across the board.

What you'll learn

What's covered

Data Overview

Aligned to

ISC2 CISSP
2.1 Identify and classify information and assets
2.4 Manage data lifecycle
NIST CSF
ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained.
ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles.
CompTIA Security+
4.2 Explain the security implications of proper hardware, software, and data asset management.
3.3 Compare and contrast concepts and strategies to protect data.
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements.
NIST 800-53
SI-12 Information Management and Retention

Key terms

Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Data Integrity
The assurance that data has not been altered or corrupted during storage or transmission.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Data Life Cycle
The stages data passes through from creation and collection, through active use and management, to eventual archiving or destruction.
Data Governance
The policies, processes, and standards that define how organizational data is managed, protected, and retained throughout its life cycle.

Topics

Data Management Data Lifecycle Information Security Data Governance Data Classification Risk Management

Transcript

Data as an Asset

Data is an asset to a company. Why else would we store the data and use the data if it didn't have any value to us? So data definitely has a value, otherwise we wouldn't have it.

Data has some sort of primary value to it — that is, we've created this data for some sort of purpose. Let's say we have a system where users are logging into our system and then filling out a profile. That filled-out profile has some sort of value to it; maybe it's so that they can start interacting with other people on our system. So it has that primary value that we can utilize for whatever its intended purpose is.

But it has a lot of other value potentially for our business as well. For instance, now that we have profile information of our customers, maybe we use it to do some sort of marketing and analytics, or use it to determine what our demographics are, or figure out how we're going to propel our marketing to the next level. So there's a lot of marketing and business analytics purpose to storing this data. We can also better support our customers with it. And if there's ever any legal action against this Pro, potentially that can prove that we've been operating in a certain way and show that we've been ethical in the way we're doing business. There are a lot of other reasons — this is just a few of the ones that I've thought of, but there are lots of other reasons why data can have a value to the company.

The Cost and Liability of Data

Storage has a cost to it as well. That data has to be stored on something, and we had to pay for whatever that something is, so there are storage costs to that. Also, if we're storing it, we probably are backing it up, and so there's storage for that backup cost, and we have to manage that backup.

It also can impact performance. If you have lots and lots and lots of data, then there becomes this manageability of all of that data as well — how do we manage this when you have so much data?

And then if that data were ever to be stolen, there could be some security ramifications from that. If we have customer records and that data is stolen, that could be a confidentiality breach, and we could have to go and notify those customers that we lost certain pieces of information, which could be devastating. Or if the information is altered or deleted, that could be problematic as well.

Depending on where you're collecting this data from and who the data subjects are, we could fall under a lot of different compliance, and so there's a liability from that perspective as well.

This is all to say that data can be an asset to the company and a liability at the same time. We need to weigh out the pros and cons of this data — how much of it is an asset and how much is a liability — and based off of that, do we keep it around and protect it, or do we get rid of it and delete it?

The Data Life Cycle

We're going to need to start guarding this data, making sure that it's secure, making sure that we're treating it correctly. Part of that approach is to realize that data has a life cycle. It has a beginning, where it's created. It has a middle, where we're going to manage it. And it has an end, where we're going to retire that data. With each one of those there are different steps that we have to take and think about as we're managing this data through this life cycle, and there are lots of different data protection techniques depending on which part of its life cycle this data is in.

At some point in time data is created, so we need to think about that process of how data is created, why it's created, and why we are storing it. We're going to think about how the data is entered and collected and compiled right at the beginning.

Then we have to go through the managing of this. We're going to store it, we're going to be using it, we'll have to share some of this data out potentially, we're going to possibly transfer, move or copy it, we're probably going to do some sort of backup to it, and maybe there's some sort of versioning on this data.

And then we have to retire the data. The retiring of the data is where we're going to archive or destroy this data.

A Different View of the Life Cycle

Here's a little different view of the data life cycle. The only reason why I'm bringing this different view up is because this is one of the standards that are out there. I'm not as big of a fan here, because it just assumes that you're going to be taking certain steps, like sharing or archiving this data, when that's not necessarily the case. It shows a little more of a linear approach, when it's a little bit messier than that.

So in my model there are all the same approaches to this and how we utilize it — in fact I actually go a little more in depth — but in this case I don't necessarily assume that we're going to take every single step.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →