Data exists in three distinct states — at rest, in transit, and in use — each requiring its own security considerations to maintain confidentiality, integrity, and availability. Understanding these states is foundational to building a complete data protection strategy.
Data States & Protection
Our data lives in different data states, and by understanding what states data lives in, we can better protect each one of those states.
When we think about protecting data, we think about protecting it with confidentiality — making sure that others can't see this that aren't supposed to see it. We think about integrity, making sure that the data that we have remains accurate. And availability, making sure that it's available when we need it.
Also, when we're thinking about protecting data, we can think of what the different states of data are. One of them is just when it's being stored, when it's sitting still, when it's at rest, so we call this data at rest. Data at rest is when it's being stored on a hard drive, or maybe it's on a thumb drive, maybe it's not being processed but in a database. Those would be data at rest.
Then we have the data that's being moved, that's going from one location to another. This is data in transit. This is when bits are flying back and forth between the source and the destination, and that data is being transferred or moved.
Then we have the in-between, where it's being processed, where data is maybe on the processor being processed, or maybe somebody actually has that document up on their screen and is utilizing that document. So that's data in process.
Let's say I have a document that's stored up in Google Docs, and this document is up in the cloud. Then that data is data at rest. What I'm going to do is open it up, and so that's going to open up on my computer. Well, in between, as it's flowing to my computer, it's being transferred to my computer — that's data in transit. And then when it's up on my computer, that is data in use.
I need to think about all of these processes, all these steps in here, to think about security: what happens at each one of these steps. In fact, as I mentioned, we need to think about confidentiality, integrity and availability, and we need to think about that at rest, in process, and in transit.
Because of this, what I have is a model that I compare. Well, how are we going to think about confidentiality when it's at rest? How are we going to think about integrity when it's at rest? How are we going to think about availability when it's at rest? We're going to do the same thing for in process and in transit. So we're thinking about all these different aspects of how we're going to protect data, no matter what is happening to it or where it's at.
We should also think about what the whole process looks like from a big picture. For instance, I might have some sort of database on this backend. Well, I have data at rest at any given time in there. And then what happens is maybe I have a bank of web servers, and so what will happen is these web servers will request certain information. It'll become in transit — that data is in transit. It gets processed, maybe on these web servers, and then perhaps it gets sent to the end user, so then it's data in transit again. And then it's on the end user machine, so maybe it's in use at that point in time. Maybe that user saves it to the hard drive; now it's data at rest again. So I need to be thinking about this whole process and what happens through here when we're sending data.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →