TechKnowSurge
NIST CSF PR.DS-01 NIST CSF PR.DS-02 NIST CSF PR.DS-10 CompTIA Security+ 3.3 NIST NICE K0728 ISC2 CISSP 2.6
VideoSecurityFree

Data States

Data exists in three distinct states — at rest, in transit, and in use — each requiring its own security considerations to maintain confidentiality, integrity, and availability. Understanding these states is foundational to building a complete data protection strategy.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data exists in three distinct states, and each state presents its own security challenges. Data at rest refers to information that is stored but not actively being processed — sitting on a hard drive, a USB device, or in a cloud database. Data in transit is any data actively moving between a source and a destination, such as files being transferred across a network. Data in use, sometimes called data in process, refers to data that is currently being accessed or processed, such as a document open on a user's screen or records being handled by an application server. A practical way to understand how these states interact is to trace a single piece of data through a full workflow. A document stored in a cloud service is data at rest. The moment a user requests it, it becomes data in transit as it travels from the cloud to their device. Once open and active on their screen, it is data in use. If the user saves a local copy, it returns to a state of rest. Security must account for every transition in that chain, not just the endpoints. Applying the core principles of confidentiality, integrity, and availability to each data state creates a comprehensive protection model. Confidentiality controls prevent unauthorized access whether data is stored, moving, or in active use. Integrity measures ensure accuracy is maintained across all three states. Availability planning ensures data can be accessed reliably at every stage of its lifecycle. Thinking across all three states and all three principles together is what separates a complete data security approach from a partial one.

What you'll learn

What's covered

Data States & Protection

Aligned to

NIST CSF
PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected.
PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected.
PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected.
CompTIA Security+
3.3 Compare and contrast concepts and strategies to protect data.
NIST NICE
K0728 Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices
ISC2 CISSP
2.6 Determine data security controls and compliance requirements

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Data at Rest
Data that is stored on a device or medium and not actively moving through a network, which can be encrypted at the disk, partition, volume, file, or database level.
Data in Transit
Data that is actively moving across a network or communication channel between two endpoints, as opposed to data sitting on a storage device. Protocols such as TLS are commonly used to encrypt data in transit so it cannot be read if intercepted.
Data in Use
Data actively being processed or accessed, such as data moving through a processor or physically reviewed, which must be secured against unauthorized exposure.

Topics

Data States Data At Rest Data In Transit Data In Use Cia Triad Data Protection Cybersecurity

Transcript

Protecting Data

Our data lives in different data states, and by understanding what states data lives in, we can better protect each one of those states.

When we think about protecting data, we think about protecting it with confidentiality — making sure that others can't see this that aren't supposed to see it. We think about integrity, making sure that the data that we have remains accurate. And availability, making sure that it's available when we need it.

The Three States

Also, when we're thinking about protecting data, we can think of what the different states of data are. One of them is just when it's being stored, when it's sitting still, when it's at rest, so we call this data at rest. Data at rest is when it's being stored on a hard drive, or maybe it's on a thumb drive, maybe it's not being processed but in a database. Those would be data at rest.

Then we have the data that's being moved, that's going from one location to another. This is data in transit. This is when bits are flying back and forth between the source and the destination, and that data is being transferred or moved.

Then we have the in-between, where it's being processed, where data is maybe on the processor being processed, or maybe somebody actually has that document up on their screen and is utilizing that document. So that's data in process.

An Example

Let's say I have a document that's stored up in Google Docs, and this document is up in the cloud. Then that data is data at rest. What I'm going to do is open it up, and so that's going to open up on my computer. Well, in between, as it's flowing to my computer, it's being transferred to my computer — that's data in transit. And then when it's up on my computer, that is data in use.

I need to think about all of these processes, all these steps in here, to think about security: what happens at each one of these steps. In fact, as I mentioned, we need to think about confidentiality, integrity and availability, and we need to think about that at rest, in process, and in transit.

Because of this, what I have is a model that I compare. Well, how are we going to think about confidentiality when it's at rest? How are we going to think about integrity when it's at rest? How are we going to think about availability when it's at rest? We're going to do the same thing for in process and in transit. So we're thinking about all these different aspects of how we're going to protect data, no matter what is happening to it or where it's at.

The Big Picture

We should also think about what the whole process looks like from a big picture. For instance, I might have some sort of database on this backend. Well, I have data at rest at any given time in there. And then what happens is maybe I have a bank of web servers, and so what will happen is these web servers will request certain information. It'll become in transit — that data is in transit. It gets processed, maybe on these web servers, and then perhaps it gets sent to the end user, so then it's data in transit again. And then it's on the end user machine, so maybe it's in use at that point in time. Maybe that user saves it to the hard drive; now it's data at rest again. So I need to be thinking about this whole process and what happens through here when we're sending data.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →