Data protection

Data protection safeguards information from corruption, compromise, or loss.

Classification

Set by the data owner based on value and sensitivity. Over-classifying wastes money by protecting everything at the top level.

The commercial ladder:

The government ladder: unclassified, sensitive but unclassified, confidential, secret (military plans), top secret (national security).

Ownership roles

The three states

Data types and sovereignty

The types: regulated data (GDPR, HIPAA), PII (identifies a person), PHI (health, HIPAA), trade secrets, intellectual property (patents, copyrights, trademarks), legal info, financial info (PCI DSS). Also human-readable vs non-human-readable (binary needs software to interpret).

Data sovereignty: data is subject to the laws of the country it sits in. GDPR protects EU citizens’ data regardless of where it’s stored, and some countries (China, Russia) require data to stay within their borders. Geofencing helps enforce this.

Securing methods

Geographic restrictions (geofencing), encryption (reversible with a key), hashing (one-way, for passwords), masking (replace with placeholders, irreversible), tokenization (swap sensitive data for tokens, the original held separately, big in payments), obfuscation (make it unintelligible), segmentation (limit lateral movement), and permission restrictions (ACLs, RBAC).

Data loss prevention

DLP monitors data in use, in transit, and at rest to stop theft. The four deployment points: