2.6 Data Security Controls
Data Security Controls at a glance
Data needs different protection depending on what it is, where it is, what is happening to it and which security or compliance requirements apply.
Effective data security therefore starts by understanding the data, determining its state and applicable requirements, and then selecting controls that appropriately reduce the risk.
At Rest
Data stored on disks, databases, backups or other repositories.
Where is it STORED?In Transit
Data moving between systems, users, applications or networks.
Where is it MOVING?In Use
Data actively being processed by applications and systems.
How is it being PROCESSED?Data Security Control thinking flow
1 What are Data Security Controls? Measures that protect information according to its requirements
Data security controls are safeguards used to protect information against threats such as unauthorised disclosure, modification, destruction or inappropriate use.
Controls may be:
Examples include:
The objective is not to deploy as many security technologies as possible.
Controls should address the sensitivity, risk, state and applicable requirements of the data.
2 The Three Data States At rest ยท In transit ยท In use
One of the most important concepts in CISSP Domain 2 is recognising that data exists in different states and that each state introduces different security considerations.
Data stored on persistent or other storage rather than actively moving between systems.
Data moving between users, systems, applications or network locations.
Data actively being processed, manipulated or consumed by a system or application.
Data States memory aid
Stored. Moving. Processing.
3 Data at Rest Protect information while it is stored
Data at rest includes information stored in locations such as:
Typical protection considerations
Protect stored information against unauthorised disclosure.
Restrict which users, applications and services may access it.
Protect devices and storage media against theft or unauthorised access.
Obscure sensitive values where full information is not required.
Replace sensitive values with substitute tokens where appropriate.
Detect unauthorised or accidental modification where required.
A laptop contains confidential customer information.
The laptop is stolen from a train.
Appropriate full-disk encryption can substantially reduce the risk that someone obtaining the physical device can read the stored data, assuming the encryption and credentials remain secure.
Once an authorised user has unlocked the system, other controls still determine what that user may access and do.
4 Data in Transit Protect information while it moves
Data in transit is information moving between systems, devices, networks or users.
Examples
Protection may include
A customer submits their payment information through a website.
The information travels from the customer's browser to the web application.
Appropriate transport protection can help prevent interception or unauthorised modification while the information is moving.A secure connection between the customer and web server does not automatically protect every connection that occurs later between the application, API, database and external services.
Secure network protocols are covered more deeply in CISSP Domain 4 and cryptographic mechanisms in Domain 3.
5 Data in Use Protect information while systems actively process it
Data in use is actively being processed by an application, operating system, processor or user.
This can be particularly challenging because a system normally needs usable access to information in order to process it.
Restrict which identities and processes may access information.
Prevent applications from exposing or manipulating information inappropriately.
Limit inappropriate access between executing processes.
Reduce unauthorised access to data held during processing.
Monitor or control how sensitive information is being used.
Display only the information required for a particular purpose.
A database is encrypted at rest.
When an authorised application queries a customer record, the application needs access to usable data in order to process the request.
Protecting storage does not automatically protect every situation in which the decrypted data is being used.Encrypting storage and network traffic is important, but data also needs protection while applications and users actively process it.
๐ Data constantly changes state The same information may move through all three states within seconds
Data security should consider the complete processing flow rather than looking at one database or one network connection in isolation.
Data states compared
| State | Simple meaning | Example | Possible controls |
|---|---|---|---|
| At Rest | Stored | Database or backup | Encryption, access control, physical protection |
| In Transit | Moving | API request | TLS, secure protocols, VPN, integrity protection |
| In Use | Being processed | Customer record loaded by an application | Access control, application security, process and memory protection |
6 Determine Security and Compliance Requirements Why does this data need protection?
Data security requirements may originate from several different sources.
The organisation may need particular information protected to support its objectives.
Laws may create obligations relating to information protection.
Regulators may establish requirements relevant to particular data or sectors.
Customers and partners may require specified protections.
Applicable standards may establish security expectations.
Organisational policies translate requirements into internal expectations.
An application processes payment-card information.
Its security requirements may reflect:
- business risk;
- contractual obligations;
- applicable payment-card standards;
- internal security policies;
- relevant legal and privacy requirements.
Meeting a particular compliance requirement does not automatically prove that every relevant security risk has been addressed.
From requirement to control
7 Scoping Determine where the requirement applies
Scoping determines which systems, applications, data, people, processes, locations and technologies fall within the boundary of a particular security or compliance requirement.
An organisation identifies a database containing regulated information.
Scoping only the database itself may be insufficient.
Relevant scope may also include:
- the application accessing it;
- administrative workstations;
- backup systems;
- network connections;
- cloud services;
- third parties handling copies.
A control cannot reliably protect a system or data flow that was accidentally excluded from consideration.
๐ฏ Reduce Scope by Architecture โ not by Assumption Smaller scope can be useful when legitimately engineered
Organisations may sometimes reduce the number of systems exposed to sensitive information through architecture and segmentation.
Instead of allowing dozens of business systems to store payment-card information, an organisation centralises that information within a dedicated payment platform.
Other systems receive only the minimum information they require.
Reducing unnecessary handling of sensitive data can reduce both attack surface and compliance complexity.The architecture and actual data flows must support the scoping decision.
8 Tailoring Adapt controls to the real environment
Security-control frameworks may provide a baseline or starting set of controls.
Tailoring adapts that starting point to the organisation, system, technology, environment and risk.
Tailoring may involve
A security-control baseline requires physical protection for certain infrastructure.
One system operates entirely within a cloud service and has no organisation-owned physical server.
Tailoring considers how the underlying security objective applies in the actual environment and which responsibilities are handled by the cloud provider or customer.
Tailoring should be reasoned, documented and consistent with applicable requirements and risk.
Scoping vs Tailoring
Scope the boundary. Tailor the controls.
9 Standards Selection Select standards appropriate to the requirement and environment
Organisations may use recognised security standards and control frameworks to help establish appropriate data-security requirements.
Selection should reflect factors such as:
Examples of relevant standards and frameworks
Information-security management and control guidance.
Extensive catalogue of security and privacy controls.
Security requirements relevant to payment-card environments.
Internal technical standards can translate broader requirements into consistent implementation.
The objective is not to apply every security standard in existence to every system.
๐ Control Baselines A starting point for control selection
A control baseline provides an initial set of controls that can then be evaluated and tailored for the particular environment.
10 Data Loss Prevention (DLP) Detect and control inappropriate use or movement of sensitive data
Data Loss Prevention technologies help identify sensitive information and monitor or control how it is stored, used and transmitted.
DLP can address several data states
Discover sensitive files stored in repositories or endpoints.
Detect sensitive information being transmitted through monitored channels.
Monitor endpoint actions such as copying or moving sensitive information.
Possible DLP actions
An employee attempts to email a spreadsheet containing thousands of customer records to a personal email account.
DLP identifies sensitive patterns within the attachment and blocks the transmission.
DLP policy should reflect business processes, classification and risk so that legitimate work can continue while inappropriate data movement is controlled.
๐ How DLP recognises sensitive information Content and context can both matter
Different DLP implementations can use multiple techniques to determine whether information is sensitive.
Sending a confidential document to an approved internal repository may be acceptable.
Sending the same document to a personal file-sharing account may trigger a DLP response.
The data may be identical while the destination changes the risk.โ๏ธ DLP False Positives and False Negatives Detection controls require tuning
Legitimate information is incorrectly identified as violating DLP policy.
Sensitive information that should have been detected passes without being identified.
Excessive false positives can encourage users to ignore warnings, while false negatives allow actual sensitive-data movement to go undetected.
11 Digital Rights Management (DRM) Control what authorised recipients may do with digital content
Digital Rights Management applies controls to digital information that can continue to govern how the content may be used after it has been distributed.
DRM may restrict actions such as
A confidential strategy document is sent to an external adviser.
DRM controls allow the adviser to view it but prevent ordinary printing and forwarding, and access expires after the engagement.
A recipient may legitimately be allowed to view information without being allowed to copy, print or redistribute it.
๐ DRM vs Access Control Who gets access vs what they may do afterwards
Determines whether an identity is permitted to access a resource.
Can impose ongoing usage restrictions on the protected digital content.
Easy distinction
12 Cloud Access Security Broker (CASB) Visibility and policy control around cloud-service use
A Cloud Access Security Broker provides security capabilities around an organisation's use of cloud services.
Depending on the implementation, CASB capabilities can help provide:
Understand which cloud services users are accessing.
Apply policies to sensitive information being placed into cloud services.
Control actions based on user, service, device or data context.
Identify suspicious activity associated with cloud-service use.
An employee attempts to upload a confidential customer dataset to an unapproved cloud-storage service.
A cloud-security control identifies the service and data sensitivity and prevents the upload according to organisational policy.
It helps organisations apply security policy in environments where users access cloud services outside traditional on-premises boundaries.
DLP vs DRM vs CASB
| Technology | Think | Primary idea |
|---|---|---|
| DLP | Stop inappropriate data movement | Identify sensitive information and detect or prevent inappropriate use or transmission. |
| DRM | Control usage rights | Restrict what authorised recipients may do with protected digital information. |
| CASB | Control cloud use | Provide visibility and policy enforcement around access to cloud services. |
DLP ยท DRM ยท CASB memory aid
DLP = DATA ยท DRM = RIGHTS ยท CASB = CLOUD
13 Encryption Protect confidentiality by making information unreadable without the appropriate key
Encryption is one of the most important technical controls for protecting sensitive information.
Disk, file, database and backup encryption may protect stored data.
Secure protocols can encrypt information moving between systems.
A database is encrypted at rest and communications to the application use encrypted transport.
An administrator with excessive database privileges can still query customer records through authorised system interfaces.
Encryption does not eliminate the need for access control.Depending on the mechanism, additional or integrated controls may be required to provide integrity and authentication.
Algorithms, cryptographic key lifecycle, PKI and cryptographic architecture belong primarily in CISSP Domain 3.
๐ Encryption is only as useful as its Key Management Protect the means of decrypting the data
A database backup is strongly encrypted.
The decryption key is saved in a text file beside the backup.
The encryption exists technically, but the surrounding protection is weak.When encryption is selected as a control, consider the complete cryptographic lifecycle rather than merely whether an "encrypt" checkbox is enabled.
14 Tokenisation Replace sensitive values with substitute tokens
Tokenisation replaces a sensitive value with a substitute value or token.
Systems that do not require the original sensitive value may use the token instead.
An application does not need to store a customer's actual card number after the initial payment process.
It stores a token representing that payment instrument instead.
Fewer systems therefore need direct access to the original sensitive value.๐ Encryption vs Tokenisation Both can protect data, but they work differently
Transforms data cryptographically so that the original can be recovered using appropriate cryptographic key material.
Substitutes the sensitive value with a token and relies on an appropriate tokenisation system or mapping where retrieval is required.
The appropriate technique depends on the business process, data, architecture and security requirements.
15 Data Masking Reveal only the information that needs to be visible
Data masking obscures or replaces sensitive information so that users or systems do not receive the complete original value.
Original: 4929 1234 5678 9999
Displayed: **** **** **** 9999
Developers need realistic customer data structures but do not require real customer identities.
Sensitive fields can be appropriately masked or replaced before the dataset is used in development.
A customer-service employee may need the last four digits of an account number without needing the complete value displayed on screen.
โ๏ธ Reduce Exposure of Sensitive Data Sometimes the best control is to minimise where the original data exists
Security becomes easier when fewer users and systems require direct access to sensitive information.
The fewer locations containing the original sensitive information, the fewer locations need the strongest associated controls.
๐ค Access Control as a Data Security Control Protect data according to authorised business need
Data security should control both:
Identity, role and business need matter.
View, modify, copy, export and delete may require different permissions.
A call-centre employee may need to view a customer's address.
They do not necessarily require permission to export the entire customer database.
Detailed access-control models and technologies are covered in CISSP Domain 5.
โ Integrity Controls Data security is not only about confidentiality
Data-security controls should also consider whether information can be modified improperly.
Published software is available publicly.
Confidentiality is not the goal โ users are supposed to download it.
Integrity and authenticity may be extremely important because users need confidence that the software has not been maliciously modified.โก Availability Controls Protected data also needs to be usable when required
Data-security requirements should consider what happens if authorised users cannot access important information.
Medical information is perfectly encrypted and restricted from unauthorised access.
A system failure makes the information unavailable to clinicians during an emergency.
Strong confidentiality controls do not compensate for unacceptable loss of availability.๐งฑ Use Layered Data Protection Do not depend on one control
Effective data protection normally combines multiple safeguards addressing different risks and failure modes.
๐๏ธ Monitoring and Logging Understand how sensitive data is being accessed
Preventive controls should often be complemented by monitoring capable of identifying unusual or inappropriate activity.
Useful events might include
A user normally accesses 20 customer records per day.
The same account suddenly downloads 250,000 customer records shortly before midnight.
Appropriate monitoring may identify the behaviour even if the account technically had permission to access the records.โ๏ธ Data Security in Cloud Services Cloud changes responsibility โ not the need for security
Moving data to a cloud provider does not remove the organisation's need to understand how that information is protected.
Questions include
The provider may protect infrastructure while the customer remains responsible for areas such as data classification, identities, permissions and configuration depending on the service model.
16 Selecting the Right Data Security Control Match protection to risk and requirement
Understand sensitivity and criticality.
At rest, in transit or in use?
Disclosure, modification, loss, exfiltration or misuse?
Business, legal, contractual, regulatory or policy?
Understand existing controls before adding more.
Does the proposed control reduce risk sufficiently?
Do not select encryption simply because a question contains the word "data."
First understand the problem the control is supposed to solve.
Which control solves which problem?
| Problem | Possible control |
|---|---|
| Stolen laptop exposes stored data | Encryption at rest |
| Network traffic may be intercepted | Encrypted transport |
| User emails confidential file externally | DLP |
| Recipient should view but not freely copy a document | DRM |
| Organisation needs visibility of cloud-service use | CASB / cloud security controls |
| Help desk only needs last four digits | Data masking |
| Application does not need original sensitive identifier | Tokenisation |
| User should not access entire dataset | Access control |
โ ๏ธ Understand Control Limitations Security technologies solve particular problems, not every problem
Does not automatically prevent an authorised but malicious user from reading information through an application.
Cannot guarantee identification of every possible sensitive-data movement and requires appropriate policy and tuning.
Can restrict supported digital actions but cannot eliminate every possible way information might be captured or disclosed.
Provides useful cloud security capabilities but does not eliminate the need for secure cloud configuration, identity controls and provider governance.
Does not automatically protect underlying source data if users or systems retain another path to the original value.
โ ๏ธ Common mistakes Data-security assumptions that often lead to poor decisions
Encryption is important, but access control, integrity, availability, monitoring and handling controls may still be required.
Applications and authorised users generally need access to usable information. Encryption at rest does not prevent every form of misuse.
Data in use is also explicitly part of the CISSP objective.
TLS can protect a communication channel but does not automatically secure endpoints, application logic or stored data.
DLP is Data Loss Prevention, focused on identifying and controlling sensitive-data use and movement. It is not a backup technology.
DLP capabilities may address data at rest, in transit and in use.
DLP focuses on inappropriate data use or movement, while DRM focuses on usage rights associated with protected digital content.
CASB is particularly associated with visibility and policy controls around cloud-service use.
Compliance demonstrates alignment with particular requirements. Risk may still exist outside those requirements.
Scope should reflect the real applicability of the requirement and actual data flows.
Tailoring should adapt controls appropriately based on applicability, environment and risk.
Standards should be selected according to applicable requirements, environment and business need.
Encryption cryptographically transforms information, while tokenisation substitutes sensitive values with tokens through a different architecture.
The original underlying information may still exist elsewhere and require strong protection.
Responsibility depends on the service model and agreement. Customers commonly retain significant responsibilities for their own data, identities and configurations.
Controls should be proportionate to the business requirement, data, threat, risk and applicable obligations.
Identify the state, requirement and problem before choosing the control
CISSP questions in this area often describe sensitive information and ask which protection is most appropriate.
First determine:
- what data is involved;
- which state it is in;
- what requirement applies;
- what threat or problem is being addressed;
- which control most directly addresses that problem.
๐พ Rest clues
โ๏ธ Transit clues
โ๏ธ Use clues
๐ง DLP clues
๐ DRM clues
โ๏ธ CASB clues
๐ฏ Scope clues
โ๏ธ Tailoring clues
๐ Standards clues
What data? What state? What requirement? What threat? What control?
๐ Practice scenarios Apply data-security-control thinking
Scenario 1
Customer records are stored within a database.
Which data state applies?
Data at rest.
Scenario 2
Customer information moves from a web application to an API.
Which state applies during the transfer?
Data in transit.
Scenario 3
An application loads a customer's record into memory while processing a request.
Which state applies?
Data in use.
Scenario 4
A stolen laptop contains highly sensitive information.
Which control can significantly reduce disclosure risk from the stored data?
Appropriate encryption at rest, together with suitable authentication and key protection.
Scenario 5
An employee tries to email thousands of customer records to a personal account.
Which technology is particularly relevant?
Data Loss Prevention.
Scenario 6
An external consultant may view a confidential document but should not normally print or forward it.
Which technology is particularly relevant?
Digital Rights Management.
Scenario 7
Security wants greater visibility into employees uploading data to SaaS applications.
Which technology is particularly relevant?
A Cloud Access Security Broker or equivalent cloud-security capability.
Scenario 8
A customer-service employee needs only the final four digits of a payment card displayed.
Which technique is particularly suitable?
Data masking.
Scenario 9
Several applications need to reference a payment instrument but do not need the original card number.
Which technique may reduce exposure of the original sensitive value?
Tokenisation.
Scenario 10
An organisation applies a recognised security-control baseline.
It then adjusts applicability, parameters and compensating controls for its particular system.
What process is occurring?
Tailoring.
Scenario 11
A compliance programme identifies which applications, databases, networks and service providers process the relevant regulated data.
What process is this?
Scoping.
Scenario 12
A team excludes a server from compliance scope because assessing it would be expensive.
The server actually processes the regulated information.
Is this valid scoping?
No. Scope should reflect actual applicability and data flows rather than convenience.
Scenario 13
A database is strongly encrypted at rest.
An administrator has excessive privileges and exports all records.
Why did encryption not prevent this?
Encryption at rest does not replace appropriate access control for authorised system use.
Scenario 14
DLP produces thousands of alerts about legitimate documents every day.
What issue is likely present?
Excessive false positives and insufficient policy tuning.
Scenario 15
An organisation complies fully with one industry standard but discovers a serious security risk not addressed by that standard.
Can the organisation ignore it because it is compliant?
No. Compliance with one set of requirements does not automatically eliminate other security risks.
Scenario 16
Data is encrypted while stored and while transmitted.
A vulnerable application exposes the decrypted data while processing it.
Which data state has become the weakness?
Data in use.
Scenario 17
A company applies the maximum possible security controls to all information regardless of classification.
Is this necessarily the best approach?
No. Controls should be proportionate to requirements, sensitivity, risk and business needs.
Scenario 18
An organisation centralises sensitive payment data and allows other business applications to use tokens instead of storing the original values.
What security benefit can this provide?
Fewer systems directly handle the original sensitive data, reducing unnecessary exposure and potentially simplifying security scope.
Data Security Control memory aid
Understand. Scope. Protect. Validate.
Technology memory aid
Encrypt. Monitor. Restrict. Minimise.
Key takeaways
CISSP objective 2.6 covers data states, scoping and tailoring, standards selection, data-security controls and compliance requirements.
Data exists in three important states: at rest, in transit and in use.
Data at rest is stored.
Data in transit is moving between systems or locations.
Data in use is actively being processed.
The same information may move through all three states during a single business transaction.
Protecting one data state does not automatically protect the others.
Encryption can protect data at rest and in transit, but access controls and application protections are still needed when authorised systems use the information.
Security requirements can originate from business, legal, regulatory, contractual, industry and organisational sources.
Scoping determines where a requirement applies.
Tailoring adapts an appropriate baseline or control set to the actual system, environment and risk.
Tailoring should not simply be used to remove inconvenient controls.
Standards should be selected according to relevant requirements rather than indiscriminately applying every available framework.
DLP helps detect and control inappropriate storage, use or movement of sensitive information.
DLP can operate across data at rest, in transit and in use.
DRM helps restrict how authorised recipients can use protected digital information.
CASB provides visibility and policy-control capabilities around organisational use of cloud services.
Masking reduces unnecessary visibility of sensitive values.
Tokenisation allows some systems to operate using substitute values instead of directly storing the original sensitive information.
Encryption is extremely important but does not replace access control, monitoring, integrity controls or appropriate key management.
Compliance should be treated as an important security requirement rather than evidence that every possible security risk has disappeared.
Data-security controls should be selected according to the actual problem being addressed.
Most importantly: understand the data, understand its state, understand the requirement, and then select controls that protect it throughout the complete processing flow.
Asset Security
You have reached the end of CyberPrepHub's Asset Security learning section.
Domain 2 follows information and assets from identification and classification through handling, ownership, lifecycle management, retention and technical protection.
The Domain 2 story
Know it. Classify it. Manage it. Protect it. Retire it.
๐ Sources & Further Reading Authoritative references
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - NIST SP 800-53 Rev. 5 โ Security and Privacy Controls for Information Systems and Organizations
View NIST publication - NIST SP 800-53B โ Control Baselines for Information Systems and Organizations
View NIST control-baseline and tailoring guidance - NIST SP 800-215 โ Guide to a Secure Enterprise Network Landscape
View NIST cloud and enterprise-network guidance - NIST โ Data Loss Prevention
View NIST DLP definition - NIST โ Data at Rest
View NIST terminology - NIST โ Data in Transit
View NIST terminology - NIST โ Tailoring
View NIST definition - NIST โ Data Masking
View NIST definition
