Data has a life. It is created, lives in storage, gets used and shared, may be archived for years and eventually should be destroyed. Different risks and controls apply at each stage, and a CISSP should be able to say which controls fit where. A widely used model, popularized by the Cloud Security Alliance, has six phases: create, store, use, share, archive and destroy. Thinking in phases helps you spot gaps, such as data that is carefully encrypted in storage but freely emailed when shared, or data that is never destroyed at all.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.