What counts as sensitive data
Sensitive data is not one category with one owner. Each kind carries a different obligation from a different source, and an organization that has not separated them cannot protect any of them deliberately.
Ideas and field notes
Practical writing about cybersecurity, compliance, and sustainable security operations.
Sensitive data is not one category with one owner. Each kind carries a different obligation from a different source, and an organization that has not separated them cannot protect any of them deliberately.
Audit practice ranks evidence by how far it sits from the party with an interest in the outcome. Organizations can choose what their procedures produce, and stronger evidence usually costs no more than weak evidence.
An annual review should test a policy against current obligations and operations, then record decisions, evidence, owners, and follow-up work. Most standards require the review; few organizations get full value from it.
Workstations and servers can be enumerated by the tools that configure them. The outsourced systems holding company data are where an inventory usually stops being accurate.
A useful policy and/or procedure identifies the evidence that will show whether the organization is actually following it.
A policy states what the organization will do; its procedures state how, who, and with what. Keeping them apart makes both usable and keeps neither one stale.