ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium
An organization is migrating its on-premises customer database, containing PII, to a public cloud environment. Before the migration, a data governance committee determines that certain fields, such as customer names and email addresses, must be obfuscated or replaced with fictitious data for all non-production environments (development, testing, QA). Which data security control is being applied here?
- AData encryption in transit
- BData loss prevention (DLP)
- CData masking
- DTokenization
Show answer & explanationAnswer & explanation
Correct answer: C. Data masking
Data masking (or data obfuscation) is the process of hiding original data with modified content. It creates a structurally similar but inauthentic version of data that can be used for purposes like testing or training in non-production environments, where real sensitive data is not required, thus protecting PII while maintaining data utility.
Why the other options are wrong
- A. Encryption in transit protects data while it's moving, not while it's at rest or being used in non-production environments.
- B. DLP aims to prevent sensitive data from leaving authorized boundaries, but data masking actively transforms the data for safe use in non-production environments.
- D. Tokenization replaces sensitive data with a unique, non-sensitive identifier (token), typically used for payment card data in production, not for creating realistic test data.
Data Masking
A technique used to create a structurally similar but inauthentic version of sensitive data, used primarily in non-production environments (e.g., development, testing) to protect real PII while maintaining data utility.
- Replaces sensitive data with fictitious data.
- Preserves data format and type for application compatibility.
- Used to protect PII in non-production environments.
Memory trick: Mask for tests, Encrypt for rest.