Certified Cloud Security Professional (CCSP)Cloud Data SecurityEasy
A company is planning to migrate its on-premises database containing sensitive customer information to a public cloud environment. Before migration, they need to identify all instances of personally identifiable information (PII) and protected health information (PHI) within their existing unstructured and structured data stores across various departments. Which process is crucial for achieving this goal?
- AData Discovery
- BData Archiving
- CData Retention Policy Enforcement
- DData Replication
Show answer & explanationAnswer & explanation
Correct answer: A. Data Discovery
Data discovery is the process of identifying and locating specific types of data (like PII or PHI) across an organization's various data stores, which is essential before migrating sensitive data to the cloud to understand what needs protection.
Why the other options are wrong
- B. Data archiving is for moving inactive data to long-term storage, not for initial identification of sensitive data.
- C. Data retention policy enforcement defines how long data is kept, not for identifying sensitive data types.
- D. Data replication copies data for availability or disaster recovery, but doesn't identify sensitive data types within it.
Data Discovery
The process of identifying, locating, and mapping sensitive data across an organization's IT environment, including structured and unstructured data stores, to understand its prevalence and ensure proper protection.
- Identifies sensitive data locations.
- Works across structured and unstructured data.
- Crucial first step for data protection initiatives.
- Helps with compliance and risk assessment.
Memory trick: Discovery is like finding hidden treasure before you move the map.