Skip to content
DAT9 finding classes

Data Protection

What happens to the data if everything else fails?

The Data domain covers the controls that determine blast radius. Every other domain is about preventing access; this one is about limiting what access is worth. Encryption, classification, retention, and injection defence decide whether a compromise is an incident or a notifiable breach.

What this domain covers

  • Encryption at rest and in transit, and key management
  • Injection defence in data-access paths
  • Data classification and inventory
  • Retention, deletion, and data-subject rights
  • Backup integrity, isolation, and restoration testing

Distribution across tiers

Tier 1 · Critical3 · 24–72 hours
Tier 2 · Regulatory3 · 30 days
Tier 3 · Best Practices3 · 90 days

Typically owned by Data platform / application engineering.

Tier 1 · CriticalCould an external attacker use this to gain access, escalate privilege, or take data — today, without an insider and without a chain of unlikely events?
Tier 2 · RegulatoryWould a named auditor, regulator, or contractual counterparty record this as a deficiency?
Tier 3 · Best PracticesDoes fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?

Other domains