Discovering Sensitive Data - Satori

Discovering Sensitive Data

In this chapter we'll provide information about Sensitive Data, and cover the following topics:

  1. What is Classified As Sensitive Personal Data?
  2. Types of Sensitive Data
  3. Is Proprietary Data Sensitive Information?
  4. Where Should Sensitive Data Be Stored?
  5. Monitoring Sensitive Data

Sensitive data is any confidential data stored or processed by an organization. Data sensitivity may be internal or external:

What is Classified As Sensitive Personal Data?

Sensitive personal data can be defined in several ways based on different regulations and locations but is generally any data about a certain person that is deemed private information.

For example, in GDPR, data is considered sensitive personal data when it includes:

Types of Sensitive Data

Sensitive data can be divided into three main categories:

Sensitive business data

Any non-public and non-routine data within a company. It is debatable whether the data sensitivity depends on the damage created if exposed.

Examples:

Classified data

Any information which is restricted due to security reasons.

Examples:

Personal data

Any data that can be linked to individuals and is not publicly accessible.

Examples:

Of course, each regulation categorizes sensitive data differently and has varied definitions of each of these data types.

A practical approach is using such regulations and frameworks to define the types of sensitive data in the organization. For example, "HIPAA data" is any data considered sensitive by HIPAA (Health Insurance Portability and Accountability Act) and "PCI data" is any data considered sensitive by PCI DSS (Payment Card Industry Data Security Standard).

Note that certain data may fall under two or more classifications. For example, a credit card number is both a PII data (as it can identify a person) and sensitive PCI data.

Is Proprietary Data Sensitive Information?

In most cases, proprietary data is considered sensitive business information. As described above, sensitive business information is non-public and non-routine which usually also applies to proprietary information.

Where Should Sensitive Data Be Stored?

In most cases, there is not a single solution to where sensitive data should be stored, but the following guidelines may help:

If the sensitive data is not required by the organization, it becomes a liability with no value and should, therefore, not be stored.

In other cases, it is extremely important to address the following questions:

This list can help you make great progress in effectively storing your sensitive data but is very generic.

Monitoring Sensitive Data

Sensitive data is not a static object that remains in its place waiting to be discovered. Rather, it is a moving target, with sensitive data being constantly inserted, transformed, and relocated. Therefore, it is important to: