SlideShare a Scribd company logo
Data Lifecycle: Risk Considerations and Controls
October, 2013
Data Lifecycle
Risk Considerations and Controls
Carlos Chalico
CISA, CISSP, CISM, CGEIT, CRISC, ISO27000 LA,
PbD Ambassador	

Ouest Business Solutions Inc.
Director Eastern Region
2
@CarlosChalicoT
#ISACA_DDay
What´s in this for you?
By the end of this session you will:	

• Understand the concept of data and general
considerations regarding its classification.	

• Know some of the risks data faces in a data
management lifecycle.	

• Challenge the relationship between business
activities and human behaviour when managing data.
3
First things first
4
Title: 
Elephant In The Room
Artist: 
Leah Saulnier The Painting Maniac
Medium:
Painting - Oil
So, what does this mean?
DATA
5
@CarlosChalicoT
#ISACA_DDay
Data (Wikipedia)
Data (/ˈdeɪtə/ DAY-tə, /ˈdætə/ DA-tə, or /ˈdɑːtə/ DAH-tə) are values of
qualitative or quantitative variables, belonging to a set of items. Data in
computing (or data processing) are represented in a structure, often tabular
(represented by rows and columns), a tree (a set of nodes with parent-children
relationship) or a graph structure (a set of interconnected nodes). Data are
typically the results of measurements and can be visualised using graphs or
images. Data as an abstract concept can be viewed as the lowest level of
abstraction from which information and then knowledge are derived. Raw
data, i.e., unprocessed data, refers to a collection of numbers, characters and
is a relative term; data processing commonly occurs by stages, and the
"processed data" from one stage may be considered the "raw data" of the next.
Field data refers to raw data collected in an uncontrolled in situ environment.
Experimental data refers to data generated within the context of a scientific
investigation by observation and recording.
!
The word data is the plural of datum, neuter past participle of the Latin dare,
"to give", hence "something given". In discussions of problems in geometry,
mathematics, engineering, and so on, the terms givens and data are used
interchangeably. Such usage is the origin of data as a concept in computer
science or data processing: data are numbers, words, images, etc., accepted as
they stand.
6
@CarlosChalicoT
#ISACA_DDay
Data (Wikipedia)
7
Data (/ˈdeɪtə/ DAY-tə, /ˈdætə/ DA-tə, or /ˈdɑːtə/ DAH-tə) are values of
qualitative or quantitative variables, belonging to a set of items. Data in
computing (or data processing) are represented in a structure, often tabular
(represented by rows and columns), a tree (a set of nodes with parent-
children relationship) or a graph structure (a set of interconnected nodes).
Data are typically the results of measurements and can be visualised using
graphs or images. Data as an abstract concept can be viewed as the lowest
level of abstraction from which information and then knowledge are derived.
Raw data, i.e., unprocessed data, refers to a collection of numbers, characters
and is a relative term; data processing commonly occurs by stages, and the
"processed data" from one stage may be considered the "raw data" of the next.
Field data refers to raw data collected in an uncontrolled in situ environment.
Experimental data refers to data generated within the context of a scientific
investigation by observation and recording.
!
The word data is the plural of datum, neuter past participle of the Latin dare,
"to give", hence "something given". In discussions of problems in geometry,
mathematics, engineering, and so on, the terms givens and data are used
interchangeably. Such usage is the origin of data as a concept in computer
science or data processing: data are numbers, words, images, etc., accepted
as they stand.
@CarlosChalicoT
#ISACA_DDay
Data
• Values of qualitative or quantitative variables.	

• Represented in a structure:	

- Tabular.	

- Tree.	

- Graph.	

• Results.	

• Lowest level of abstraction for information and
knowledge.	

• Numbers, words, images, accepted as they stand.
8
@CarlosChalicoT
#ISACA_DDay
Data
9
Data +Value = Information
KnowledgeDecision 	

Making
Failure
Success
Results
@CarlosChalicoT
#ISACA_DDay
Classifying Data
DATA
10
Process Sensitivity
IT Infrastructure
@CarlosChalicoT
#ISACA_DDay
Classifying Data: Process
11
Financial
Commercial
Strategic
Operational
Personal
Raw Unnecesary...
Combined
@CarlosChalicoT
#ISACA_DDay
Classifying Data: Sensitivity
Top Secret
Secret
Sensitive
Confidential
Proprietary
Public
12
@CarlosChalicoT
#ISACA_DDay
13
Top Secret
Secret
Sensitive
Confidential
Proprietary
Public
Financial
Financial
Financial
Financial
Financial
Financial
Classifying Data
Personal
Personal
Commercial
Commercial
Commercial
Strategic
Strategic
Strategic
Strategic
Strategic
Operational
Operational
Operational
Operational
Operational
Operational
Raw
Raw
Combined
Combined
Combined
@CarlosChalicoT
#ISACA_DDay
14
Classifying Data
15
Understanding Data Classification Based on Business and Security Requirements

ISACA Journal, 2006,Volume 5; Rafael Etges, CISA, CISSP and Karen McNeil
Classifying Data
@CarlosChalicoT
#ISACA_DDay
Data Lifecycle: Risk Considerations and Controls
October, 2013
Data - concept
Data - classification
Data Lifecycle
17
@CarlosChalicoT
#ISACA_DDay
Data Lifecycle Risks
Before	

!
During	

!
After
18
Confidentiality	

!
Integrity	

!
Availability
@CarlosChalicoT
#ISACA_DDay
Countermeasures
• Information Security Programs	

- COBIT	

- ISO27000	

- ISO38500	

- ITIL	

• Specific Controls	

- Data Loss Prevention	

- Awareness	

- Incident Response Management	

• Compliance
19
Governance
Corporate
IT
Data
@CarlosChalicoT
#ISACA_DDay
What about today?
20
New Trends
NewTrends
21
@CarlosChalicoT
#ISACA_DDay
NewTrends
22
@CarlosChalicoT
#ISACA_DDay
NewTrends
23
@CarlosChalicoT
#ISACA_DDay
Data Lifecycle: Risk Considerations and Controls
October, 2013
Data Lifecycle
Risks in data lifecycle
Countermeasures
Risks in new trends
NewTrends
25
@CarlosChalicoT
#ISACA_DDay
Where are we going?
• Real stories:	

- The ones capable of identifying who is pregnant.	

- The ones capable of knowing where you are without
letting you notice it.	

- The ones using your personal data for not intended
purposes without your consent.	

- The ones tweetting without taking care of its
company reputation.
26
@CarlosChalicoT
#ISACA_DDay
27
Where are we going?
Values
Behavioral
actions
Changing the Social Contract
@CarlosChalicoT
#ISACA_DDay
28
Where are we going?
Identity
Reputation
Privacy
Ownership
@CarlosChalicoT
#ISACA_DDay
Source: Ethics of Big Data, Kord Davis
29
Where are we going?
Take care of the
LIFESTREAM
Yours
Your
Organization’s
@CarlosChalicoT
#ISACA_DDay
Source: Ethics of Big Data, Kord Davis
Where are we going?
30
Inquiry
Analysis
Articulation
Action
@CarlosChalicoT
#ISACA_DDay
Ethics of
Big Data
Source: Ethics of Big Data, Kord Davis
Bibliography
31
@CarlosChalicoT
#ISACA_DDay
Data Lifecycle: Risk Considerations and Controls
October, 2013
What happens
Where we are going
Conclusions
• You need to know your data.	

• Data needs to be protected according to the process
they serve or support and also considering their
sensitivity.	

• COBIT 5 is a good framework to define controls
related to data classification and protection.	

• Data faces risks all over their lifecycle.	

• Countermeasures defined shall be alligned to
corporate and IT governance.
33
@CarlosChalicoT
#ISACA_DDay
Conclusions
• New technologies and processes always, always (yes,
always) bring new risks into the landscape.	

• Big Data considerations are changing the social
contract.	

• You need to use your values and do what is right and
should be considered right by others when managing
data.	

• You should take care of your lifestream and your
company’s.
34
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
35
http://www.slideshare.net/sap/99-facts-on-the-future-of-business
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
36
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
37
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
38
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
39
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
40
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
41
SAP & Vuzix Augmented Reality
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
42
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
43
@CarlosChalicoT
#ISACA_DDay
FinalThoughts
44
@CarlosChalicoT
#ISACA_DDay
Questions and Answers
45
Carlos Chalico
CISA, CISSP, CISM, CGEIT, CRISC, ISO27000 LA,
PbD Ambassador	

Ouest Business Solutions Inc.
carlos.chalico@ouestsolutions.com	

(647)6388062	

twitter: @CarlosChalicoT	

LinkedIn: ca.linkedin.com/in/carloschalico/
@CarlosChalicoT
#ISACA_DDay
Data Lifecycle: Risk Considerations and Controls
October, 2013
Thank You!

More Related Content

What's hot (20)

PPTX
Infrastructure Planning and Design
Sergi Duró
 
PPTX
Information system implementation, change management and control
Shruti Pendharkar
 
PPTX
Database management functions
yhen06
 
PPT
Unit 1 - Introduction to Software Engineering.ppt
DrTThendralCompSci
 
DOCX
Components of a Data-Warehouse
Abdul Aslam
 
PDF
Install active directory on windows server 2016 step by step
Ahmed Abdelwahed
 
PPTX
System Development Life Cycle (SDLC), Types of SDLC | Waterfall Model and Spi...
Uttar Tamang ✔
 
PPT
Managing the information system project
a23ccb
 
PPT
Object Oriented Analysis and Design
Haitham El-Ghareeb
 
PPTX
Ch 4 components of the sqa system
Kittitouch Suteeca
 
PDF
IT Project Management - Study Notes
Marius FAILLOT DEVARRE
 
PPTX
Data Reduction
Rajan Shah
 
PPTX
RMMM Plan
Ankit Bahuguna
 
PDF
DBMS Unit - 3 - Relational query languages
Gyanmanjari Institute Of Technology
 
PPTX
Transaction processing ppt
Javed Khan
 
PPTX
Multidimensional data models
774474
 
PPTX
Software testing & Quality Assurance
Webtech Learning
 
PPTX
Software Configuration Management (SCM)
Er. Shiva K. Shrestha
 
PPTX
Data Modeling PPT
Trinath
 
PPT
Os Swapping, Paging, Segmentation and Virtual Memory
sgpraju
 
Infrastructure Planning and Design
Sergi Duró
 
Information system implementation, change management and control
Shruti Pendharkar
 
Database management functions
yhen06
 
Unit 1 - Introduction to Software Engineering.ppt
DrTThendralCompSci
 
Components of a Data-Warehouse
Abdul Aslam
 
Install active directory on windows server 2016 step by step
Ahmed Abdelwahed
 
System Development Life Cycle (SDLC), Types of SDLC | Waterfall Model and Spi...
Uttar Tamang ✔
 
Managing the information system project
a23ccb
 
Object Oriented Analysis and Design
Haitham El-Ghareeb
 
Ch 4 components of the sqa system
Kittitouch Suteeca
 
IT Project Management - Study Notes
Marius FAILLOT DEVARRE
 
Data Reduction
Rajan Shah
 
RMMM Plan
Ankit Bahuguna
 
DBMS Unit - 3 - Relational query languages
Gyanmanjari Institute Of Technology
 
Transaction processing ppt
Javed Khan
 
Multidimensional data models
774474
 
Software testing & Quality Assurance
Webtech Learning
 
Software Configuration Management (SCM)
Er. Shiva K. Shrestha
 
Data Modeling PPT
Trinath
 
Os Swapping, Paging, Segmentation and Virtual Memory
sgpraju
 

Similar to Data Lifecycle Risks Considerations and Controls (20)

PDF
Why L-3 Data Tactics Data Science?
Rich Heimann
 
PPTX
Data Scientist
Prince Barai
 
PDF
The field-guide-to-data-science
Booz Allen Hamilton
 
PPT
Colloquium(7)_DataScience:ShivShaktiGhosh&MohitGarg
Shiv Shakti Ghosh
 
PDF
The Field Guide to Data Science
Booz Allen Hamilton
 
PPTX
Chapter 2- Data Science and big data.pptx
HailieeyesusKindie
 
PDF
Data science
Biniam Behailu
 
PPTX
intro to data science Clustering and visualization of data science subfields ...
jybufgofasfbkpoovh
 
PDF
Big Data for Library Services (2017)
Albert Anthony Gavino, MBA
 
PPTX
1 UNIT-DSP.pptx
PothyeswariPothyes
 
PDF
The Field Guide to Data Science
EMC
 
PPTX
Week-1-Introduction to Data Mining.pptx
Take1As
 
DOCX
What is Data Science?
Ahmed Banafa
 
PDF
365 Data Science
IvanHo572682
 
PDF
Thinkful DC - Intro to Data Science
TJ Stalcup
 
PPT
Data literacy
Jayanta Nayek
 
PPTX
PowerPoint Template
butest
 
PPT
data science ppt of emngineering studnets
anughasha
 
PPTX
Understanding the Value of Database Discovery - Beyond Unstructured Data
Logikcull.com
 
PDF
KIT-601 Lecture Notes-UNIT-1.pdf
Dr. Radhey Shyam
 
Why L-3 Data Tactics Data Science?
Rich Heimann
 
Data Scientist
Prince Barai
 
The field-guide-to-data-science
Booz Allen Hamilton
 
Colloquium(7)_DataScience:ShivShaktiGhosh&MohitGarg
Shiv Shakti Ghosh
 
The Field Guide to Data Science
Booz Allen Hamilton
 
Chapter 2- Data Science and big data.pptx
HailieeyesusKindie
 
Data science
Biniam Behailu
 
intro to data science Clustering and visualization of data science subfields ...
jybufgofasfbkpoovh
 
Big Data for Library Services (2017)
Albert Anthony Gavino, MBA
 
1 UNIT-DSP.pptx
PothyeswariPothyes
 
The Field Guide to Data Science
EMC
 
Week-1-Introduction to Data Mining.pptx
Take1As
 
What is Data Science?
Ahmed Banafa
 
365 Data Science
IvanHo572682
 
Thinkful DC - Intro to Data Science
TJ Stalcup
 
Data literacy
Jayanta Nayek
 
PowerPoint Template
butest
 
data science ppt of emngineering studnets
anughasha
 
Understanding the Value of Database Discovery - Beyond Unstructured Data
Logikcull.com
 
KIT-601 Lecture Notes-UNIT-1.pdf
Dr. Radhey Shyam
 
Ad

More from Carlos Chalico (19)

PDF
Isaca monterrey dic 2019
Carlos Chalico
 
PDF
ISACA Monterrey - Confianza Digital Diciembre 2018
Carlos Chalico
 
PDF
ISACA Privacidad LATAM
Carlos Chalico
 
PDF
ISACA DevOps LATAM
Carlos Chalico
 
PDF
Kijiji 160616
Carlos Chalico
 
PDF
EuroCACS 2016 There are giants in the sky
Carlos Chalico
 
PDF
133 Chalico Privacidad
Carlos Chalico
 
PDF
121 Chalico Internet de las Cosas
Carlos Chalico
 
PDF
Asobancaria definiendo la estrategia de privacidad
Carlos Chalico
 
PDF
Día Internacional de Protección de Datos Personales IFAI 2015
Carlos Chalico
 
PDF
Latin CACS 2009 224
Carlos Chalico
 
PDF
Latin CACS 2009 Carlos Chalico
Carlos Chalico
 
PDF
Latin CACS 2007 CC CZ
Carlos Chalico
 
PDF
Latin cacs 2004 CC CZ
Carlos Chalico
 
PDF
Día Internacional de la Protección de Datos Personales 2015
Carlos Chalico
 
PDF
IT Governance
Carlos Chalico
 
PDF
InfoDF Auditoría de Sistemas
Carlos Chalico
 
PDF
InfoDF Protección de Datos Personales en Redes Sociales
Carlos Chalico
 
PDF
Giss 2009 Final
Carlos Chalico
 
Isaca monterrey dic 2019
Carlos Chalico
 
ISACA Monterrey - Confianza Digital Diciembre 2018
Carlos Chalico
 
ISACA Privacidad LATAM
Carlos Chalico
 
ISACA DevOps LATAM
Carlos Chalico
 
Kijiji 160616
Carlos Chalico
 
EuroCACS 2016 There are giants in the sky
Carlos Chalico
 
133 Chalico Privacidad
Carlos Chalico
 
121 Chalico Internet de las Cosas
Carlos Chalico
 
Asobancaria definiendo la estrategia de privacidad
Carlos Chalico
 
Día Internacional de Protección de Datos Personales IFAI 2015
Carlos Chalico
 
Latin CACS 2009 224
Carlos Chalico
 
Latin CACS 2009 Carlos Chalico
Carlos Chalico
 
Latin CACS 2007 CC CZ
Carlos Chalico
 
Latin cacs 2004 CC CZ
Carlos Chalico
 
Día Internacional de la Protección de Datos Personales 2015
Carlos Chalico
 
IT Governance
Carlos Chalico
 
InfoDF Auditoría de Sistemas
Carlos Chalico
 
InfoDF Protección de Datos Personales en Redes Sociales
Carlos Chalico
 
Giss 2009 Final
Carlos Chalico
 
Ad

Recently uploaded (20)

PPTX
lecture 13 mind test academy it skills.pptx
ggesjmrasoolpark
 
DOCX
Q1_LE_Mathematics 8_Lesson 4_Week 4.docx
ROWELLJAYMALAPIT
 
PDF
An Uncut Conversation With Grok | PDF Document
Mike Hydes
 
PPTX
short term project on AI Driven Data Analytics
JMJCollegeComputerde
 
PPTX
Fluvial_Civilizations_Presentation (1).pptx
alisslovemendoza7
 
PDF
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
apidays
 
PPTX
Data-Users-in-Database-Management-Systems (1).pptx
dharmik832021
 
PPTX
Introduction to computer chapter one 2017.pptx
mensunmarley
 
PDF
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
apidays
 
PPT
Real Life Application of Set theory, Relations and Functions
manavparmar205
 
PPTX
7 Easy Ways to Improve Clarity in Your BI Reports
sophiegracewriter
 
PDF
Top Civil Engineer Canada Services111111
nengineeringfirms
 
PPTX
Introduction to Data Analytics and Data Science
KavithaCIT
 
PPTX
Probability systematic sampling methods.pptx
PrakashRajput19
 
PDF
202501214233242351219 QASS Session 2.pdf
lauramejiamillan
 
PPTX
UPS Case Study - Group 5 with example and implementation .pptx
yasserabdelwahab6
 
PPTX
UVA-Ortho-PPT-Final-1.pptx Data analytics relevant to the top
chinnusindhu1
 
PDF
McKinsey - Global Energy Perspective 2023_11.pdf
niyudha
 
PPTX
M1-T1.pptxM1-T1.pptxM1-T1.pptxM1-T1.pptx
teodoroferiarevanojr
 
PDF
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
apidays
 
lecture 13 mind test academy it skills.pptx
ggesjmrasoolpark
 
Q1_LE_Mathematics 8_Lesson 4_Week 4.docx
ROWELLJAYMALAPIT
 
An Uncut Conversation With Grok | PDF Document
Mike Hydes
 
short term project on AI Driven Data Analytics
JMJCollegeComputerde
 
Fluvial_Civilizations_Presentation (1).pptx
alisslovemendoza7
 
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
apidays
 
Data-Users-in-Database-Management-Systems (1).pptx
dharmik832021
 
Introduction to computer chapter one 2017.pptx
mensunmarley
 
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
apidays
 
Real Life Application of Set theory, Relations and Functions
manavparmar205
 
7 Easy Ways to Improve Clarity in Your BI Reports
sophiegracewriter
 
Top Civil Engineer Canada Services111111
nengineeringfirms
 
Introduction to Data Analytics and Data Science
KavithaCIT
 
Probability systematic sampling methods.pptx
PrakashRajput19
 
202501214233242351219 QASS Session 2.pdf
lauramejiamillan
 
UPS Case Study - Group 5 with example and implementation .pptx
yasserabdelwahab6
 
UVA-Ortho-PPT-Final-1.pptx Data analytics relevant to the top
chinnusindhu1
 
McKinsey - Global Energy Perspective 2023_11.pdf
niyudha
 
M1-T1.pptxM1-T1.pptxM1-T1.pptxM1-T1.pptx
teodoroferiarevanojr
 
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
apidays
 

Data Lifecycle Risks Considerations and Controls