What it means
Security needs change as data moves between systems, people, suppliers, formats, and jurisdictions. Classification, ownership, access, encryption, backup, monitoring, retention, and deletion should follow the data rather than one application alone.
Why it matters
Lifecycle thinking helps prevent forgotten copies, unnecessary retention, and protection gaps during transfer or disposal.
Practical focus
- Identify owners, purpose, sensitivity, and required retention
- Control access and transfer at each stage
- Track copies in backups, exports, and third parties
- Verify secure disposal when the business need ends
Common mistakes
- Protecting production data but ignoring test and backup copies
- Retaining information indefinitely
- Assuming deletion in an application removes every copy
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: