Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

A Botanist's Guide to Data

An alternative view of information security.

Thinking about data in terms of its "life" isn't a complicated idea, but it's a powerful one. Acknowledging that information lives, grows and dies can help a company focus its security and business continuity efforts in the right places. And that's an increasingly important task, given the bumper crops of information that businesses produce every day.

To help, we've developed a botanist's guide of sorts to the life of data - from germination to the compost heap, bonfire or fossil record - with the help of Jay White, global information protection architect at Chevron. We hope that the parallels between the information lifecycle and the plant lifecycle will play some small part in putting the need for information protection into context at your company. Because data, as you know, has a life all of its own.

SEED

Someone gets an idea; something happens.

GERMINATION

Data starts to grow. It can sprout either in a structured place, such as an ERP system - the orderly English gardens of the information ecosystem - or in the wily and unstructured jungles of e-mail, instant messaging, word processing and spreadsheet software.

STEMS AND ROOTS

Information takes on its defining characteristics. Consider three main criteria for identifying its genus and species:

1. Criticality

How important is the information? Is it a small edging plant, or an oak tree that keeps down air-conditioning expenses and houses birds? Would losing it affect anyone's health and safety, the environment, the company's finances or corporate reputation? All the information on your corporate systems can be ranked. (Well, there might be a few weeds.)

  • • Low
  • • Moderate
  • • Significant
  • • Mission-critical

2. Sensitivity

How carefully must the information be tended? Can it grow anywhere, or is it fussy about moisture or prone to infestation? Governments often have official and elaborate hierarchies for classifying information, but corporations may break things down more simply.

For example:

Public information - Information that's meant to be readily available, such as press releases or recommendations on how to purchase goods and services.

Business information - This might include daily transactions, training materials, policy manuals and telephone directories - anything that isn't meant for the public but that doesn't need special protection, either.

Confidential information - The bulk of information that needs to be protected, such as large financial transactions, regulatory actions, employee evaluations, unpublished market research or internal audit reports.

Classified information - Reserved for the most sensitive information, which requires more time-consuming and expensive protection. It might include personnel information (with salaries), corporate-level strategic plans, passwords, trade secrets, and information about mergers and acquisitions.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Chevron, Department of Defence, Genus, Parallels

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • New Mobility Requires a New Network Strategy
    Computing has gone through several major transitions through the ages, each of which raised the value of the network and dramatically lowered the cost of computing. In the years after its birth in the mainframe era, the computing industry shifted to client/server and then Internet computing. Today, we are beginning yet another major computing revolution: the shift to mobile computing. This revolution already allows us to carry mini computers, called “smartphones,” in our pockets. This shift will drive down the cost of computing even further and drive up the value of the network, forever changing its role in organisations. Read on.
    Learn more »
  • Virtualisation and Cloud Computing: Optimised Power, Cooling, and Management Maximises Benefits
    While the benefits of this technology and service delivery model are well known, understood, and increasingly being taken advantage of, their effects on the data center physical infrastructure (DCPI) are less understood. The purpose of this paper is to describe these effects while offering possible solutions or methods for dealing with them. Read this whitepaper.
    Learn more »
  • The Pathways ICT Leadership Development Program Brochure and Curriculum 2012
    Developed by the CIO executive Council, Pathways is a unique, flexible, self-managed, self-paced 12-month CIO designed and delivered professional development program that brings together best practices, thought leadership and business insights for today’s most promising ICT professionals.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments