Skip to content

Lesson 1 — Security as a Business Rule → Access → Evidence System

What Chapter 7 means by Data Security

DMBOK frames Data Security as the planning, development, and execution of security policies and procedures that provide proper authentication, authorization, access, and auditing of data and information assets within business, cultural, and regulatory constraints.

The word proper matters. Security is not “block as much as possible.” It is appropriate access + appropriate protection.

The Goldilocks problem

Too little security exposes data to misuse, breach, regulatory penalties, contractual failure, reputation damage, and operational disruption. Too much security can stop legitimate work, create operational risk, and encourage people to bypass controls.

Example: A service representative needs a shipping address to replace a customer card. The representative does not need full payment credentials or employee salary information. No access prevents the job; full-record access creates unnecessary exposure. The correct entitlement is the minimum sufficient access for the role.

Five sources of security requirements

  • Stakeholder expectations — customers, employees, patients, citizens, suppliers, and partners expect responsible stewardship.
  • Government regulation — law may restrict access, require protection, or require openness, transparency, or subject access.
  • Proprietary business concerns — trade secrets, research, M&A plans, pricing, customer knowledge, and competitive information.
  • Legitimate business access — employees and processes still need data to do authorized work.
  • Contracts / NDAs / industry obligations — promised protections can apply even without a specific law.

Two primary business drivers

  1. Risk reduction — reduce compliance, fiduciary, legal, reputation, and operational risk.
  2. Business growth — trustworthy digital services, e-commerce, partner exchange, and customer confidence depend on usable security.

The exam lens

When two answers both sound “secure,” prefer the one that:

  • connects the control to a business/regulatory requirement;
  • preserves legitimate access;
  • uses the least privilege needed;
  • creates measurable, auditable evidence.

Stop and check

A proposal would block all analysts from approved customer analytics. Is stronger restriction automatically the better DMBOK answer?

No. Chapter 7 requires preventing inappropriate access and enabling appropriate access.

Source anchor: pp. 209–214.

← Guided Learning · Next: Requirements, Classification & Risk →