Case 03 — Regulatory Data-Control Remediation
Situation
A regulator asks a financial-services company to demonstrate control over sensitive customer data.
The company discovers: - PII appears in production databases, the enterprise warehouse, an analytics lake, test environments and vendor extracts; - internal confidentiality labels are inconsistent; - privacy/card-data obligations overlap for some records; - an access review shows many analysts can see more fields than their jobs require; - authentication is strong, but role grants expose broad datasets; - test teams receive full production copies and mask data only in the user interface; - nobody can produce complete lineage showing where the regulated fields move; - exception approvals exist in email but are not consistently tied to data assets or users; - a security team proposes encrypting everything and declaring the issue solved; - affected business teams fear the remediation will block legitimate analytical work.
Your task
Use the ten-layer worksheet.
Your response must distinguish: - internal confidentiality classification vs external regulation; - vulnerability vs threat vs risk; - authentication vs authorization vs entitlement; - persistent vs dynamic masking; - Governance policy/exception authority vs Security/Data Management execution; - Catalog/discovery vs lineage; - technical control deployment vs Organizational Change/communication needed for durable adoption.
Minimum retrieval requirements
State closed-book: 1. why correct authentication does not prove access is appropriate; 2. why one “highest security label” does not replace all applicable regulatory categories; 3. why UI masking alone is weak for a copied test database containing underlying PII; 4. what Metadata evidence is needed to answer “where does this field go?”; 5. why the strongest possible control is not automatically the best control; 6. how legitimate-use needs should influence remediation without weakening accountability.