科研速览 · Science Skim继续刷下去 · Keep skimming →
2026-07-31· Computer security

Protecting Data and Systems

Jason Edwards

原始摘要(英文原文)· Original abstract
This chapter frames data protection as a business requirement driven by how information creates value and risk as it moves across systems workflows and third parties. It explains why protection succeeds only when controls change real handling behavior rather than existing as policy text or feature toggles. Readers learn how to tie sensitivity to business impact and convert that understanding into repeatable decisions for storage sharing and monitoring. The chapter then translates core protection mechanisms into operational practice. It covers practical data classification that drives enforceable handling rules and shows how encryption at rest and in transit depends on key management certificate lifecycle and observability to avoid false confidence. It also emphasizes purpose bound access controls including least privilege time bounded access and governance for service accounts to prevent access drift and reduce blast radius. Finally the chapter focuses on preventing unauthorized movement and exposure through approved sharing pathways and well tuned controls at key transition points such as exports links and permission changes. It explains how to monitor data access for misuse by correlating identity entitlement changes and access sequences rather than relying on isolated alerts. AI enabled protection is addressed as decision support for classification and prioritization with clear human approval boundaries and strict governance to manage drift bias and leakage risk.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Protecting Data and Systems — 科研速览 Science Skim