← CCSP: cloud security, data, and operations
03 / 8 · 45 MIN

Data protection, location, and classification

Map copies, keys, and access to information enabling reidentification.

Concept and mechanism

Data protection includes content, copies, keys, and metadata that can reconstruct meaning. Tokenizing identifiers reduces exposure in some flows, but a freely accessible token-original table keeps reversal available to the same users. Separate token access from mapping access and justify each use. Removing names also does not establish irreversible anonymization when stable identifiers can be linked to other sources. For location, consider primary database, backups, logs, exports, and processing. Encryption does not make a copy fall outside a contractual requirement covering it. Classification and discovery help make that scope visible.

Guided application

In a fictional project, the recovery account has IAM Allow for a KMS key in another account, but the key policy does not authorize external access. In a policy-based design, both sides need corresponding permissions. Knowing a key ID or recreating an alias replaces neither authorization nor cryptographic material. Bind that condition to restoration testing before project closure. For DLP, assess results with clear denominators: ten confirmed violations among forty reviewed blocks represent twenty-five percent of blocks. Recall remains unknown without observing escaped violations. Combine precision, operational impact, and coverage to tune rules while preserving evidence and ownership of gap treatment. An active rule does not prove absence of leakage.

IN PRACTICE

Permission to read a snapshot and permission to use its key are separate conditions.

Common pitfalls

Token as anonymization; forgotten copies; alias as equivalent key; one account’s IAM as complete authorization.

Related topics: Architecture, responsibilities, and portability · Versions, retention, and holds · Infrastructure, isolation, and recovery

Take this idea with you

Protect the complete path of data, identification, and decryption.

Create account

Reference: Cryptographic storage design · CCSP examination outline effective 2026-08-01; January2026 V2 PDF