# What Is Data Security? Data Protection and Modern Corporate Data Security Architecture

**URL:** https://securesys.com.tr/en/learning/data-security-and-classification/what-is-data-security

![What Is Data Security? Data Protection and Modern Corporate Data Security Architecture](/images/bilgi-merkezi/covers/cover-veriguv-01.webp)

**Data security is the body of technology, processes and security controls that provides for the digital and physical data organizations have to be protected against unauthorized access, modification, deletion, loss, leakage and misuse. The concept of data security does not mean only encrypting files or putting a password on a database. Modern data security is a holistic security approach built on discovering where the data is located, determining its importance level, classifying it, controlling who can access it, monitoring data movements and preventing possible data leaks.**

Today one of the most valuable digital assets of organizations is data. Customer records, employee information, financial data, trade secrets, contracts, personal data, source code, production information, R&D documents, e-mails, backups and management reports form an important part of organizations' operations. From the cyber attacker's point of view too the final target of most attacks is now no longer only to obtain a server. The essential target is to reach critical data, to take this data outside, to encrypt it, to change it or to turn it into economic value.

For this reason in the modern cyber security approach this question is becoming increasingly more important:

**"Which data do we have, where is this data located, how sensitive is it, who can access it and if it leaves the organization can we notice this?"**

In an organization that cannot answer all of these questions having a strong firewall, EDR, SIEM or IAM infrastructure may not be sufficient on its own. Because one of the final aims of security technologies is to protect the organization's critical data.

### What Is Data Security?

**Data security is data being protected in line with the confidentiality, integrity and availability principles from the moment it is created to the moment it is deleted or made anonymous. This approach can also be thought of as Data Lifecycle Security.**

When data is created or reaches the organization first where it will be stored is determined. Afterwards who can access this data is defined. The data can be transferred to other systems, shared by e-mail, carried to a cloud environment, backed up or shared with third parties. All of these movements give rise to different security risks.

For this reason data security is not a single technology.

Inside a modern Data Security Architecture:

**Data Discovery, Data Classification, Data Loss Prevention (DLP), Data Security Posture Management (DSPM), Database Activity Monitoring (DAM), Encryption, Data Access Governance, Identity Security, Data Masking, Tokenization, Backup Security and Zero Trust**

different security layers such as these can be used together.

The common aim of these technologies is to protect not only the point at which the data is stored but its whole lifecycle.

### What Is the Difference Between Data Security and Data Protection?

Even though the concepts of Data Security and Data Protection are most of the time used in place of each other their scopes can be different. While Data Security focuses more on data being protected against unauthorized access, leakage, modification and attacks, Data Protection can from a broader perspective cover data being processed, stored, backed up safely, its confidentiality and its being able to be restored when necessary.

For example a database being protected with strong authentication and encryption is a Data Security control. The same database being backed up regularly, a retention policy being applied and it being able to be restored in a disaster recovery scenario, on the other hand, is part of the broader Data Protection approach.

Privacy, on the other hand, is a different but related concept. While privacy is concerned with for which purpose and within which legal framework personal data is processed, Data Security focuses on this data being protected technically and organizationally.

For this reason an organization that wants to be KVKK or GDPR compliant cannot be satisfied only with preparing legal texts. It must also be able to manage technically where the personal data is located, who accesses it and how it is protected.

### What Are the Fundamental Aims of Data Security?

**The foundation of data security is formed by the classic CIA Triad: Confidentiality, Integrity and Availability.**

**Confidentiality expresses only authorized people or systems being able to access the data. Only the relevant application and authorized users should be able to access a customer database. An unauthorized employee or attacker reaching this data is a confidentiality violation.**

**Integrity expresses the data not being changed in an unauthorized or uncontrolled way. Financial records, logs, customer information or system configurations being manipulated can create a serious security and operational risk.**

**Availability, on the other hand, expresses the data being accessible when it is needed. The data being encrypted as a result of a ransomware attack, a storage failure or it being deleted by mistake can cause an availability loss.**

Modern Data Security alongside these three fundamental principles also takes into account concepts such as authenticity, accountability, privacy and resilience.

### Why Is Corporate Data the Main Target of Cyber Attacks?

For the cyber attacker data has an economic value. Customer information can be sold, personal data can be used for fraud purposes, intellectual property can be transferred to competitors or critical documents can be used for ransomware extortion purposes.

Modern ransomware groups may not be satisfied only with encrypting the data. The attacker first moves inside the organization network, discovers the critical data repositories and can take the important data outside. Afterwards by encrypting the systems they can create additional pressure on the organization.

In this attack model the importance of data security increases even more. Because only having a backup is not sufficient. Backup systems can provide the continuity of the operation but cannot bring back the confidentiality of confidential data that has previously been taken outside.

For this reason there is a strong relationship between ransomware defense and Data Security.

### Where Is Corporate Data Located?

One of the biggest difficulties of a data security programme is that the data is not located only inside a database. Corporate data can be distributed to many different systems.

For example data:

file servers,

databases,

employee laptops,

e-mail systems,

SharePoint,

OneDrive,

Google Drive,

cloud object storage,

SaaS applications,

backup systems,

mobile devices,

USB drives,

collaboration platforms,

source code repositories

can be located on these.

The same customer information can be present in four different copies in the production database, in an Excel report, in an e-mail attachment and on the user's laptop.

**This situation is an important data security problem that can be called Data Sprawl.**

If the organization does not know where the data is it is also not possible for it to protect it effectively.

**For this reason one of the first steps of modern data security is Data Discovery.**

### What Is Data Discovery?

Data Discovery is the process of discovering where the data inside the organization is located and which type of information it contains. The aim is not only to produce a list of storage locations. The content of the data also needs to be understood.

For example inside an Excel file:

a national identity number,

a telephone number,

an e-mail address,

credit card information,

customer information

can be present.

The name of the file can be report.xlsx.

When the file name is looked at it may not be understood that it is sensitive. When content inspection is carried out, on the other hand, it can be seen that it contains sensitive data.

Modern Data Discovery solutions therefore try to analyze the content instead of the file name or location.

This approach is important especially in terms of KVKK, GDPR, PCI DSS and corporate data security programmes.

### What Is Sensitive Data?

Sensitive Data is sensitive data that in the case of unauthorized access, disclosure or modification can create damage for a person or organization.

This scope can change according to the organization.

For example:

personal data,

special category personal data,

financial information,

credit card data,

customer records,

trade secrets,

source code,

R&D documents,

strategic plans,

contracts,

authentication credentials

can be evaluated as sensitive data.

Not every piece of data is critical at the same level.

For this reason Data Classification is necessary.

### What Is Data Classification?

Data classification is data being separated into categories according to its sensitivity and business value level.

A common classification model:

#### Public

#### Internal

#### Confidential

#### Restricted

can be in this way.

Public data can be open to the public.

Internal data can be only for use inside the organization.

Confidential data can be limited to authorized employees.

Restricted data, on the other hand, can be used for critical information that requires the highest protection.

However, classification is not only putting a label.

Its real value emerges with the label changing the security controls.

For example when a document is classified as Restricted:

external sharing can be closed,

encryption can be applied,

its being copied to a USB can be prevented,

printing can be restricted,

DLP monitoring can be increased.

In this case the classification becomes an active security control.

### Why Is Data Classification at the Centre of Data Security?

The organization cannot apply the same security policy to all data.

A public marketing document and a confidential merger document do not have to be protected at the same security level.

Maximum security being applied to every piece of data can make the operation harder.

No classification being made at all, on the other hand, can cause critical data to be protected insufficiently.

For this reason one of the fundamental principles of modern Data Security is the:

#### Know Your Data

approach.

First the data must be known.

Then it must be classified.

Afterwards appropriate security controls must be applied.

This relationship:

**Discover → Classify → Protect → Monitor → Respond**

can be summarized in this way.

### What Is Data Loss Prevention – DLP?

**DLP, that is, Data Loss Prevention, is the security approach aimed at preventing sensitive data being taken outside the organization in an unauthorized way or being shared through inappropriate channels.**

For example an employee can want to send a confidential Excel file to their personal e-mail account.

DLP can detect this.

According to the policy:

an alert,

a warning,

a block

can be applied.

Similarly while a sensitive document is being uploaded to:

a USB drive,

cloud storage,

a web application

DLP can come into play.

For this reason DLP is one of the enforcement layers of Data Classification.

### What Is Endpoint DLP?

Endpoint DLP controls the data movements that take place on user computers.

For example actions such as:

USB Copy

Print

Clipboard

Screenshot

Local Save

Browser Upload

can be monitored or limited within the scope of the policy.

Endpoint DLP is important especially in insider threat and accidental data leakage risks.

However, very aggressive DLP policies can affect user productivity.

For this reason DLP deployment must be carried out risk-based.

### Network DLP and E-Mail DLP

Network DLP tries to detect sensitive data movement over network traffic.

E-mail DLP, on the other hand, applies policy especially on outbound e-mails.

For example while an employee is sending an attachment to an external recipient personal data can be present inside the attachment.

DLP can detect this with content inspection.

The policy:

"Restricted classified files cannot be sent to external recipients."

can be in this way.

This is the data-centric security approach.

### What Are Data at Rest, Data in Transit and Data in Use?

Modern data security takes into account three fundamental states of data.

**Data at Rest is data sitting on storage.**

Data inside a database, disk, backup or object storage is an example of this.

**Data in Transit is data carried over the network.**

The traffic between the client and server or system-to-system API communication is an example of this.

**Data in Use is data actively used by an application or user.**

These three states require different security controls.

For Data at Rest encryption.

For Data in Transit TLS.

For Data in Use access control, application security, masking or other protection mechanisms can be applied.

### Why Is Encryption Important in Data Security?

Encryption is one of the fundamental security controls that makes data unreadable by an unauthorized party.

Even if the disk is stolen encrypted data may not be able to be read directly.

Even if a database backup is obtained by the attacker encryption can provide protection.

When network traffic is encrypted with TLS the data interception risk can be reduced.

However, encryption on its own is not sufficient.

If the attacker obtains a legitimate user credential they can reach the decrypted data over the application.

For this reason:

**Encryption + Identity Security + Access Control**

must be applied together.

### Why Is Encryption Key Management Critical?

The security of encryption does not depend only on the algorithm.

If encryption keys are not protected correctly data protection weakens.

For this reason Key Management is an important Data Security capability.

Encryption keys:

secure storage,

rotation,

access control,

audit,

backup

must be managed with these.

KMS and HSM technologies can be used for this purpose.

The key and the encrypted data being kept uncontrolled in the same place can create a risk.

### What Is Data Masking?

Data Masking enables the real value of sensitive data to be hidden from unauthorized or unnecessary users.

For example a credit card number:

4444 5555 6666 7777

instead of this:

**** **** **** 7777

can be shown in this way.

This is important especially for test and development environments.

A developer may not have to see all of the production customer data.

Data masking is the data-level application of the Least Privilege principle.

### What Is Tokenization?

Tokenization is a meaningless token being used in place of sensitive data.

The real data is kept inside a secure environment.

In application operations the token can be used.

This is a protection approach that can be used especially for payment systems and sensitive identifiers.

Tokenization and encryption are not the same thing but the two can reduce sensitive data exposure in different use cases.

### What Is Database Activity Monitoring – DAM?

An important part of corporate critical data is located inside databases.

For this reason database access monitoring is one of the critical layers of Data Security.

**Database Activity Monitoring – DAM enables the user and application activities carried out on the database to be monitored.**

For example information such as:

which user logged in,

which table they accessed,

which query was run,

how many records were read,

which privileged operation was carried out

can be monitored.

This is important especially for privileged DBA accounts and sensitive databases.

### Why Can DBA Authorities Create a Data Security Risk?

A Database Administrator can need broad permissions for the system to work.

However, these permissions can at the same time provide access to sensitive data.

For this reason the DBA having the access right technically does not mean they are authorized to see all the data from a business point of view.

With DAM and PAM integration privileged database activity can be monitored.

For example PAM:

the DBA's session,

DAM, on the other hand:

the SQL activity run inside the session

can monitor these.

This provides stronger accountability.

### What Is Data Access Governance?

Data Access Governance is the process of managing which identity can access which data.

This approach is the intersection of IAM and Data Security.

For example if an employee is a member of the:

Finance Department

they can access finance documents.

When the department changes the access must be removed.

Otherwise Permission Creep can arise.

For this reason Data Access Governance:

Identity

Data Classification

Business Role

must evaluate this information together.

### How Is Least Privilege Applied in Data Security?

Least Privilege is not only for administrator accounts.

It must be applied for data access too.

An employee must access only the data necessary to do their duty.

For example HR can access employee records.

However, it may not be necessary for them to access the source code repository.

A developer can access source code.

However, it may not be necessary for them to access the payroll database.

This is the Need-to-Know principle.

Modern Data Security:

#### Who Can Access What Data?

must be able to answer this question continuously.

### What Is Excessive Data Access?

A user having data access above the business need can be evaluated as excessive data access.

For example an employee may be working only on Türkiye customers.

However, they can have access to the global customer database.

This creates unnecessary exposure.

When attackers compromise the user account they can use this broad access.

For this reason excessive permissions are not only an identity security but a Data Security problem.

### What Is Data Security Posture Management – DSPM?

Inside modern cloud environments it has become harder to track where the data is.

**For this reason Data Security Posture Management – DSPM has become an important technology area.**

DSPM generally focuses on discovering sensitive data, classifying it and analyzing which security risks it is under.

For example DSPM can look for the answers to these questions:

Where is the sensitive data?

Is it publicly accessible?

Who can access it?

Is there encryption?

Are there duplicate copies?

Is the data stale?

Are high-risk identities providing access?

This approach provides data-centric risk visibility.

### What Is Shadow Data?

Shadow Data is data copies not fully known by the security or governance teams.

For example a customer list exported from the production database can be taken into Excel by an employee.

Afterwards it can be uploaded to a SharePoint folder.

While the original database is protected strongly the Excel file can be under weaker security controls.

This is the Shadow Data problem.

Modern DSPM solutions can help to discover this kind of uncontrolled data copy.

### What Is Dark Data?

Dark Data is data collected by the organization but not actively used or whose business value is uncertain.

This data can be kept on storage for years.

The problem is this:

Unused data can also be stolen by the attacker.

For this reason Data Minimization is important.

The organization must not store sensitive data it does not need forever.

This creates a risk in terms of both security and privacy.

### Why Is Cloud Data Security Different?

Cloud environments have increased data mobility.

A user within a few minutes can carry a large dataset onto:

OneDrive,

SharePoint,

a SaaS application,

object storage

these.

A wrong sharing configuration can open sensitive data to external users.

Cloud Data Security therefore requires not only encryption but controls such as:

Sharing Governance

Identity Security

DLP

DSPM

CASB

these.

### The Public Cloud Storage Risk

Cloud object storage can become public because of a wrong configuration.

In this case data exposure can arise without authentication being necessary.

For this reason for cloud storage:

Public Access Control

Encryption

IAM Policies

Logging

Data Classification

must be applied.

CSPM and DSPM together can analyze these risks from different angles.

### What Is the Difference Between CSPM and DSPM?

CSPM, that is, Cloud Security Posture Management, focuses on cloud infrastructure configurations.

For example:

Is the storage public?

Is the security group open?

Is encryption enabled?

DSPM, on the other hand, focuses on the data itself.

For example:

Is there sensitive data inside this storage?

Which type of data is there?

Who can access it?

For this reason:

**CSPM = Infrastructure-Centric**

**DSPM = Data-Centric**

it can be thought of in this way.

The two approaches complement each other.

### Why Is Insider Threat Important in Terms of Data Security?

Data leakage is not always carried out by an external attacker.

An authorized user can also use the data wrongly or maliciously.

An employee:

can send a customer list to personal e-mail,

can copy it to a USB,

can upload it to personal cloud storage.

This can be intentional or accidental.

For this reason Insider Threat programmes are closely related to Data Security.

### What Is Accidental Data Leakage?

Not every data leakage is malicious.

An employee can send an e-mail to the wrong recipient.

They can share a sensitive file with a public link.

They can upload it to the wrong folder.

For this reason security controls must provide protection not only against malicious behavior but against human error too.

DLP at this point can provide a preventive control.

### What Is Data Exfiltration?

Data Exfiltration is data being taken outside the organization in an unauthorized way.

The attacker over a compromised account with methods such as:

a cloud download,

a database export,

e-mail,

a web upload,

an encrypted archive

can carry out data exfiltration.

A modern Data Security Architecture must be able to detect unusual data movement.

For example if a user normally downloads 20 MB of data a day them suddenly downloading 200 GB can be an anomaly.

This is an important use case for behavior analytics and UEBA.

### Why Should Identity Security and Data Security Work Together?

Every operation that accesses data takes place over an identity.

This can be a human identity.

It can be a Service Account.

It can be an AI Agent.

For this reason Data Security and Identity Security cannot be thought of separately from each other.

A modern access decision can be in this way:

**Identity Risk + Device Risk + Data Classification + Requested Action**

For example:

A Low-Risk Employee

A Managed Device

An Internal Document

=

Allow.

However:

A High-Risk User

An Unmanaged Device

Restricted Data

=

Block.

**This is the Adaptive Data Access approach.**

### What Is Zero Trust Data Security?

The Zero Trust principle can be applied to data too.

Being inside the internal network is not a sufficient reason for trust for data access.

Every access request:

identity,

device,

resource,

data sensitivity,

risk

must be evaluated over these.

For this reason the fundamental principle of Zero Trust Data Security:

#### Never Trust Data Access by Location; Verify Access by Identity and Context

can be thought of as this.

### How Is Data Lifecycle Security Provided?

The Data Lifecycle generally consists of these stages:

**Create → Store → Use → Share → Archive → Delete**

At every stage different security controls are necessary.

At the Create stage classification can be applied.

At the Store stage encryption can be used.

At the Use stage access control can be applied.

At the Share stage DLP can come into play.

At the Archive stage a retention policy can be applied.

At the Delete stage secure deletion can be carried out.

For this reason data security is not only storage security.

It must cover the whole lifecycle of the data.

### What Is Data Retention?

Data Retention is the policy that determines for how long the data will be kept.

Not every piece of data should be kept forever.

Business, legal and regulatory requirements must be taken into account.

When the retention period ends the data:

delete,

anonymize,

archive

can be done.

Keeping unnecessary data increases the attack surface.

For this reason Data Minimization is one of the important principles of Data Security.

### Should Backup Data Also Be Classified?

Yes.

If the production data is confidential the backup copy is confidential too.

Indeed a backup can most of the time be riskier.

Because a large amount of data can be in a single place.

For this reason the backup:

encryption,

access control,

immutability,

retention

must be protected with these.

Backup systems must be evaluated as a privileged attack surface.

### How Is Artificial Intelligence Changing Data Security?

Generative AI and AI Agents are creating new risks for Data Security.

An employee can enter confidential information into a public AI service as a prompt.

An AI Agent can access an internal database.

A RAG system can produce answers over sensitive documents.

For this reason an important part of AI Security is actually Data Security.

The organization must answer these questions:

Which data does the AI access?

Is there sensitive data inside the prompt?

Does the model output contain sensitive information?

Does the RAG authorization preserve the user permissions?

Can the agent send the data to an external system?

These questions will be part of the new generation Data Governance programmes.

### Shadow AI and the Data Leakage Risk

Shadow AI is employees using AI tools that are not approved by the organization.

For convenience purposes an employee can upload information such as:

a contract,

source code,

customer data,

a financial report

to an AI tool.

In this case traditional e-mail DLP may not be sufficient on its own.

Web DLP, CASB, browser security and AI usage governance can be evaluated together.

For this reason Generative AI adoption requires the Data Security Architecture to be re-evaluated.

### Data Security in RAG Systems

Retrieval-Augmented Generation enables an AI answer to be produced over corporate documents.

However, if the RAG system presents all the documents to the model with the same authorization sensitive information leakage can arise.

For example a normal employee:

Board Documents

or:

Salary Information

must not be able to receive an answer over these.

**For this reason inside RAG Security Permission-Aware Retrieval is of critical importance.**

The AI must not use a document the user cannot access during retrieval either.

This is the direct intersection of Identity Security and AI Data Security.

### How Should AI Agent Data Access Be Managed?

If an AI Agent can carry out operations on a database or file repository on its own it must use a unique identity.

The agent's access must be:

task-specific,

least privilege,

time-bound

these.

For example if a reporting agent needs only read permission database write permission must not be given.

High-risk data access must in addition be kept under monitoring.

**This is the foundation of the Agentic Data Security approach.**

### The Relationship Between Data Security and KVKK

Within the scope of KVKK alongside personal data being processed lawfully applying appropriate security measures is also important.

For this reason technical Data Security controls are an important part of a KVKK programme.

For example controls such as:

Data Discovery

Data Classification

Access Control

DLP

Encryption

Logging

Data Masking

Backup Security

can strengthen the technical foundation of personal data security.

However, using a Data Security product on its own does not mean KVKK compliance. Legal, organizational and technical processes need to be handled together.

### How Is a Data Security Programme Started?

A corporate Data Security programme should not start by directly buying DLP.

First the data landscape must be understood.

The first question:

**"What are we protecting?"**

should be this.

Then:

**"Where is it located?"**

Afterwards:

**"How critical is it?"**

and:

**"Who can access it?"**

these questions must be answered.

For this reason a healthy starting model:

**Discover → Inventory → Classify → Assign Owner → Protect → Monitor → Respond**

can be in this way.

This order creates not a technology-centric but a data-centric security programme.

### A Risk-Based Approach for Data Security

All data should not be handled with the same security priority.

For example a public website image and a customer database are not at the same risk level.

The risk assessment can take into account these factors:

Data Sensitivity

Business Criticality

Legal Impact

Access Exposure

Location

Identity Risk

Data Volume

Over these factors high-risk datasets can be prioritized.

This is the fundamental approach of DSPM and modern Data Security programmes.

### Who Is the Data Owner?

For every critical dataset a business owner must be determined.

The IT team can manage the storage infrastructure.

However, IT cannot always determine the business value of the data.

For example HR can be the owner of the employee data.

Finance can be the owner of the financial reports.

The Data Owner:

classification,

access approval,

retention

can play a role in these decisions.

For this reason Data Governance and Data Security complement each other.

### The Difference Between Data Security and Data Governance

Data Governance manages the ownership, quality, lifecycle, usage and policy dimensions of data.

Data Security, on the other hand, focuses on the data being protected against unauthorized access and threats.

However, the two areas are not independent of each other.

If the Data Owner is not known an access review becomes harder.

If there is no classification creating a DLP policy becomes harder.

If the retention is not known unnecessary data is kept.

For this reason for strong Data Security a Data Governance foundation is important.

### How Should a Modern Data Security Architecture Look?

A modern corporate Data Security Architecture can work with this logic:

#### Data Sources

↓

#### Data Discovery

↓

#### Data Classification

↓

#### Data Ownership

↓

#### Access Governance

↓

#### Encryption / Masking / Tokenization

↓

#### DLP / DAM / DSPM

↓

#### Behavior Monitoring

↓

#### SIEM / SOC

↓

#### Incident Response

Around this architecture systems such as:

IAM,

PAM,

IGA,

Cloud Security,

Backup,

AI Governance

are located.

For this reason Data Security should not be a separate silo.

It must be located at the centre of the Enterprise Security Architecture.

### Important KPIs for Data Security

A Data Security programme must be measurable.

For example:

Sensitive Data Discovery Coverage

Classified Data Ratio

Unknown Data Owner Count

Publicly Exposed Sensitive Data Count

DLP Incident Count

Critical DLP Incident Count

Unencrypted Sensitive Data Count

Excessive Data Access Count

Dormant Sensitive Data Count

Shadow Data Findings

Database Privileged Activity Alerts

Data Exfiltration Incidents

Sensitive Data Exposure Remediation Time

metrics such as these can be tracked.

The aim is not only to increase the number of alerts but to reduce the risk level.

### The Most Frequently Made Mistakes in Data Security

The most common mistake in corporate Data Security projects is buying technology without determining which data will be protected. DLP can be installed but if there is no classification it becomes uncertain according to what the policies will work. DSPM can be installed but if data ownership has not been defined it may not be clear by whom the risks found will be fixed.

Another mistake is focusing only on database security. The moment sensitive data is exported from the database to Excel it can move outside the database security controls. For this reason a data-centric approach is necessary.

The third mistake is seeing encryption as the complete solution. Encryption can reduce data storage and transmission risks but an attacker using an authorized credential can reach the decrypted data.

The fourth mistake is ignoring insider threat. Not every data leak is carried out by malware. An authorized user mistake or a malicious employee is also an important risk source.

The fifth mistake, on the other hand, is leaving AI use outside the Data Security programme. As Generative AI and AI Agents access corporate data these systems must also be taken into the data governance and DLP scope.

### Data Security Checklist

- Is a corporate Data Inventory present?
- Is Sensitive Data Discovery being carried out?
- Are PII and personal data being detected?
- Are Data Owners defined?
- Is a Data Classification Policy present?
- Have the Public/Internal/Confidential/Restricted classes been determined?
- Are classification labels being applied?
- Is DLP being used?
- Is Endpoint DLP present?
- Is E-Mail DLP being applied?
- Is Cloud DLP being evaluated?
- Is sensitive data encrypted?
- Are encryption keys managed centrally?
- Is Data Masking being used?
- Are database activities being monitored?
- Are privileged DBA activities being monitored?
- Is excessive data access being detected?
- Are Access Reviews being applied?
- Is DSPM being used or evaluated?
- Is Shadow Data being detected?
- Is Dark Data being reduced?
- Are cloud sharing policies being controlled?
- Is public storage exposure being monitored?
- Is backup data encrypted?
- Is a Data Retention Policy present?
- Is secure deletion being applied?
- Are Insider Threat use cases defined?
- Is mass download being detected?
- Is Data Exfiltration monitoring being carried out?
- Is data leakage over AI tools being controlled?
- Are RAG systems permission-aware?
- Do AI Agents use Least Privilege?
- Are Data Security events transferred to the SIEM/SOC?
- Is a Data Incident Response playbook present?

### Data Security Maturity Model

**Level 1 – No Data Visibility: The organization does not know exactly where the data is located. Classification and ownership are limited. Security is more infrastructure-centric.**

**Level 2 – Basic Data Protection: Encryption, backup and basic access controls are applied. Critical data repositories start to be determined.**

**Level 3 – Classified Data Security: Data Discovery, Classification, DLP, DAM and access governance are applied. Sensitive data becomes visible.**

**Level 4 – Data-Centric Security: DSPM, behavior analytics, cloud data security and advanced DLP capabilities are used. Risk is prioritized over data sensitivity.**

**Level 5 – Adaptive Data Security: Identity risk, data classification, device posture and behavior signals are included in real-time access decisions. Human, Machine and AI Agent access is managed inside a common Data Security Architecture.**

This transformation:

#### Infrastructure Security

↓

#### Data Visibility

↓

#### Data Classification

↓

#### Data-Centric Protection

↓

#### Adaptive Data Security

proceeds in this way.

### Frequently Asked Questions

#### What is data security?

Data security is the body of technical and organizational controls that provides for digital or physical data to be protected against unauthorized access, modification, deletion, loss and leakage.

#### What is Data Security?

Data Security means veri güvenliği in Turkish and expresses data being protected in line with the confidentiality, integrity and availability principles throughout its whole lifecycle.

#### What is data classification?

Data classification is data being separated into categories such as Public, Internal, Confidential or Restricted according to its sensitivity and business value.

#### What is Sensitive Data?

It is sensitive data that in the case of unauthorized disclosure or modification can create damage for a person or organization.

#### What is Data Discovery?

It is the process of discovering where the data inside the organization is located and which type of sensitive information it contains.

#### What is DLP?

Data Loss Prevention is the security approach that aims to detect and prevent sensitive data being taken outside the organization in an unauthorized way or being shared through inappropriate channels.

#### What is DSPM?

Data Security Posture Management is the data-centric security approach that analyzes where sensitive data is located, who accesses it and which security risks it is under.

#### What is DAM?

Database Activity Monitoring is the user and application activities carried out on the database being monitored and analyzed.

#### What is Data at Rest?

It is data stored on storage, a disk, a database or a backup.

#### What is Data in Transit?

It is data carried over the network from one system to another.

#### What is Data in Use?

It is data actively processed by an application or user.

#### What is Shadow Data?

It is uncontrolled or forgotten data copies of which the security and governance teams do not have full visibility.

#### What is Dark Data?

It is data stored by the organization but whose active use or business value is limited.

#### What is Data Masking?

It is the protection method that provides for the real value of sensitive data to be hidden from unauthorized users.

#### What is Data Exfiltration?

It is data being taken outside the organization in an unauthorized way.

#### What is Zero Trust Data Security?

It is the security approach in which data access is verified continuously over identity, device, data sensitivity and risk context instead of trusting the network location.

#### Is there a relationship between data security and KVKK?

Yes. Within the scope of KVKK appropriate technical and organizational measures are necessary for personal data security to be provided. Data Discovery, Classification, DLP, Encryption, Access Control and Logging can be evaluated among the technical controls that support this programme.

#### Does artificial intelligence create a data security risk?

Yes. Because Generative AI, RAG and AI Agents can access sensitive corporate data or share this data with external services they can create new data leakage and authorization risks.

### Conclusion: You First Need to Know Where the Data You Cannot Protect Is

The most important problem of modern data security is now no longer only whether the attacker can get past the firewall. Organizations' data is continuously moving between the data center, cloud, SaaS, employee endpoints, collaboration platforms, backup systems and AI applications.

For this reason a security architecture cannot be thought of only as network or endpoint centred.

The asset that really needs to be protected is the data.

However, in order to be able to protect the data it must first be seen.

For this reason the fundamental chain of modern Data Security:

**Discover → Classify → Protect → Control Access → Monitor → Detect → Respond**

must be built in this way.

Data Discovery shows which data the organization has.

Data Classification determines how critical the data is.

IAM and Data Access Governance control who can access it.

Encryption, Masking and Tokenization reduce the exposure risk of the data.

DLP tries to prevent the data leaving in an uncontrolled way.

DAM monitors database activities.

DSPM analyzes the security posture of sensitive data.

The SIEM and SOC, on the other hand, evaluate all these signals inside an incident context.

On top of this the AI and Agentic AI layer has started to be added.

Now only:

**"Which user can access which data?"**

this question is not sufficient.

The new question:

**"Which human, application, service account or AI Agent can access which data, for which purpose, with which authority and for how long?"**

should be this.

For this reason the data security approach of the future will be:

#### Data-Centric

#### Identity-Aware

#### Risk-Adaptive

#### AI-Aware

this.

The final aim of a corporate Data Security Architecture is not to lock every file. The aim is to apply protection at the right level to the right data by understanding the value and sensitivity of the data.

And the most important sentence of this chapter:

**Modern data security is not protecting the data only on the server it is stored on; it is discovering where it is located, classifying its sensitivity, controlling who can access it and being able to monitor throughout the lifecycle all the critical data movements carried out by a human, application or AI Agent.**
