Data-centric security software focuses on securing the data itself, rather than the infrastructure or application used to store or access that data. This approach differs from a traditional network (or perimeter-centric) security approach, which focuses on protecting the locations where data is accessed or stored, such as servers, networks, applications, and devices.
This software can be used to achieve a zero trust security model and safeguard data across complex IT environments, including cloud environments. Businesses use data-centric security solutions to protect data when it’s in transit, at rest, or in use.
Core capabilities of data-centric security software include the discovery of sensitive data, policy management, access control, encryption, data obfuscation processes such as data masking, and monitoring data access and usage for suspicious behaviors. Additionally, these tools facilitate the labeling, tagging, and tracking of sensitive data points as well as auditing for security and compliance assurance.
Certain functionalities of data-centric security tools may be similar to those of data governance software, mainly in terms of compliance and policy enforcement. While that is an important functionality, data-centric security tools are intended primarily for data lifecycle management rather than for data security. Sensitive data discovery software is a subset of a broader functionality offered by data-centric security software and specializes in discovering sensitive data.
To qualify for inclusion in the Data-Centric Security category, a product must:
Provide sensitive data discovery functionality
Support data classification with the tagging and auditing of sensitive information
Enforce access control policies for sensitive information
Offer encryption for data at rest and in transit
Monitor for abnormalities related to information access and user behavior