The Information Protection Life Cycle (IPLC) and its accompanying Information Protection Framework (IPF) focus specifically on protecting information across its entire usable lifespan, addressing a gap left by broader IT and cybersecurity frameworks. The IPLC defines three stages—Acquire & Assess, Active Use Life, and Disposition—supported by six categories of controls to reduce risk as information is created, used, shared, stored, and eventually removed.
In Acquire & Assess, the core requirement is to discover and classify information so protections match real sensitivity and value. Data objects should be analyzed by content, semantics, criticality, and intended audience, recognizing that not all information deserves equal protection. Classification approaches differ by data type: structured data can track sensitivity at the database row/column/table level, while unstructured content can be tagged via metadata. Data inventories—made more common through GDPR-driven DPIAs—support this foundational step and improve downstream handling.
During Active Use Life, five control categories apply. Control Access aims for granular, policy-based access decisions using attributes of users, devices, and resources, but remains difficult at enterprise scale across mixed environments. Secure controls protect confidentiality and integrity via encryption, masking, pseudonymization, and tokenization, though deployment and interoperability are challenging. Monitor and Detect emphasizes endpoint, server, and network detection (EPP, EDR, SIEM, IDS, and ML-based NTDR), requiring skilled analysts. Contain and Recover prioritizes incident containment backed by preparation—backups, response plans, recovery procedures, and communications. Deceive introduces Distributed Deception Platforms to lure attackers into realistic fake environments, accelerating detection and reducing response time, especially where IoT/medical devices can’t run standard tools.
In Disposition, information that is no longer needed and not legally required should be archived or deleted, aligning with data minimization to reduce liability.
See All Locations
See All Locations