A data-centric approach focuses on the data itself rather than only on the systems that store it. It aims to detect personal data in communications, storage, and movement across the environment so organisations can understand usage and protection more directly, even when applications and processes change.
Expanded Definition
A data-centric approach treats the data asset as the primary security object. Rather than relying only on application boundaries or infrastructure controls, it asks where sensitive data appears, how it moves, who can access it, and whether its protection travels with the data across repositories, endpoints, APIs, and messaging paths.
This is broader than simple storage protection and narrower than generic security monitoring. In practice, it often involves discovery, classification, and policy enforcement so that the same data can be governed consistently even when systems, business processes, or ownership change. The core idea is especially important for personal data, regulated data, and other high-value records that may be copied or transformed many times.
Consensus is strong on the need to identify and protect data directly, but organisations differ on how far to centralise classification, how much to automate enforcement, and where to place ownership. A common boundary mistake is to assume application security alone is enough when the real exposure is in the data lifecycle itself.
For control context, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful because it links data handling expectations to concrete control families.
Examples and Use Cases
A data-centric approach typically shows up in environments where data moves faster than the systems around it:
- Classifying sensitive customer records as they enter collaboration tools, cloud storage, or analytics pipelines.
- Applying protection rules to emails, file shares, and chat messages that contain regulated personal data.
- Tracking copies of source data across backups, test environments, and export files so protection does not disappear outside the original system.
- Supporting DLP, encryption, tokenisation, or masking decisions with direct detection of the data type rather than folder names or application labels.
- Giving data stewards and security teams a shared view of where important information resides, especially when ownership is distributed.
The tradeoff is that data-focused controls can be more precise, but they also depend on reliable detection and classification. If the content is misidentified, the organisation may overprotect low-risk data or miss the records that matter most.
In operational terms, this is often the difference between protecting a platform and protecting the information that the platform carries.
Security Implications
When organisations are not data-centric, they often end up with uneven protection. A sensitive record may be well defended in one application and exposed in another copy, export, attachment, log file, or test dataset. That creates blind spots for privacy, insider misuse, accidental sharing, and downstream breach impact.
Data-centric failures usually appear as weak visibility, inconsistent handling rules, and poor control continuity across transfers. The same item of data may inherit different protections depending on where it sits, which makes auditability and retention harder to prove. For personal data, that can turn a routine operational workflow into a compliance issue if the organisation cannot show where the data went or who could access it.
A practitioner observation matters here: if a team cannot answer where the sensitive data lives after one export, copy, or integration step, the environment is not truly governed at the data layer. That is where loss of control usually begins.
In practice, the blast radius is rarely limited to the first system that was compromised. It expands to every place the data was replicated, cached, forwarded, or reused without matching safeguards.
Domain and Governance Relevance
In the identity and security domain, a data-centric approach strengthens governance by shifting the question from "Is the system approved?" to "Is the data itself identified, classified, and protected wherever it appears?" That matters because modern environments fragment responsibility across cloud services, SaaS tools, pipelines, and collaborators.
The approach is also relevant to NHI and agentic AI when those entities read, transform, or route sensitive data. If non-human identities, service accounts, or agents can access data broadly, the governance issue is no longer just identity scope; it is whether the data layer has its own protection model, including detection, labelling, and conditional access decisions.
For organisations managing regulated or personal data, data-centric governance helps align security, privacy, and operational ownership around the same object. It does not replace platform controls, but it prevents security from depending entirely on whichever application happens to hold the data at a given moment.
That makes it especially valuable where ownership is distributed and data changes hands often.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM — Asset Management | Data-centric approaches depend on knowing where sensitive data exists and moves. |
| Recommendation — Track sensitive data locations and movement paths so protection follows the asset. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | Staff handling data must recognise classification and sharing boundaries. |
| 3 — Data Protection | Directly addresses protecting data through classification, handling, and safeguards. | |
| Recommendation — Train users to identify and handle sensitive data consistently across workflows. Apply data protection controls to preserve safeguards across copies and transfers. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Ownership | Data-centric governance overlaps with ownership of machine-accessible sensitive data paths. |
| Recommendation — Inventory data-accessing non-human identities and assign accountable ownership. | ||
| NIST AI 600-1 | MAP — Map Context and Data Flows | AI systems need mapped data flows when sensitive data is processed or transformed. |
| Recommendation — Map data flows before enabling AI systems to ingest or transform sensitive content. | ||
Related resources from NHI Mgmt Group
- Why do healthcare organisations need a data-centric approach when securing AI and cloud environments?
- Why do data security programmes need identity-centric access reporting?
- Why do infrastructure-centric tools struggle with data security governance?
- How should teams choose between workflow-centric privacy tools and data-centric DSPM platforms?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org