Data in use

Data being actively processed, held in memory, CPU registers or cache, or shown on a screen, where it normally has to be in plaintext for the application or person to work with it.

Data in use is information that an application or a person is actively working with: loaded into RAM, held in processor registers and caches, or displayed on screen. It is one of the three data states, and commonly regarded as the hardest to protect, because most processing needs the data decrypted first.

The threats follow from that exposure: memory-scraping malware on payment terminals, a cold-boot attack on RAM after power loss, side-channel attacks between processes sharing hardware, and a person reading a screen over someone’s shoulder. Controls include least privilege, process isolation and operating system memory protection, and confidential computing, where a trusted execution environment isolates the data from the host and, in many designs, keeps it encrypted in memory. Homomorphic encryption, which computes on ciphertext, remains niche because of its performance cost. Screen locks and a clean desk policy cover the human side of the same state.

Exam relevance: a scenario is likely to describe data processed on a shared or untrusted platform, such as a public cloud host, and ask what protects it. Candidates are expected to recognise that encryption at rest and in transit do not cover this state, and that isolation and trusted execution environments are the controls designed for it.