Data lifecycle
The stages information passes through from creation or collection to destruction, with security and privacy requirements attached to each stage according to the data's classification.
The data lifecycle describes what happens to information between its creation and its end. Models divide it differently. One widely used version, in Cloud Security Alliance guidance, names six phases: create, store, use, share, archive and destroy. The ISC2 outline lists the lifecycle topics under objective 2.4 as data roles, collection, location, maintenance, retention, remanence and destruction. Across these models, protection follows from the data’s classification and has to hold at every stage.
Each stage raises its own questions. At collection, collection limitation and data minimization restrict what enters. During storage and use, the data states decide which controls apply, and data maintenance keeps the data accurate. Data retention sets how long it stays, and at the end media sanitization deals with data remanence. The lifecycle of the data is separate from the lifecycle of the asset holding it: a server may be retired while its data is migrated, or data destroyed while the server is reused.
Exam relevance: a scenario is likely to describe a control gap at one stage, such as production data copied into a test environment or backups kept past their retention period. Candidates are expected to identify the stage and apply the classification-driven control for it, and to treat destruction as part of the lifecycle rather than an afterthought.