• Home
  • Southern New Hampshire University
  • Emerging Technologies/Big Data
  • Data Security Principles for Data Analysts

Data Security Principles for Data Analysts

6-2 Journal: The Data Analyst and Security 6-2 Journal: The Data Analyst and Security Elaina Hiatt Professor Ross February 12, 2024 6-2 Journal: The Data Analyst and Security The three most relevant guiding principles to a Data Analyst from the DAMA Guide to the Data Management Body of Knowledge are: 1. "Be a responsible trustee of data about all parties. They own the data. Understand and respect the privacy and confidentiality needs of all stakeholders, be they clients, patients, students, citizens, suppliers, or business partners." (DAMA 2010) 2. "Definition of data security requirements and data security policy is a collaborative effort involving IT security administrators, data stewards, internal and external audit teams, and the legal department. The data governance council should review and approve high-level data security policy." (DAMA 2010). 3. "Periodically conduct objective, independent, data security audits to verify regulatory compliance and standards conformance, and to analyze the effectiveness and maturity of data security policy and practice." (DAMA 2010). The first principle is the most important and the one to begin with because recognizing that the data belongs to someone else makes the Analysts and all supporting roles recognize the need to protect it. With any relationship trust is important and as data becomes more readily available, the need for trust with that data is more imperative. This policy, by respecting and acknowledging the privacy and confidentiality of the data based on who's it is, helps to solidify that trust. The second principle is next important because it shows that protecting data is a team effort. It is not the sole responsibility of just one role, all roles need to safeguard data in the best ways possible and then collaborate to continue to ensure data protection. It also specifies the need for a data governance council to review and approve policies that are "high-level". This adds an extra layer of security to further ensure that the data is protected. The third principle is the most effective way for a data analyst, and their team, to remain compliant with the current 6-2 Journal: The Data Analyst and Security data regulations. Objectively auditing their systems and procedures will also identify any weaknesses or potential non-compliant areas. Three principles that could be used in collaboration with other roles are: 1. "In an outsourced environment, be sure to clearly define the roles and responsibilities for data security, and understand the "chain of custody" for data across organizations and roles." (DAMA 2010). 2. "Monitor data access to certain information actively, and take periodic snapshots of data access activity to understand trends and compare against standards criteria." (DAMA 2010). 3. "Data-to-process and data-to-role relationship (CRUD-Create, Read, Update, Delete) matrices help map data access needs and guide definition of data security role groups, parameters, and permissions." (DAMA 2010). Examples of the types of collaborative activities that occur between a data analyst and other roles are with an Analytics Engineer, ETL developers, and graphic designers. "An analytics engineer acts as a link between data engineers and data