5.3. Information Protection, Data Lifecycle Management, and Data Governance
💡 First Principle: Protecting data properly requires answering three separate questions about the same content — how sensitive is it (classification), how should access to it be restricted (protection), and how long should it be kept before disposal (lifecycle) — and the six capabilities in this section each answer one piece of that puzzle, working together on the same underlying content.
Why care: getting only one of these three right isn't enough. Classifying data without protecting it leaves it exposed; protecting data without managing its lifecycle leaves an organization holding onto liability-generating data indefinitely; and neither matters if you can't discover where sensitive data actually lives in the first place.
⚠️ Common Misconception: Assuming sensitivity labels and retention labels serve the same purpose because both are applied as "labels." The 5.3.3 and 5.3.6 sections unpack why they solve entirely different problems.