Data Security: Protect Files, Recovery, and Disposal - Yenra

Map important information, control access, protect storage and transfers, test recovery, and choose a documented disposal process.

An ivory document tray sits between a navy storage cabinet and a separate teal backup cabinet, with an amber access token.
Conceptual illustration: access, primary storage and recovery copies each need their own protection.

Start with a small data map

Data security becomes manageable when you can name the information, its owner, its locations and the people who need it. Start with the records whose loss, exposure or alteration would interrupt an important activity: customer records, financial files, credentials, source material or irreplaceable personal documents.

For each collection, record where the original lives, how it is shared, where backups go and who decides retention. Include exports, email attachments, synchronized devices and temporary working copies. A single document may have several exposure paths.

A fictional small-team data map
CollectionOwner and allowed usersProtection and recovery check
Customer contact listOperations owner; named support staff.Restricted workspace, approved sharing, review departing staff access.
InvoicesFinance owner; accounts team.Protected storage, named-recipient transfers, recover an archived sample.
Project source filesProject owner; assigned contributors.Version history plus a separately protected backup and a restore test.

On a narrow screen, scroll the table sideways. Keyboard users can focus the table and use the arrow keys.

The NIST CSF 2.0 small-business resources organize cybersecurity around governance, identification, protection, detection, response and recovery. Use that broader structure to assign responsibility; this page concentrates on the life of the data.

Give access a purpose and an end

Grant access to named accounts according to the work each person performs. Use supported multifactor authentication, remove unused accounts and review privileges when roles change. Separate everyday work from administrative access where the platform supports it.

Define three events: joining, changing role and leaving. At each event, identify the collections affected and the person responsible for updating permissions. An account removal checklist is more useful when it includes shared links, service accounts and synchronized copies as well as the central login.

Check permissions with a harmless sample. Confirm an intended account can perform its required action, and that an uninvited test account cannot. Keep the test controlled and avoid using another person’s credentials. Record both successful access and expected rejection.

Protect storage, transfers and recovery keys

Encryption at rest protects stored data under particular key and device conditions. Encryption in transit protects a communication channel or message. Inspect both paths: a protected laptop can still upload a readable file to an inappropriate sharing destination.

Use the operating system or service’s supported encryption controls. Check status on the actual device and arrange recovery according to the product and organization’s instructions. A recovery key stored only on the device it unlocks may be unavailable precisely when it is needed.

An unlocked session or authorized application may read encrypted-at-rest data. Continue to protect the account, apply updates and restrict sharing. Encryption works alongside access control, not as a substitute for deciding who receives a file.

When sharing, choose named recipients and a suitable access level, verify the address or account, then test the actual retrieval process. The email-encryption guide explains how message and transport protection differ.

Test recovery as an activity

A backup is useful when an authorized person can recover the required information in the available time. Synchronization and version history can help, but their ability to recover from account compromise, deletion or ransomware depends on how they are configured.

CISA’s StopRansomware guide recommends offline, encrypted backups of critical data and regular testing of availability and integrity. Choose an arrangement appropriate to the service: separation can involve offline copies or properly configured protected backup storage, with access independently controlled.

  1. Choose a harmless representative file and record its expected content or checksum.
  2. Identify a specific backup version and restore it to an isolated test location using the documented process.
  3. Open it in its intended application and compare it with the expected record. A successful job status alone does not establish that the content is usable.
  4. Record elapsed recovery time, dependencies, who performed the test and any missing data. Remove test copies according to the retention rule.

Retire data and media deliberately

First establish retention needs and any holds with the information owner. Then distinguish deleting an account or file from sanitizing its storage medium. Identify every relevant copy, including backups whose retention schedule may be independent.

NIST SP 800-88 Revision 2, published in September 2025 provides media-sanitization guidance. Choose a supported method for the device, data sensitivity and reuse or disposal plan, and document verification and validation. Cryptographic erase depends on the encryption implementation and removal of the relevant keys and recoverable copies; a generic delete command is insufficient evidence.

Keep the record of what was retired, the approved method, operator, date and result. If a device fails or the supported sanitization method cannot be verified, escalate through the organization’s disposal process rather than assuming its data has disappeared.

Keep a usable review record

Download the data protection review worksheet (plain text). Save a copy, fill it out in a text editor, and keep it with your approved project records.