Designing Trusted Data Platforms for Enterprise Infrastructure
Synopsis
To many stakeholders, enterprise infrastructure means core services that are trusted, high performance, cost-effective, and resilient. Trusted Data Platforms support enterprise infrastructure by enforcing security, privacy, governance, and business continuity requirements. To consider such platforms truly trusted, the formal definition of trust must therefore be examined. It is commonly stated that trust must be earned. However, simply having the trust of stakeholders is not sufficient to communicate that data platforms are indeed capable of providing the required levels of confidentiality, integrity, availability, and resilience. Stakeholders must also be able to judge both the level of risk associated with the platform and whether the measures in place are appropriate when compared against the level of trust being afforded. A trusted data platform is able to demonstrate that its level of risk is acceptable to all relevant stakeholders and that it has taken adequate measures to protect the data it processes.
Trust can be considered as an attribute assigned to an entity in a relationship by a judge, where that attribute has been earned through a series of actions performed by that entity. While the judge deciding whether to trust may, for example, be a colleague deciding whether to share sensitive information with another or a more abstract stakeholder, the entity in the relationship is frequently an organisation that is a custodian of data. In more general terms, trust is the expectation that the entity, on any future interaction, will act in accordance with a declared set of principles, thereby establishing an integrity profile for itself. For enterprise infrastructure, these principles usually span the areas of security, privacy, governance, and business continuity. When any of these principles fail, trust is accordingly broken, sometimes with devastating or catastrophic consequences.










