ID.AM-07.135
Does your organization have a process to continuously discover and analyze ad hoc data to identify new instances of sensitive data types?
Explanation
This question assesses whether your organization actively monitors and analyzes data across systems to identify previously unknown or newly created instances of sensitive information (like PII, financial data, or intellectual property). Continuous discovery helps prevent data sprawl and ensures that all sensitive information receives appropriate protection controls regardless of where it resides or when it was created. Evidence could include documentation of your data discovery tool configuration, scheduled scan reports, data classification policies, or screenshots of your data discovery dashboard showing regular scanning activities and results. Ideally, you should be able to demonstrate how newly discovered sensitive data is subsequently classified and protected.
Implementation Example
Continuously discover and analyze ad hoc data to identify new instances of designated data types
ID: ID.AM-07.135
Context
- Function
- ID: IDENTIFY
- Category
- ID.AM: Asset Management
- Sub-Category
- Inventories of data and corresponding metadata for designated data types are maintained

