For the past six years I have been the Senior DBA and Manager of Development, not both at the same time of course, for a company which hosts a multi terabyte Data Warehouse for a United States federal agency. While this data is not secret, hence I can at least refer to its existence, it does need to be protected from unauthorized access.
I have suggested to my boss, on multiple occasions, that the best way to protect the data would be to unplug the servers, encase the servers in concrete, bury them hundreds of feet underground then build a nuclear spent rod storage facility on top of that very spot. Nobody is getting access to that data without paying a pretty steep price. (Of course, I am not really sure what affect that much radiation would have upon the storage media. Better than a magnet?)
What would be the result if we did implement my idea? Is the data secure? Probably. Is it available for use? Not very likely! If data isn’t available for use what is its value? Nada, nunca, zipoola. If we have data but cannot use it, then there is no benefit to having the data. It is like having a Rembrandt painting and storing it in a room with only walls but no doors and you are on the outside wishing you could look inside.
The other extreme, that of making data too available also has its downside. If everybody has the same data what is its value? Nada, nunca, zipoola. If we have the same data as everybody else then there is no benefit in having the data. It is like everybody having the same Rembrandt painting. It would be viewed as commonplace, unnoticed, probably used to hide the hole in the wall rather than admired for its beauty.
The Great Security Balancing Act requires us to make the data available to authorized users and protect it from everyone else. It is like having a Rembrandt painting and showing it only to your closest friends. Yes, armed guards, lasers, protective trapdoors and vicious chihuahuas would be strategically placed surrounding the masterpiece. But the painting would now have great value, it would be appreciated for what it is! A masterpiece!
Why do we have to implement proper security procedures around our data? To keep it safe? In my opinion, No. That is not the best answer. We protect our data to keep its value. If our data has no value our employers sure don’t need an expensive DBA protecting something that is worthless. So how much is your data worth?