Research and Standards Referenced
The following sources informed the research, standards alignment, regulatory discussion, incident examples, and practical guidance throughout this book. They are included for reference, validation, and further reading. This bibliography is not intended to replace legal, regulatory, compliance, or technical advice. Readers should confirm current requirements with qualified counsel, auditors, regulators, and authoritative source materials before making decisions based on any framework, law, or standard.
Cybersecurity and Data Breach Research
IBM Security. Cost of a Data Breach Report 2025. IBM, 2025.
Used to support discussions of breach cost, AI governance gaps, shadow AI, incident impact, data discovery, classification, access control, encryption, and executive risk reporting. (https://www.ibm.com/reports/data-breach)
Verizon. 2025 Data Breach Investigations Report. Verizon Business, 2025.
Used to support discussion of ransomware, third-party involvement, credential abuse, vulnerability exploitation, and the broader breach landscape affecting data security programs. (https://www.verizon.com/business/resources/T16f/reports/2025-dbir-data-breach-investigations-report.pdf)
Artificial Intelligence Risk, Governance, and Security
National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework. NIST, 2023.
Used to support discussion of AI risk governance, AI lifecycle management, trustworthy AI, measurement, accountability, and risk-based oversight. (https://www.nist.gov/itl/ai-risk-management-framework)
National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST, 2024.
Used to support discussion of generative AI risks, prompt security, synthetic content, data exposure, model misuse, and governance practices specific to generative AI systems. (https://www.nist.gov/itl/ai-risk-management-framework)
National Institute of Standards and Technology. SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models. NIST, 2025.
Used to support discussion of secure AI development, dual-use foundation models, AI supply chain risk, model development practices, testing, deployment, and lifecycle security. (https://csrc.nist.gov/pubs/sp/800/218/a/final)
Open Worldwide Application Security Project. OWASP Top 10 for Large Language Model Applications, 2025. OWASP, 2025.
Used to support discussion of prompt injection, sensitive information disclosure, insecure output handling, training data poisoning, supply chain vulnerabilities, excessive agency, and model/application abuse. (https://owasp.org/www-project-top-10-for-large-language-model-applications/)
Open Worldwide Application Security Project. OWASP Top 10 for Agentic Applications. OWASP, 2025.
Used to support discussion of agentic AI risks, autonomous workflows, tool use, excessive agency, identity misuse, data exposure, and controls for AI agents.
Cloud Security Alliance. AI Controls Matrix. Cloud Security Alliance, 2025.
Used to support discussion of AI control objectives, AI assurance, cloud AI governance, control mapping, audit readiness, and alignment with broader security and governance programs. (https://cloudsecurityalliance.org/artifacts/ai-controls-matrix)
Cloud Security Alliance. Cloud Controls Matrix. Cloud Security Alliance.
Used as supporting context for cloud security controls, cloud governance, and the relationship between cloud security posture and AI/data security posture.
International Organization for Standardization. ISO/IEC 42001: Artificial Intelligence Management System. ISO, 2023.
Used to support discussion of AI management systems, AI governance, policy ownership, risk management, accountability, lifecycle controls, and continuous improvement.
Privacy, Data Protection, and Regulatory Sources
European Union. General Data Protection Regulation, Regulation (EU) 2016/679. European Union, 2016.
Used to support discussion of data protection by design and default, security of processing, right to erasure, minimization, retention, deletion, privacy operations, and cross-border data governance. (https://gdpr-info.eu)
European Union. Artificial Intelligence Act. European Union, 2024.
Used to support discussion of high-risk AI systems, AI data governance, cybersecurity, transparency, technical documentation, human oversight, robustness, and lifecycle accountability.
European Union Agency for Cybersecurity and EU AI Office. Cybersecurity and the EU AI Act Guidance. ENISA and EU AI Office.
Used to support discussion of AI cybersecurity, regulatory readiness, trustworthy AI, lifecycle risk, and security obligations under the EU AI Act.
California Privacy Protection Agency. California Consumer Privacy Act and California Privacy Rights Act Guidance and Frequently Asked Questions. CPPA.
Used to support discussion of consumer privacy rights, deletion, data minimization, retention, sharing, and privacy program obligations. (https://cppa.ca.gov/faq.html)
California Privacy Protection Agency. Data Minimization Enforcement Advisory. CPPA, 2024.
Used to support discussion of data minimization as a practical security and privacy control, especially in AI-enabled data environments. (https://www.troutman.com/insights/data-minimization-under-the-ccpa)
U.S. Department of Health and Human Services. HIPAA Privacy, Security, and Breach Notification Rules. HHS.
Used to support discussion of electronic protected health information, administrative safeguards, physical safeguards, technical safeguards, confidentiality, integrity, availability, access controls, audit controls, and healthcare data protection. (https://www.hhs.gov/hipaa/index.html)
Federal Trade Commission. Standards for Safeguarding Customer Information, Gramm-Leach-Bliley Act Safeguards Rule. FTC.
Used to support discussion of customer information protection, written information security programs, access controls, encryption, disposal, monitoring, testing, service provider oversight, and board reporting.
Federal Trade Commission. Health Breach Notification Rule and GLBA Safeguards Rule Breach Notification Materials. FTC.
Used to support discussion of breach notification, customer information exposure, unauthorized acquisition, and regulatory consequences of weak data security.
U.S. Securities and Exchange Commission. Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Final Rule. SEC, 2023.
Used to support discussion of material cybersecurity incident disclosure, governance, risk management, strategy, board oversight, and executive accountability. (https://www.sec.gov/files/rules/final/2023/33-11216.pdf)
New York State Department of Financial Services. 23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies. NYDFS.
Used to support discussion of cybersecurity programs, encryption, nonpublic information, asset inventory, secure disposal, third-party service provider risk, monitoring, training, incident response, business continuity, and disaster recovery. (https://www.dfs.ny.gov/system/files/documents/2023/03/23NYCRR500_0.pdf)
Data Lifecycle, Retention, and Destruction
National Institute of Standards and Technology. SP 800-88 Revision 1, Guidelines for Media Sanitization. NIST, 2014.
Used to support discussion of data destruction, media sanitization, clear, purge, destroy, verification, disposal workflows, and evidence of destruction.
National Institute of Standards and Technology. Cybersecurity Framework 2.0. NIST, 2024.
Used as supporting context for governance, identify, protect, detect, respond, and recover functions across cybersecurity and data security programs.
National Institute of Standards and Technology. SP 800-53, Security and Privacy Controls for Information Systems and Organizations. NIST.
Used as supporting context for access control, audit and accountability, configuration management, incident response, risk assessment, system and information integrity, privacy controls, and security program governance.
National Institute of Standards and Technology. SP 800-61, Computer Security Incident Handling Guide. NIST.
Used as supporting context for incident response planning, preparation, detection, analysis, containment, eradication, recovery, and post-incident improvement.
Data Security, DLP, Identity, and Cloud Security
Gartner. Market Guide and Research on Data Security Posture Management. Gartner.
Used as supporting context for DSPM category definition, mandatory capabilities, vendor evaluation, discovery, classification, posture management, and data risk prioritization.
Microsoft. Microsoft Purview Documentation. Microsoft.
Used as supporting context for data classification, sensitivity labels, information protection, DLP, retention, eDiscovery, insider risk, and Microsoft 365 data governance.
Google. Google Workspace Security, DLP, and Data Protection Documentation. Google.
Used as supporting context for SaaS data controls, collaboration security, DLP policies, file sharing governance, and cloud productivity platform data protection.
Box. Box Governance, Shield, and Data Protection Documentation. Box.
Used as supporting context for collaboration data security, content governance, retention, legal hold, classification, and data protection in SaaS repositories.
Snowflake. Security, Access Control, and Data Governance Documentation. Snowflake.
Used as supporting context for cloud data warehouse access control, role-based access, data governance, logging, and data-sharing risk.
Google Cloud Mandiant. UNC5537 Snowflake Customer Environment Threat Intelligence Reporting. Google Cloud/Mandiant, 2024.
Used to support discussion of valid credential abuse, cloud data warehouse exfiltration, MFA gaps, access monitoring, and the limits of traditional SaaS and cloud controls.
Incident and Enforcement References
Office of the Privacy Commissioner of Canada. Investigation into Desjardins Data Breach. OPC.
Used to support discussion of insider risk, partial DLP deployment, excessive access, monitoring limitations, and long-running data exfiltration.
U.S. Government Accountability Office. Equifax Data Breach Report. GAO.
Used to support discussion of vulnerability management, data governance, database segmentation, detection, and failure to protect large volumes of sensitive personal information.
Federal Trade Commission. Marriott and Starwood Data Security Enforcement Materials. FTC.
Used to support discussion of long-running compromise, encryption gaps, access controls, segmentation, monitoring, MFA, and protection of customer records.
Office of the Comptroller of the Currency. Capital One Enforcement Action and Cloud Risk Management Findings. OCC.
Used to support discussion of cloud security, risk assessment, DLP gaps, alerting, configuration weakness, and cloud data exposure.
Open-Source, Governance, and Data Cataloging References
Apache Software Foundation. Apache Atlas Documentation.
Used as supporting context for open-source metadata management, data cataloging, lineage, classification, and governance foundations.
OpenMetadata. OpenMetadata Documentation.
Used as supporting context for open-source data discovery, metadata management, data lineage, collaboration, and governance foundations.
DataHub Project. DataHub Documentation.
Used as supporting context for metadata platforms, data cataloging, lineage, ownership, discovery, and governance workflows.
OpenDLP Project. OpenDLP Documentation and Historical Materials.
Used as historical context for open-source data discovery and legacy DLP/classification approaches.
Vendor and Product DocumentationUsed for Context
Vendor and product documentation may have beenUsed for contextual understanding of tool capabilities, but references to products in this book are informational only and do not imply endorsement. Product features, licensing, integrations, branding, and technical capabilities change frequently, so readers should validate current functionality directly with the vendor.
Author’s Professional Experience
This book also draws from the author’s professional experience in cybersecurity architecture, penetration testing brokerage, data security health assessments, DSPM program design, incident response planning, risk advisory work, identity and access governance, DLP modernization, and executive security communication.
Where the book includes professional observations, practical field examples, maturity models, templates, operating models, and recommendations, those sections should be understood as the author’s applied professional judgment unless a specific external source is cited.

