Information Asset Lifecycle
In the Certified in the Governance of Enterprise IT (CGEIT) framework, the Information Asset Lifecycle is the end-to-end management of information from its creation to its final disposal. Information is treated as a strategic enterprise asset that must deliver value, be protected, and comply with l… In the Certified in the Governance of Enterprise IT (CGEIT) framework, the Information Asset Lifecycle is the end-to-end management of information from its creation to its final disposal. Information is treated as a strategic enterprise asset that must deliver value, be protected, and comply with legal and regulatory obligations. COBIT 2019, which underpins much of CGEIT, describes information as an enabler and defines lifecycle phases such as Plan, Design, Build/Acquire, Use/Operate, Monitor, and Dispose. The Plan phase aligns information needs with business objectives and defines ownership, classification schemes, and value. In Design and Build/Acquire, information is created, collected, or purchased, with quality criteria such as accuracy, completeness, and integrity built in. During Use/Operate, information is stored, processed, shared, and maintained. Access controls, security measures, and data quality management help it remain reliable and available to authorized users. The Monitor phase checks whether information continues to meet business, risk, and compliance requirements and whether controls are effective. Finally, the Dispose phase covers archiving and secure destruction in line with retention policies, legal holds, and privacy regulations. From a governance perspective, the board and executive management Evaluate, Direct, and Monitor (EDM) the lifecycle rather than manage it day to day. Key governance concerns include: - Benefits realization: maximizing the business value derived from information. - Risk optimization: managing confidentiality, integrity, availability, and privacy risks. - Resource optimization: ensuring cost-effective storage, infrastructure, and skilled people. - Accountability: assigning clear information owners and custodians, often defined through RACI charts. Effective lifecycle governance requires policies on data classification, retention, and ownership, together with metrics that measure information quality and compliance. When governed well, the information asset lifecycle supports informed decision-making, regulatory compliance, and competitive advantage. It also reduces risks such as data breaches, the cost of excessive retention, and the loss of critical knowledge. This ensures that information consistently contributes to stakeholder value creation, which is the core objective of governance of enterprise IT.
Information Asset Lifecycle in CGEIT: Governance of Enterprise IT Guide
Information Asset Lifecycle: A Complete CGEIT Guide
1. What Is the Information Asset Lifecycle?
The Information Asset Lifecycle is the sequence of stages that information passes through, from creation or acquisition to final disposal. Here information is treated as a business asset, in the same way as financial, physical or human capital. In the CGEIT domain Governance of Enterprise IT (Domain 1), the lifecycle is a governance concern rather than just a technical one. The board and executive management must make sure information is managed so that it:
- creates value,
- keeps risk within appetite, and
- uses resources efficiently.
COBIT 2019 lists Information as one of the seven components of a governance system. It describes the information lifecycle with these stages:
- Plan: define the information architecture, standards, ownership and quality criteria.
- Design: define data models, classification schemes, retention rules and controls.
- Build / Acquire: create, capture or purchase the information, such as records, data feeds and databases.
- Use / Operate: store, share and use the information for business activities.
- Monitor: check that information keeps meeting quality, security and compliance criteria.
- Dispose: archive, retain or securely destroy the information when its value ends or retention periods expire.
Many organizations and ISACA materials use simpler but equivalent wording:
Create/Collect, Store, Use, Share, Archive, Destroy.
2. Why Is It Important?
- Value creation: Information drives decisions, products and competitive advantage. Governing its lifecycle keeps it accurate, available and relevant.
- Risk management: Each stage has its own risks. Examples include unauthorized access during use, data leakage when sharing, and data remanence after poor disposal.
- Regulatory compliance: Laws such as GDPR, HIPAA, SOX and records retention rules apply to how long data is kept, where it is stored and how it is destroyed.
- Cost optimization: Keeping data longer than necessary raises storage costs, legal discovery exposure and complexity.
- Accountability: A lifecycle approach makes it clear who owns, maintains and protects information at every point.
- Alignment with strategy: Information investments and controls are prioritized according to business value and criticality.
3. How It Works: Key Governance Elements
a) Information Ownership and Stewardship
- Information/Data Owner: a senior business manager who is accountable for the information. The owner decides classification, access rights and retention.
- Data Steward: manages quality, definitions and day-to-day governance on the owner's behalf.
- Data Custodian: usually IT. The custodian implements technical controls such as backups, storage and access mechanisms, following the owner's decisions.
- Key exam point: Accountability for information belongs to the business owner, not IT.
b) Information Classification
- Information is classified by sensitivity and criticality, for example Public, Internal, Confidential and Restricted.
- Classification decides what controls apply throughout the lifecycle.
- Classification should be done early (Plan/Design/Create) and reviewed regularly.
c) Information Quality Criteria
COBIT describes information quality across three dimensions:
- Intrinsic: accuracy, objectivity, believability, reputation.
- Contextual: relevance, completeness, currency, appropriate amount, concise representation, consistency, interpretability, understandability, ease of manipulation.
- Security/Accessibility: availability and restricted access.
d) Policies and Standards
Typical policies include:
- information management policy,
- data classification policy,
- records retention schedule,
- acceptable use policy,
- data privacy policy,
- secure disposal standard.
These policies turn governance direction into operational rules.
e) Retention and Disposal
- Retention schedules are driven by legal, regulatory and business requirements.
- Legal holds override normal disposal.
- Secure destruction methods include degaussing, shredding, cryptographic erasure and certified wiping.
- Disposal should be documented with evidence, such as certificates of destruction.
f) Monitoring and Metrics
Example metrics include:
- percentage of information assets with an assigned owner,
- percentage of data classified,
- number of data quality incidents,
- data breaches by lifecycle stage,
- compliance with the retention schedule.
These give the board assurance that information is governed effectively.
g) Linkage to COBIT Processes
- EDM01 (Ensured Governance Framework Setting and Maintenance): sets the direction for information governance.
- EDM03 (Ensured Risk Optimization): covers information risk appetite.
- APO01 (Managed I&T Management Framework): includes information management roles.
- APO03 (Managed Enterprise Architecture): includes information architecture.
- APO14 (Managed Data): the core process for managing data across its lifecycle.
- DSS05 (Managed Security Services) and DSS06 (Managed Business Process Controls): protection and integrity of information during use.
4. Governance vs. Management Perspective
- Governance (board/executives): evaluates, directs and monitors. It sets the information strategy and risk appetite, approves policies, assigns accountability and checks results.
- Management (business and IT): plans, builds, runs and monitors. It carries out classification, implements controls, manages storage and runs disposal.
CGEIT questions are usually asked from the governance point of view.
5. Exam Tips: Answering Questions on Information Asset Lifecycle
- Think like a governance professional, not a technician. The right answer usually involves setting direction, assigning accountability, aligning with business objectives or getting assurance. It rarely involves configuring a specific tool.
- Accountability lies with the business owner. If asked who is accountable for classifying data, approving access or setting retention, choose the information/data owner (business), not IT, the DBA or the custodian.
- Classification comes first. When asked what should be done FIRST to protect information or decide controls, the answer is often to identify and classify information assets or establish ownership.
- Policy before procedure. If there is no governance framework, the best answer is usually to establish an information management policy or framework that has executive approval.
- Business requirements drive retention. Retention periods should come from legal, regulatory and business requirements. They should not be set by IT storage capacity or convenience.
- Secure disposal is a governance issue. Watch for scenarios about decommissioned hardware, cloud exit or outsourcing termination. The best answer ensures information is disposed of in line with policy, with verification.
- Look for the whole-lifecycle answer. Options that cover the full lifecycle, such as an integrated information governance framework, often beat options that fix only one stage.
- Value and risk balance. CGEIT stresses benefits realization, risk optimization and resource optimization. Prefer answers that balance value delivery with risk, not ones that remove all risk at any cost.
- Watch keywords: MOST important, FIRST, BEST and PRIMARY. For example, the PRIMARY reason for an information lifecycle approach is usually to maximize value while managing risk and compliance.
- Third parties and cloud: The enterprise stays accountable for its information even when it is outsourced. Look for answers involving contractual clauses, right to audit, data location and return or destruction at the end of the contract.
- Metrics and monitoring: When asked how the board gains assurance, choose answers about KPIs and KRIs, independent assurance or audit, and reporting against policy.
- Eliminate distractors. Rule out options that are purely technical (e.g., buy a DLP tool), that hand accountability to IT, or that are reactive when a proactive governance option exists.
6. Sample Question Walkthrough
Question: An enterprise has found that sensitive customer data is kept indefinitely across multiple systems. What should the IT governance committee do FIRST?
A. Purchase additional storage
B. Instruct IT to delete data older than five years
C. Ensure a data retention policy based on legal and business requirements is defined and approved
D. Encrypt all databases
Answer: C.
- Governance sets direction through policy grounded in business and legal requirements.
- B is arbitrary and may break regulations.
- A and D are technical measures that do not fix the root governance gap.
7. Summary
The Information Asset Lifecycle treats information as a valuable enterprise asset that must be governed from planning to disposal. For CGEIT, remember these points:
- business ownership and accountability,
- classification as the foundation,
- policy-driven controls at each stage,
- retention set by legal and business needs,
- secure, verified disposal,
- ongoing monitoring that gives the board assurance.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!