Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Map enterprise data by connecting each data category to the business workflow that creates or uses it, the systems and services that store or process it, the paths it takes between them, and the people or identities that can access it. Treat the result as a maintained architecture and risk record—not a one-time list of databases.

What should an enterprise data map show?

A useful map links business context to technical reality. Start with the data category and purpose, then follow the information through the workflow and the components involved. Include storage, processing, movement, and access: a list of storage locations alone will miss important copies, transfers, and service-to-service paths.

Think in connected records rather than one giant diagram. A high-level view can show the workflow and major systems; supporting records can hold detailed repositories, connections, identities, and review history. This keeps the map useful for decisions without requiring every technical detail to fit on one page.

How to build the map

  1. Set a manageable scope and purpose

    Name the business process, product, environment, or data set you are mapping. State what decision the map should support—for example, a risk assessment, access review, privacy documentation, or incident response. If the environment is large, begin with one meaningful business or system boundary, then expand.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    #1 Best Overall
    Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  2. Identify data categories and labels

    List categories that matter to the scoped process, such as personal information, financial records, health information, or controlled unclassified information (CUI) where applicable. Record known classifications and handling requirements. Avoid assigning one label to an entire application if it handles materially different data classes; document which workflows or components handle which classes.

    NIST’s SP 1800-39, Data Classification Practices, an initial public draft published February 12, 2026, discusses finding and labeling sensitive unstructured data and using persistent labels to characterize and manage data assets. Its draft status means the guidance may evolve.

  3. Trace the business workflow end to end

    Follow the information from collection or creation through transformation, use, logging, sharing, transmission, retention, and disposal. Note why each action occurs and which team or process is responsible. NIST’s glossary treats processing as a lifecycle of actions, not merely computation, so include steps that create copies or move information even when no obvious database update occurs.

    Rank #2
    OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
    • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
    • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
    • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
    • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
    • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
  4. Inventory systems and services at each step

    For every workflow step, identify the applications and components that store or process the data. Depending on the process, this may include databases, file stores, collaboration spaces, data lakes, backups, logs, cloud services, and external systems. Record the service or component name rather than relying only on a broad platform label.

    What’s actually slowing this PC down?

    Pick the symptom - the matching free tool is one click away.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

    Sensitive unstructured data can be distributed across conversations, file repositories, and data lakes as well as structured databases. NIST SP 1800-39 (initial public draft, February 12, 2026) addresses discovery and classification of data across varied repositories; the practical implication is to include those repositories in scope rather than assuming the database inventory is complete.

  5. Draw the movement paths and boundaries

    For each significant flow, record its source, destination, transfer mechanism, and the boundary it crosses. Include user-facing traffic as well as east-west service communication, hybrid connections, and cloud or multi-cloud paths. Show the service identities and external parties involved where relevant.

    Rank #3
    Sale
    Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
    • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
    • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
    • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
    • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
    • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

    NIST IR 8505, A Data Protection Approach for Cloud-Native Applications (final, September 2024), addresses data protection in cloud-native, multi-cloud, service-mesh, and hybrid architectures, including data in transit. That makes network and service-to-service paths part of the data map, not optional detail beneath the storage inventory.

  6. Record who and what can access the data

    Capture people, groups, roles, service identities, and third parties with access. Add the relevant privilege or role context, and tie access to the systems or flows where it applies. NIST’s information-location discussion connects visibility into components and users with appropriate information-flow and access controls.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  7. Assign owners and change triggers

    Give each data domain or system a responsible owner who can verify the record. Review it when workflows, architecture, vendors, system locations, or access arrangements change, and maintain a last-reviewed date and change note. For CUI, NIST SP 800-171 Revision 3 (2024) specifically calls for documenting the location of CUI and system components where it is processed or stored, including changes to those locations.

    Rank #4
    Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
    • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
    • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
    • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
    • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
    • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

What fields belong in a useful data-map record?

The fields below form a practical operational template. They are not all universally mandated; the applicable requirements depend on the data, organization, contract, and jurisdiction.

Record field What to capture
Data category or label The data class and any known classification or handling note; distinguish different classes handled by the same resource.
Business purpose and workflow Why the data is used and the lifecycle actions it passes through, from collection or creation to disposal.
Source and destination The originating and receiving process, system, service, or external party for each meaningful flow.
Systems and services Applications, components, repositories, backups, logs, cloud services, and other relevant systems that store or process the data.
Storage and processing locations The known locations where information resides or is processed, described at a level useful to the review.
Movement path and boundary Transfer mechanism, path, and any relevant organizational, network, cloud, or vendor boundary crossed.
Access identities Users, groups, roles, service identities, and third parties with access, including relevant privilege context.
Owner and review history The accountable owner, last-reviewed date, and changes that should trigger an update.
Retention and handling notes Applicable retention period or handling rules, when established for the data and context.

NIST SP 800-171 Revision 3’s location requirement is specifically for CUI: it calls for identifying and documenting CUI locations and the system components on which it is processed and stored. Do not treat that CUI-specific requirement as a universal legal rule for every enterprise dataset.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should the map handle cloud and shared systems?

Represent cloud and SaaS services as parts of the workflow, not as a single undifferentiated “cloud” box. Where relevant, show the service or component, its role in storage or processing, the path data takes to and from it, and the identities or third parties with access. For hybrid or service-mesh designs, capture the connections between services as well as the major environments they connect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

When a resource handles multiple data classes, annotate the applicable classes at the workflow, component, or flow level. A single label for an application or server can conceal important differences—for example, one process may use a general business dataset while another handles a more restricted category. NIST’s Big Data Reference Architecture discusses data-level security and dataset catalog concepts that support this kind of distinction.

How much detail is enough?

Use the level of detail required for the decision the map supports. An architecture view should make the workflow, major locations, flows, and access relationships understandable. Keep exhaustive per-device or per-service details in supporting technical records when putting them all in the main view would make it difficult to use.

The European Data Protection Board’s DPIA Template Explainer 2026 (April 2026) recommends balancing completeness with manageability and keeping very detailed inventory in technical documentation. That guidance belongs in its relevant European data-protection and DPIA context; it is not a general rule for every organization or jurisdiction.

How to choose tools for discovery and maintenance

Tools can help discover repositories, classify data, or maintain a dataset catalog, but no tool should be assumed to reveal every workflow, transfer, or access relationship automatically. When evaluating an implementation approach, compare:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Repository coverage: whether discovery includes both structured and unstructured data sources in scope.
  • Cloud and SaaS coverage: whether the relevant cloud services, collaboration systems, and external platforms can be represented.
  • Classification and labels: whether labels can distinguish data classes within shared resources and remain associated with data assets.
  • Flow and access visibility: whether the approach captures movement between components and the users, roles, service identities, and third parties that can reach data.
  • Integration and export: whether records can be connected to existing architecture, security, privacy, or governance processes and exported for review.
  • Maintenance effort: how owners will validate findings, correct gaps, and keep records current after changes.

NIST materials establish the relevance of data discovery, classification, flow, and access visibility; they do not establish vendor rankings or product performance. Validate coverage against the actual systems and workflows in scope.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.