Agile is not one of the four A's of Data Security. DAMA security guidance groups core security processes around Access, Audit, Authentication, and Authorization. These capabilities collectively control who can interact with information resources, establish identity, determine permitted actions, and provide evidence of activity for monitoring and accountability. DAMA-aligned security references identify these four concepts directly.
Authentication confirms the identity of a user or system. Authorization determines what an authenticated identity is permitted to do. Access concerns the actual ability to obtain or interact with data and services. Audit provides traceability by recording and reviewing relevant activities.
Agile, by contrast, is an approach to iterative delivery and project or product development. It may influence how security controls are implemented within development lifecycles, but it is not itself one of the foundational security-control categories identified in this model.
Data Security and Data Quality are separate but related disciplines. Unauthorized modifications can compromise accuracy and integrity, while weak auditability can prevent organizations from identifying how data was altered. Appropriate security controls therefore help preserve the reliability of governed information.
Metadata classification also supports these controls by identifying sensitive data and linking it to access and protection requirements.
Reference Topics: DAMA-DMBOK2 Chapter 7 — Data Security; Access; Authentication; Authorization; Audit; Data Governance; Chapter 13 — Integrity and Controlled Data Modification.
===============
Submit