What Is Data-Centric Security? | MindLink
For many years, cybersecurity focused on protecting the network.
8 min read
Admin : Sep 29, 2026, 11:25:29 AM
Modern defence operations depend on information moving quickly between people, systems, organisations and coalition partners. But sharing information is only useful if the security controls governing that information move with it.
This is where NATO STANAG 4774 becomes important.
STANAG 4774 defines a standardised syntax for confidentiality metadata labels. These machine-readable labels allow security information to be associated with data so that systems can understand how that data should be protected and handled. NATO’s interoperability documentation identifies ADatP-4774 as its Confidentiality Metadata Label Syntax standard.
Rather than relying solely on the security of the network or application containing information, security metadata helps make protection data-centric. The information can carry security attributes that systems can use when deciding how it may be accessed, exchanged or processed.
For defence organisations working across federated environments, this is an important step towards sharing information securely without losing control of it.
STANAG 4774 is a NATO Standardization Agreement covering the syntax used for confidentiality metadata labels.
The associated NATO publication is ADatP-4774, Confidentiality Metadata Label Syntax. NATO’s current interoperability documentation lists STANAG 4774 alongside STANAG 4778, which provides the corresponding Metadata Binding Mechanism.
In simple terms:
STANAG 4774 defines the security label.
STANAG 4778 defines mechanisms for binding that metadata to the information it protects.
The distinction matters. A security label is useful only if systems can interpret it consistently and maintain the relationship between the label and the associated information.
Together, these standards provide part of the technical foundation required for interoperable security labelling across NATO and coalition environments.
A security label is metadata describing security characteristics associated with a piece of information.
Think of metadata as information about information.
A document might have conventional metadata describing its author, creation date or subject. A confidentiality metadata label instead provides information that systems can use when applying security policy to that data.
This creates an important distinction between protecting a location and protecting the information itself.
Traditional network-centric security might effectively say:
This network is classified, therefore information inside it is protected.
Data-centric security introduces another layer:
This particular piece of information has security attributes that must be considered wherever it is used.
NATO’s current Data Strategy reflects this broader direction, stating that data shared across the Alliance should be protected at source and controlled according to confidentiality and originator-defined rules.
Humans can read markings such as classification banners and handling instructions. Computers need security information expressed in a form they can process consistently.
This becomes increasingly important when information passes between systems.
Consider a coalition operation involving personnel from several nations.
A message, document or other data object may be technically capable of moving across the collaboration environment. But that does not necessarily mean that every authenticated user within that environment should be able to access it.
Different information may be subject to different security policies, releasability requirements or other restrictions.
Machine-readable confidentiality metadata enables applications and security services to recognise security information associated with the data and use it as part of automated policy enforcement.
This supports a fundamental principle of modern secure collaboration:
Being connected to a system does not automatically mean being authorised to access every piece of information within it.
This distinction becomes particularly important in classified and air-gapped environments.
An organisation may have an isolated, highly protected network. However, there may still be hundreds or thousands of authorised users operating inside that environment.
Those users do not necessarily have identical information requirements.
Some information may need to be restricted according to mission, role, organisation, nationality, clearance, releasability or another policy attribute.
Protecting the network perimeter alone therefore does not solve the entire problem.
Security controls also need to operate within the trusted environment.
This is one of the reasons data-centric security has become so important. Instead of assuming everything inside a particular boundary can be treated identically, controls can take account of the characteristics of individual information assets and the users attempting to access them.
STANAG 4774 provides a standard way of representing confidentiality metadata.
This helps separate the security characteristics of information from the application, server or network on which that information happens to reside.
Conceptually, the process can be viewed as:
DATA
↓
CONFIDENTIALITY METADATA LABEL
↓
SECURITY POLICY
↓
USER / SYSTEM ATTRIBUTES
↓
ACCESS DECISION
The security label does not itself make the access decision. Instead, it provides machine-readable information that security mechanisms can use when applying policy.
This distinction is important.
STANAG 4774 is not an access-control engine. It provides standardised confidentiality metadata that can be used by systems responsible for enforcing security policy.
Security labels become particularly powerful when combined with Attribute-Based Access Control (ABAC).
ABAC makes access decisions by evaluating attributes associated with the user, resource, environment and applicable policy.
For example, a user might have attributes representing:
The information being requested can also have attributes represented through security metadata.
An ABAC engine can then evaluate the relevant attributes against policy.
Instead of asking simply:
“Is this user logged in?”
the system can make a much more granular decision:
“Is this user authorised, under the applicable policy, to access this particular information?”
This is particularly valuable in coalition and multinational environments where users may share infrastructure but have different information-access permissions.
Security clearance alone does not necessarily establish a requirement to access every item at that classification level.
A user may have an appropriate clearance while still lacking a need to know particular operational information.
Data-centric controls provide a way to enforce more granular information-sharing policies.
For example:
User A
Appropriate clearance + correct mission attributes + permitted releasability attributes
→ Access may be permitted
User B
Appropriate clearance but does not satisfy the applicable information-sharing policy
→ Access may be denied
The precise decision depends on the organisation’s security policy and implementation, rather than STANAG 4774 alone.
This is an important difference between authentication, clearance and authorisation.
Knowing who someone is does not, by itself, determine which information they should receive.
STANAG 4774 and STANAG 4778 are closely related, but they perform different functions.
STANAG 4774 — Confidentiality Metadata Label Syntax
Defines the syntax used for confidentiality metadata labels.
STANAG 4778 — Metadata Binding Mechanism
Defines mechanisms for binding metadata to the data it describes.
NATO’s interoperability documentation explicitly lists the two standards separately under these functions.
NATO’s Federated Mission Networking documentation also brings them together in its Text-Based Collaboration Services Metadata Labelling Profile. It identifies both ADatP-4774 and ADatP-4778 as mandatory standards for that profile and states that the structure of the binding is defined in ADatP-4778.
A useful shorthand is therefore:
4774 = what the confidentiality label looks like
4778 = how metadata is bound to the information
We will examine STANAG 4778 in more detail in a separate article.
Modern NATO operations involve information moving between different organisations, nations, systems and security architectures.
Without agreed standards, one system might describe security information in a way another system cannot reliably interpret.
Standardisation helps create a common technical language.
This is especially relevant to Federated Mission Networking (FMN), where independently controlled systems need to work together while maintaining appropriate security controls.
NATO’s FMN documentation includes a dedicated Text-Based Collaboration Services Metadata Labelling Profile, describing how standard confidentiality metadata is applied to text-based collaboration services. That profile specifies STANAG 4774 and STANAG 4778.
The objective is not simply connectivity.
It is controlled interoperability.
Systems need to exchange information while preserving the security context required to protect it.
This is one of the hardest problems in secure collaboration.
Suppose information originates in one mission system and needs to be shared with an authorised coalition partner.
Several questions immediately arise:
Who is allowed to receive it?
What security restrictions apply?
Can the receiving system understand those restrictions?
Can policy be enforced after the information crosses the boundary?
Does the security context remain associated with the information?
Standardised metadata labelling helps provide the machine-readable security context needed to address these questions.
The receiving environment still requires compatible policy and enforcement mechanisms. STANAG 4774 does not magically make two security domains interoperable.
But it provides a standardised way of expressing confidentiality metadata that interoperating systems can understand.
No. STANAG 4774 is a confidentiality metadata labelling standard, not an encryption standard.
Encryption and security labelling address different problems.
Encryption protects information from being read without the appropriate cryptographic access.
A security label describes security characteristics associated with the information so that systems can apply the appropriate policy.
In a secure architecture, these controls can complement one another.
Encryption may protect information in transit or at rest, while security metadata helps systems determine whether a particular user, service or destination is permitted to receive or process that information.
Collaboration presents a particularly interesting use case because information is constantly being created and exchanged.
A secure messaging environment may involve:
Security therefore needs to extend beyond protecting the collaboration server itself.
The system must also control who can access what information.
NATO’s FMN metadata-labelling profile specifically addresses text-based collaboration, demonstrating the relevance of STANAG 4774 and STANAG 4778 to this type of environment.
Security labels form part of a wider transition in defence information security.
Historically, security has often been heavily dependent upon network boundaries. Information was protected by placing it within a suitably classified environment.
That remains important, but modern coalition operations increasingly require information to be discoverable, exchanged and processed across distributed systems.
NATO’s 2025 Data Strategy describes a move from isolated private data repositories towards shared data spaces and federated data meshes, while emphasising controlled sharing and data-centric security.
The principle is straightforward:
Protect the network, but protect the data as well.
Security metadata helps make this possible because security information can remain associated with the data rather than being inferred solely from its current location.
The direction is already visible in NATO procurement. In June 2026, the NCI Agency described a Data Centric Security project intended to provide metadata-labelling capabilities for FMN, explicitly requiring compliance with ADatP-4774, ADatP-4778 and ADatP-5636.
MindLink is designed for secure mission collaboration in defence and national-security environments where simply authenticating users to a communications platform is not enough.
MindLink combines secure collaboration with data classification, user entitlements and need-to-know controls, helping organisations restrict access to mission information according to security requirements. MindLink also supports secure federation for sharing classified information between distributed mission components and partner environments.
This reflects the broader data-centric principle behind security labelling: information should not become accessible merely because a user happens to be inside the same collaboration environment.
Security policy needs to remain relevant at the level of the information itself.
For multinational and coalition operations, standardised approaches to security metadata are therefore an important component of interoperable, controlled information sharing.
As defence organisations become more connected, the challenge is no longer simply how to prevent information from leaving a secure network.
Increasingly, the challenge is:
How can information move to the people and systems that need it without also becoming available to those that do not?
This requires security controls capable of operating at the level of individual information assets.
STANAG 4774 contributes to that architecture by providing a standardised syntax for confidentiality metadata labels. Combined with binding mechanisms such as STANAG 4778 and policy-enforcement technologies such as ABAC, security metadata can help enable more granular and interoperable control of classified information.
The result is a shift from securing only the environment in which information resides towards protecting information according to its own security context.
For modern coalition operations, that distinction is fundamental.
STANAG 4774 is a NATO standard for Confidentiality Metadata Label Syntax. It provides a standardised way of representing confidentiality metadata associated with information.
A security label is machine-readable metadata representing security information associated with data. Systems can use that metadata when applying security policies governing how information is accessed, handled or exchanged.
STANAG 4774 defines the confidentiality metadata label syntax. STANAG 4778 defines metadata binding mechanisms used to associate metadata with the information it describes.
No. STANAG 4774 concerns confidentiality metadata labels. Encryption is a separate security mechanism. The two can form complementary parts of a wider information-security architecture.
STANAG 4774 provides standardised confidentiality metadata that can be consumed by security mechanisms. An Attribute-Based Access Control system can evaluate relevant resource, user and contextual attributes against policy to determine whether access should be permitted.
Yes. NATO’s FMN Text-Based Collaboration Services Metadata Labelling Profile specifies ADatP-4774 alongside ADatP-4778 for applying standard confidentiality metadata to text-based collaboration services.
Coalition environments bring together users and systems from different organisations and nations. Machine-readable security metadata helps interoperating systems preserve and interpret the security context associated with information, supporting controlled sharing rather than assuming every connected user has identical access rights.
No. Data-centric controls complement rather than eliminate network, identity, cryptographic and endpoint security. Security labelling allows controls to take account of the individual information asset rather than relying solely on the security boundary surrounding it.
For many years, cybersecurity focused on protecting the network.
Modern defence, government and national security operations depend on people being able to communicate quickly across teams, organisations and...
Protecting classified information is not simply a question of deciding who is trusted.