Header image

Session 2.3b Update: Closing the Metadata Capability Gap in Enterprise Migration to Data-centric Security

Tracks
Wednesday, November 18, 2026
10:30 AM - 11:30 AM
Bradman Theatre

Presentation Outline

Defence organisations are migrating from network-centric security toward data-centric security (DCS) and Zero Trust, where policy decisions depend on machine-readable attributes attached to the data itself. Standards such as STANAG 4774, STANAG 4778, ACP 240, and FMN Spiral 5 define the target architecture, while the US DoD Zero Trust Data Pillar and Minimum Essential Metadata requirements reinforce the same direction. However, most enterprises inherit a heterogeneous metadata estate — application-specific labels, visual markings without embedded metadata, repository-dependent classification context, and proprietary formats — that prevents consistent enforcement by ABAC engines, cross-domain solutions, DLP, guards and gateways. This presentation argues that the primary barrier to operational DCS and Zero Trust is not the absence of classification policy or security tooling, but the absence of a consistent, authoritative, machine-readable metadata layer across enterprise applications, endpoints, transports, and boundaries. Endpoint DLP, EDR, and labelling tools may inspect or control content, but they do not by themselves create the common metadata foundation that enforcement systems require. The presentation identifies three dimensions of the capability gap — metadata disparity across applications, the divide between local usability and cross-domain interoperability, and the gap between labelling and enforcement — and proposes an architectural response: a trusted metadata layer providing multi-policy comprehension, standards-based translation, binding-aware transformation, and Policy Information Point services for resource attributes. Practical deployment patterns, use-case scenarios, and an incremental migration approach aligned with DCS maturity levels are presented for defence PMOs, information architects, and security architects.


Speaker

Agenda Item Image
Mr Greg Colla
CTO
Janusnet

Biography

Greg Colla is the Chief Technology Officer, where he leads the company's technology strategy and product innovation in data-centric security, authoritative enterprise metadata, and security classification solutions for government, defense, and regulated industries.

With more than 20 years of experience delivering secure information management technologies, Greg specializes in the practical implementation of authoritative metadata that enables Zero Trust architectures, Attribute-Based Access Control (ABAC), Data Loss Prevention (DLP), encryption, and secure information sharing across complex enterprise environments. His work focuses on transforming policy and security classification requirements into interoperable, mission-ready capabilities that operate consistently across enterprise applications, endpoints, and isolated networks.

Greg has worked extensively with government and defense organizations to address the challenges of protecting unstructured information while maintaining collaboration and operational effectiveness. He is a strong advocate for standards-based metadata, believing that authoritative data tagging is the foundation for modern data-centric security and the automation of security policy across heterogeneous systems. He regularly advises customers on enterprise metadata strategies, security classification, and Zero Trust implementation for high-assurance environments.
loading