The document outlines 21 basics of data security that provide two functions: allowing access to those who need it and restricting access to only those who need it. The 21 basics include using groups instead of user IDs to own resources, limiting groups and profiles to a single function, prohibiting access across business lines without necessity, and immediately revoking access when jobs or responsibilities change. Following these basics provides a solid structure for access control and auditing.