CLASSIFICATION
As the process of organizing data into relavant categories- It may be used and
protected more efficiently
Based on value [ data has a value]
Steps:
1. Data classification policy (template)
2. Classification exercise
3. Protect the data (controls)
Types of classification
Whose data?
Electronic or non-electronic?
Based on where it is stored (local, service, provider, cloud)
Classification Public Internal Confidential Restricted
examples Marketing Company Unpublished PHI/PII/Financial
details polices financial information of
informations employee/coustomer
s
sensitivity low medium high Very high
Approaches:
Manual
Automated (tools)
RESTRICTED
Customer details
PUBLIC
employee INTERNAL
customer website
Company polices
Employee HR
details, salary
details