Classification and Categorization
Once we have an inventory of assets, understanding the value of those assets becomes the next step as it will drive asset classification, which, in turn, will drive the protection of those assets throughout their life cycle.
9 slides · 2 min read · Domain 2
Having a complete inventory that is updated and reflective of creation/disposition/ destruction of assets becomes very important.
An updated and meaningful inventory of assets can then be used by the owners of those assets to determine value and classify assets based on that value.
Text on this slide
Asset Inventory
Assess and Review
Determine and Assign Ownership Classify Based on Value
Protect and Handle Based on Classification
The classification system will then determine the protection requirements.
This leads to two useful definitions for classification and categorization that focus on who it is that is using the organization's information.
Classification
Classification is the process of recognizing the impacts to the organization if its information suffers any security compromise - to its confidentiality, integrity, availability, non-repudiation, authenticity, privacy, or safety-related characteristics.
A classification label could thus indicate "minor, may disrupt some processes" or "grave, could lead to loss of life or threaten ongoing existence of the organization."
Note that a classification is not a label. (Security labels are part of implementing controls to protect classified information.)
Categorization
Categorization is the process of grouping sets of data, information or knowledge that have comparable sensitivities (impact or loss ratings), and have similar security needs mandated by law, contracts, or other compliance regimes.
These definitions are as directly applicable to small and medium sized enterprises or businesses (SMEs or SMBs) as they are to defense contractors, government agencies, and major globe-spanning enterprises in the private sector.
While they are consistent with NIST SP 800-60r1, FIPS 199, GDPR, and many ISO/IEC standards, their benefit to the organization does not depend upon using those as compliance frameworks. Instead, the benefit starts from flowing down from the compliance regimes that establish the boundaries within which the organization must operate.
Text on this slide
Drivers for Security
Compllance Regimes Prioritles Risks Threats Compromises are to
Confidentiality Integrity Avallability Non-repudiation Authenticity Privacy Safety
Impacts
What type of Impact? Extent? Loss of life? Out of business? Criminal/civil actlon?
Categorize
Impacts Severity Drivers
Impacts Classification
Categorization Security Baselines
Controls Strategles
Security Planning
This context can be seen in the figure showing the flow from the highest level of risk drivers through to capturing security planning decisions in security baselines.
With these definitions in hand, the organization can then go on to create the controls processes, such as policies and security baselines, as part of implementing their security programs.
