Classification and Categorization

Once we have an inventory of assets, understanding the value of those assets becomes the next step as it will drive asset classification, which, in turn, will drive the protection of those assets throughout their life cycle.

9 slides · 2 min read · Domain 2

Slide 1

Having a complete inventory that is updated and reflective of creation/disposition/ destruction of assets becomes very important.

An updated and meaningful inventory of assets can then be used by the owners of those assets to determine value and classify assets based on that value.

Text on this slide

Asset Inventory

Assess and Review

Determine and Assign Ownership Classify Based on Value

Protect and Handle Based on Classification

The classification system will then determine the protection requirements.

This leads to two useful definitions for classification and categorization that focus on who it is that is using the organization's information.

Classification

Classification is the process of recognizing the impacts to the organization if its information suffers any security compromise - to its confidentiality, integrity, availability, non-repudiation, authenticity, privacy, or safety-related characteristics.

A classification label could thus indicate "minor, may disrupt some processes" or "grave, could lead to loss of life or threaten ongoing existence of the organization."

Note that a classification is not a label. (Security labels are part of implementing controls to protect classified information.)

Categorization

Categorization is the process of grouping sets of data, information or knowledge that have comparable sensitivities (impact or loss ratings), and have similar security needs mandated by law, contracts, or other compliance regimes.

These definitions are as directly applicable to small and medium sized enterprises or businesses (SMEs or SMBs) as they are to defense contractors, government agencies, and major globe-spanning enterprises in the private sector.

While they are consistent with NIST SP 800-60r1, FIPS 199, GDPR, and many ISO/IEC standards, their benefit to the organization does not depend upon using those as compliance frameworks. Instead, the benefit starts from flowing down from the compliance regimes that establish the boundaries within which the organization must operate.

Text on this slide

Drivers for Security

Compllance Regimes Prioritles Risks Threats Compromises are to

Confidentiality Integrity Avallability Non-repudiation Authenticity Privacy Safety

Impacts

What type of Impact? Extent? Loss of life? Out of business? Criminal/civil actlon?

Categorize

Impacts Severity Drivers

Impacts Classification

Categorization Security Baselines

Controls Strategles

Security Planning

This context can be seen in the figure showing the flow from the highest level of risk drivers through to capturing security planning decisions in security baselines.

With these definitions in hand, the organization can then go on to create the controls processes, such as policies and security baselines, as part of implementing their security programs.

Test this domain