Data Classification and Categorization Policy

A data classification and categorization policy is a formal set of guidelines for categorizing data, defining handling procedures, and assigning roles and responsibilities.

4 slides · 3 min read · Domain 2

Slide 1

When classifying and categorizing data, data owners should determine the following aspects of the policy:

  • Data classification and categorization. Define the criteria and processes used to determine the levels of information security protection required. These should include policies and criteria for reviewing and changing the levels of classification and categorization, if required, throughout the life cycle of that data.
  • Data access. Define the roles of people who can access the data. Examples include:
  • Data disposal. Data classification and categorization directly influence the method by which the data is to be disposed:
  • Printed data disposal may require cross-cut shredding, as defined by the asset owner.
  • Digital data disposal may require employees to use a utility to verify that data has been fully removed from their PCs after they erase files containing sensitive data to address any possible data remanence issues

or concerns.

  • Accounting clerks are permitted to see all accounts payable and receivable but cannot add new accounts.
  • Employees are allowed to see the names of other employees (along with managers' names and departments and the names of vendors and contractors working for the company. However, only human resources (HR) employees and managers can see the related pay grades, home addresses, and phone numbers of the entire staff. Also, only HR managers can see and update employee information classified as private, including Social Security numbers (SSNs) and insurance information.
  • Data encryption. Data owners will have to decide whether their data needs to be encrypted and how. Data encryption will usually be required to meet specific legal, regulatory, or contractual requirements for the use of encryption. The Payment Card Industry Data Security Standard (PCI DSS) is one of the more common forms of such contractually based encryption requirements. (While it is natural to assume that security requirements should be used to select, design, and implement a control strategy, contractual or legal requirements can and often do directly dictate the use of a solution such as encryption.)
  • Data security. Determine whether the data is generally available or restricted by default. As an example, many companies set access controls to deny database access to everyone except those who are specifically granted permission to view or update the data.
  • Data retention. Many industries require that data be retained for a certain length of time. Many financial regulations around the world require specific retention periods. Asset owners need to know the regulatory requirements for their data and base the retention period on regulatory and business requirements.
  • Appropriate use of data. This aspect of the policy defines whether data is for use within the company, is restricted for use by only those in selected roles, or can be made public to anyone outside the organization. In addition, some data has associated legal usage definitions. The organization's policy should spell out any such restrictions or refer to the legal definitions as required. Proper data classification also helps the organization comply with pertinent laws and regulations. For example, classifying credit card data as private can help ensure compliance with the PCI DSS. One of the requirements of this standard is to encrypt credit card information. Data owners who correctly defined the encryption aspect of their organization's data classification policy will require that the data be encrypted according to the specifications defined in this standard.
Test this domain