Data Classification Types


  • data owner is responsible for data classification
  • classified according to an overall organizational policy based on a specific characteristic of a given dataset
    • policies may assign responsibilities and define roles

Sensitivity

  • data is assigned a classification according to its sensitivity
    • based on the negative impact an unauthorized disclosure would cause
    • used by the U.S. Military
  • all data must be classified with a label

Jurisdiction

  • data is classified based on the geophysical location of the source or storage point of the data according to laws and regulations affecting it
  • has significant impact on how data is treated and handled
  • e.g., PII of citizen of EU is more strict than in US

Criticality

  • Classify data based on how critical it is to the organization
  • BIA can help determine what data should be classified as