Data Classification Types
- data owner is responsible for data classification
- classified according to an overall organizational policy based on a specific characteristic of a given dataset
- policies may assign responsibilities and define roles
Sensitivity
- data is assigned a classification according to its sensitivity
- based on the negative impact an unauthorized disclosure would cause
- used by the U.S. Military
- all data must be classified with a label
Jurisdiction
- data is classified based on the geophysical location of the source or storage point of the data according to laws and regulations affecting it
- has significant impact on how data is treated and handled
- e.g., PII of citizen of EU is more strict than in US
Criticality
- Classify data based on how critical it is to the organization
- BIA can help determine what data should be classified as