0% found this document useful (0 votes)
3 views2 pages

Data Classification Management Security Policy

The Data Classification, Management, and Security Policy outlines standards for handling and protecting company data, applicable to all employees and stakeholders. It categorizes data into four classifications: Public, Internal, Confidential, and Restricted, each with specific management and security controls. Compliance is mandatory, with incidents requiring immediate reporting and documentation, and the policy is subject to annual review.

Uploaded by

Trang Diệp
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views2 pages

Data Classification Management Security Policy

The Data Classification, Management, and Security Policy outlines standards for handling and protecting company data, applicable to all employees and stakeholders. It categorizes data into four classifications: Public, Internal, Confidential, and Restricted, each with specific management and security controls. Compliance is mandatory, with incidents requiring immediate reporting and documentation, and the policy is subject to annual review.

Uploaded by

Trang Diệp
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Data Classification, Data Management,

and Data Security Policy


Serial #: WS-ISMS-PCY-1201

Security Level: Internal

Access: IT and Security Teams

Owner: Toni Pham

Approver: Bella Zhu

Effective Date: 12-Apr-2023

Revision History
Date Serial# Description of Name Remarks
Change
12-Apr-2023 WS-DCDMDS-PCY-1107 Published Toni Pham V1.0
20-May-2024 WS-DCDMDS-PCY-1107 Reviewed Toni Pham V1.1
15-Mar-2025 WS-DCDMDS-PCY-1107 Reviewed Toni Pham V1.2

1. Purpose
The purpose of this policy is to define the standards for classifying, managing, and securing
data, ensuring appropriate handling and protection of the company's information assets.

2. Scope
This policy applies to all employees, contractors, vendors, and stakeholders who access,
manage, or handle company data.

3. Data Classification
Company data must be classified into the following categories:

• Public: Information intended for public disclosure.


• Internal: Information for internal use only.
• Confidential: Sensitive data requiring protection from unauthorized access.
• Restricted: Highly sensitive data, with restricted access due to significant risks.

4. Data Management
Data management responsibilities include creation, storage, access, transfer, and disposal:

• Creation and storage must be secure and in line with data classification.
• Access restricted to authorized personnel based on roles and responsibilities.
• Sensitive data transferred electronically must be encrypted.
• Data disposal must adhere to retention schedules and ensure secure deletion.

5. Data Security Controls


Security measures for each data classification level:

• Public: No special measures required.


• Internal: Basic security controls, restricted access.
• Confidential: Strict access control, encryption, detailed logging.
• Restricted: Highest security controls, multi-factor authentication, comprehensive
encryption, detailed audit trails.

6. Incident Management and Reporting


Security incidents must be reported immediately to the Information Security Team.
Incidents are to be documented, investigated, and resolved following the Incident Response
Plan.

7. Roles and Responsibilities


• Information Security Team: Oversight and compliance monitoring.
• Data Owners: Classifying and managing data according to policy.
• Employees/Users: Adherence to data security measures and reporting incidents.

8. Enforcement and Exceptions


Compliance is mandatory; non-compliance can result in disciplinary action. Exceptions
must be documented and approved by senior management and the Information Security
Team.

9. Policy Review
This policy will be reviewed annually or when significant changes occur.

You might also like