Data Classification, Data Management,
and Data Security Policy
Serial #: WS-ISMS-PCY-1201
Security Level: Internal
Access: IT and Security Teams
Owner: Toni Pham
Approver: Bella Zhu
Effective Date: 12-Apr-2023
Revision History
Date Serial# Description of Name Remarks
Change
12-Apr-2023 WS-DCDMDS-PCY-1107 Published Toni Pham V1.0
20-May-2024 WS-DCDMDS-PCY-1107 Reviewed Toni Pham V1.1
15-Mar-2025 WS-DCDMDS-PCY-1107 Reviewed Toni Pham V1.2
1. Purpose
The purpose of this policy is to define the standards for classifying, managing, and securing
data, ensuring appropriate handling and protection of the company's information assets.
2. Scope
This policy applies to all employees, contractors, vendors, and stakeholders who access,
manage, or handle company data.
3. Data Classification
Company data must be classified into the following categories:
• Public: Information intended for public disclosure.
• Internal: Information for internal use only.
• Confidential: Sensitive data requiring protection from unauthorized access.
• Restricted: Highly sensitive data, with restricted access due to significant risks.
4. Data Management
Data management responsibilities include creation, storage, access, transfer, and disposal:
• Creation and storage must be secure and in line with data classification.
• Access restricted to authorized personnel based on roles and responsibilities.
• Sensitive data transferred electronically must be encrypted.
• Data disposal must adhere to retention schedules and ensure secure deletion.
5. Data Security Controls
Security measures for each data classification level:
• Public: No special measures required.
• Internal: Basic security controls, restricted access.
• Confidential: Strict access control, encryption, detailed logging.
• Restricted: Highest security controls, multi-factor authentication, comprehensive
encryption, detailed audit trails.
6. Incident Management and Reporting
Security incidents must be reported immediately to the Information Security Team.
Incidents are to be documented, investigated, and resolved following the Incident Response
Plan.
7. Roles and Responsibilities
• Information Security Team: Oversight and compliance monitoring.
• Data Owners: Classifying and managing data according to policy.
• Employees/Users: Adherence to data security measures and reporting incidents.
8. Enforcement and Exceptions
Compliance is mandatory; non-compliance can result in disciplinary action. Exceptions
must be documented and approved by senior management and the Information Security
Team.
9. Policy Review
This policy will be reviewed annually or when significant changes occur.