Nejat Center
Social Development, Drug Rehabilitation and Medical Services (NDRC)
احیای مجدد اعتیاد و خدمات،مؤسسه انکشاف اجتماعی
طبی نجات سنتر
Data Inventory Management Policy
(Last Updated April 2025)
Purpose
Our Data Inventory Policy aims to establish a comprehensive framework for
identifying, classifying, and managing the data assets within NDRC. This
policy aims to provide clear guidelines and procedures for documenting the
types, locations, and sensitivity levels of our data and defining ownership
and accountability. This policy seeks to enhance data governance, protect
sensitive information, and ensure compliance with privacy regulations and
data protection requirements by implementing effective data inventory
practices. Through regular data audits, mapping exercises, and classification
standards, we strive to improve data visibility, enable effective data
protection measures, and minimize the risk of unauthorized access or data
breaches. By prioritizing data inventory management, we enhance our
overall cybersecurity posture, reduce data-related risks, and maintain the
trust and confidence of our stakeholders.
Scope
The Data Inventory Policy applies to all NDRC's employees, contractors, and
stakeholders and encompasses the systematic identification, classification,
and management of all data assets within our IT infrastructure. This policy
covers all types of data, including sensitive, personal, confidential, and
regulated information. It sets forth guidelines for data discovery,
classification, and mapping to understand data assets' location, sensitivity,
and ownership. The policy defines procedures for maintaining an accurate
and up-to-date data inventory, including retention periods, sharing
agreements, and disposal practices. It also outlines the responsibilities of
individuals involved in data inventory processes, including data owners, IT
administrators, and data stewards. Compliance with this policy is mandatory
for all individuals within NDRC, and any deviations or exceptions require
approval from the designated authority responsible for data inventory and
cybersecurity governance.
Nejat Center
Social Development, Drug Rehabilitation and Medical Services (NDRC)
احیای مجدد اعتیاد و خدمات،مؤسسه انکشاف اجتماعی
طبی نجات سنتر
Safeguards
To achieve NDRC's overall mission, and the purpose of this cybersecurity policy, NDRC shall:
DTA-01 Maintain a data inventory management system to track data managed by NDRC.
DTA-02 Ensure NDRC's data inventory management system maintains an Inventory of data
managed by NDRC and under its control.
DTA-03 Ensure NDRC's data inventory management system maintains an Inventory of data
managed by NDRC and under the control of third parties.
DTA-04 Ensure NDRC's data inventory management system maintains documented
definitions of categories of data managed by NDRC.
DTA-05 Ensure NDRC's data inventory management system defines data owners for all data
managed by NDRC.
DTA-06 Ensure NDRC's data inventory management system tracks the necessity of the data
managed by NDRC when NDRC's data owners approve it.
DTA-07 Ensure NDRC's data inventory management system tracks the business purpose of
all data managed by NDRC.
DTA-08 Ensure NDRC's data inventory management system tracks data that should be
masked in information systems.
DTA-09 Ensure NDRC's data inventory management system tracks the classification,
criticality, and sensitivity of all data managed by NDRC.
DTA-10 Ensure NDRC's data inventory management system documents the location of all
data managed during the processing lifecycle.
DTA-11 Maintain a system to automatically inventory and classify items managed by NDRC
(whether onsite or located at a third party).
DTA-12 Ensure that NDRC's data inventory system automatically discovers data managed by
NDRC (whether onsite or at a third party).
Nejat Center
Social Development, Drug Rehabilitation and Medical Services (NDRC)
احیای مجدد اعتیاد و خدمات،مؤسسه انکشاف اجتماعی
طبی نجات سنتر
DTA-13 Ensure that NDRC's data inventory system automatically classifies and labels data
managed by NDRC (whether onsite or located at a third party).
DTA-14 Ensure that NDRC's data inventory system automatically discovers when its private
data is located in publicly available locations.
DTA-15 Ensure that NDRC's data inventory system is integrated with NDRC's asset inventory
system.
DTA-16 Ensure that NDRC's data inventory system logs and alerts events related to the data
managed by NDRC (such as access, changes, and deletions).
DTA-17 Ensure that NDRC's data inventory system logs and alerts events related to the
system configuration files managed by NDRC (such as access, changes, and
deletions).
DTA-18 Define a process NDRC shall use to define data retention periods for different types
of data managed by NDRC.
DTA-19 Define a process NDRC shall use to archive data managed by NDRC whenever
possible.
Policy Sanctions
Non-compliance with this policy may result in disciplinary action in line with our NDRC's human
resources procedures. Consequences may range from mandatory refresher training and written
warnings to temporary suspension of remote access privileges and, in severe cases, termination of
employment or contractual obligations. Individuals could be subject to legal consequences under
applicable laws if violations involve illegal activities. These sanctions emphasize the critical
importance of cybersecurity, the individual's role in protecting our digital assets, and the potential
risks associated with policy violations. Enforcement will be consistent and impartial, with the
severity of the action corresponding directly to the seriousness of the breach.