0% found this document useful (0 votes)
6 views2 pages

Data Classification Policy Overview

The Data Classification Policy outlines four levels of data classification to protect information assets based on sensitivity and potential impact of disclosure. The levels include Public, Internal Use Only, Confidential, and Restricted, each with specific examples and required controls for handling. Additionally, documents containing Level 3 or Level 4 data must be labeled, and external transmission of Restricted data requires approval from a Data Owner.

Uploaded by

touiladam902
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views2 pages

Data Classification Policy Overview

The Data Classification Policy outlines four levels of data classification to protect information assets based on sensitivity and potential impact of disclosure. The levels include Public, Internal Use Only, Confidential, and Restricted, each with specific examples and required controls for handling. Additionally, documents containing Level 3 or Level 4 data must be labeled, and external transmission of Restricted data requires approval from a Data Owner.

Uploaded by

touiladam902
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Data Classification Policy

Information Handling Standards

Data Governance Committee

January 17, 2026

Abstract
To ensure the effective protection of information assets, data must be classified accord-
ing to its sensitivity and the impact of its potential disclosure. This policy outlines the four
classification levels used by the organization.

1 Classification Levels

1.1 Level 1: Public


Information that is intended for public use or has been approved for release to the general
public.
- Examples: Marketing materials, press releases, job postings.
- Controls: No special protection required.

1.2 Level 2: Internal Use Only


Information that is proprietary but not highly sensitive. Unauthorized disclosure would cause
minimal harm.
- Examples: Organizational charts, internal memos, policies.
- Controls: Access limited to employees; standard encryption on laptops.

1.3 Level 3: Confidential


Sensitive information where unauthorized disclosure could cause financial loss, reputational
damage, or legal issues.
- Examples: Customer PII (Personally Identifiable Information), contracts, payroll data.
- Controls: Multi-Factor Authentication (MFA) required for access; encryption at rest and in
transit.

1.4 Level 4: Restricted


Highly sensitive trade secrets or data subject to strict regulatory compliance (e.g., HIPAA, GDPR).
Disclosure could cause catastrophic damage.
- Examples: Source code, encryption keys, merger and acquisition strategies.
- Controls: Strict ”Need to Know” access; auditing of all access logs; data cannot be stored
on portable drives.

1
2 Labeling and Handling
All documents and emails containing Level 3 or Level 4 data must be clearly labeled in the header
or footer. External transmission of Restricted data requires approval from a Data Owner.

You might also like