0% found this document useful (0 votes)
15 views15 pages

Data Classification & Categorization

The document outlines the processes of data classification and categorization, defining how to determine the sensitivity and organization of information. It details the roles and responsibilities in data management, asset inventory, and the importance of data retention and destruction practices. Additionally, it emphasizes the need for appropriate security standards and methods to protect data throughout its lifecycle.

Uploaded by

Ajaz ahmed Khaja
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
15 views15 pages

Data Classification & Categorization

The document outlines the processes of data classification and categorization, defining how to determine the sensitivity and organization of information. It details the roles and responsibilities in data management, asset inventory, and the importance of data retention and destruction practices. Additionally, it emphasizes the need for appropriate security standards and methods to protect data throughout its lifecycle.

Uploaded by

Ajaz ahmed Khaja
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
_ DATA CLASSIFICATION AND ____ DATA CATEGORIZATION _ Definition: Process of determining the sensitivity level of information. _ a Example: Confidential patient records classified as _ EIQ oe es ae oa Memory Trick: Think “how sensitive’! Data Categorization: Process of organizing informa- tion into groups or classes : Example: Grouping data by type (e.g. financial, legal) Memory Trick: Matrix Sas aE —-€lassification answers “how sensitive is the data 7” Categorization answers “what-type-of-data is it?” Examples of Sensitive Data: Examples of — * Trade secrets Categories * Financial-information + Business es «Intellectual property «Legal oe ___¢ Pll (Personally Identifiabe ___» Customer ___ Information) « Research ae __Examples of Categories: ___* Business + Legal e Cuctamer VDetinition : Asset classification groupes assets based on sensitivity or importance lypes: PUBLIC + Public: data can be shared (Inx: Press reiease ) INTERNAL CONFIDENTIAL ¢ Internal: limited to organization RESTRICTED (Ex: Employee policies) * Confidential must protection (Ex: Trade secrets) ¢ Restricted: highly sensitive data (Ex: Classified information) Business Value Logic —> Sensitive / important assets higher value Memory Trick: /e\. Remember /o\ Fr\ Cats J RLS Zit Ne In / Firm> least \ {PP ___\ Pajamas MARKING ano LABELING requirements Marking «Labeling identifying sensitive informa- tion with visible designation Example: Ex: “CONFIDENTIAL” printed on a document Typical Labels Chart Bacaiing process of managing and protecting assets | 4 | Restricted | Handling process of managing and protecting assets Memory Aid: 4} &M : : ae & Manage Identify > Classify > Protect (information) DATA CLASSIFICATION AND DATA CATEGORIZATION DEFINITION: Classifying information according to its level of sensitivity & impor- tance. PURPOSE: To protect info by applying appropriate controls Data Data Categorization Classification (Steps backward) (Sensible backward) ° * Label with a Identify —>| Category * Assess * Assess + Identify * Label with a Classification EXAMPLE: es) » lop Secret”— classification applied to document with joins) sensitive content MAMORY TRICK: —Use Data Categorization to organize info into categories, THEN apply Data Classification based on sensitivity MEMORY TRICK: Use Data Categorization to organize info into categories, THEN apply Data Classification based on sensitiv- INFORMATION AND ASSET OWNERSHIP DEFINITION: Assigning roles and responsibilities for information and asset management ROLES INFOSEC MAPPING — Owner: establishes Owner = Management requirements Custodian = IT Personnel — Custodian: protect User = Employees User: follow policies OWNERSHIP LIFECYCLE Aca iT owner 7 owners i : Monitor ea & review charge! 5 End-of- Ownership REMEMBER! — owners are in charge implies authority! ASSET_INVENTORY DEFINITION: A comprehensive list of an organization's assets (e.g., hardware, software, data) COMPONENTS: Assign labels or identifiers to each asset LOGGING: Record details about assets in an inventory system TRACKING: Monitor assets throughout their lifecycle ASSET INVENTORY TAGGING LOGGING | | TRACKING G EXAMPLE: A company maintains an inventory of all laptops, servers, software licenses, and sensitive data WHY IMPORTANT: Tied to asset lifecycle (purchase, use, disposal) 2. Supports security controls (e.g., access management) ASSET MANAGEMENT POLICIES Example: MEMORY AID: Rules for managing assets throughout their lifecycle An asset management policy may specify how assets should be classified, used, and disposed of. Policies provide a PLAN. LIFECYCLES Phases an asset goes Example: MEMORY AID: TRANSFER Example: MEMORY AID: through from acquisition to disposal Hardware assets typically go through planning, procurement, maintenance, maintenance, and disposal The steps of a lifecycle a represent its cycle ce Transitioning assets between owners or locations A computer may be transferred to a new department, building, or company TRANS fer indicates CHANGE DATA ROLES DEFINITION: Data roles are responsibilities __assigned to individuals for managing and protecting data. Sa DATA ROLES: _DATA OWNER DATA DATA “Initiates, clasify CONTROLLER CUSTODIAN and makes Determines how Stores and decisions data data useved safeguardes data DATA PROCESSOR Processes data on behalf of the controller __EXAMPLES: An executive (owner)) __develops policies for HR data ___Acompliance officer (controller) oversees data handling practices IT staff (custodians) maintain and back up data MEMORY AID: Data a - R ae R es R ce O.C.P.C. OWNER CONTROLLER PROCESSOR CUSTODIAN ee roles ee ey ike a chain Retermining adac - command records rerention for data DATA LOCATION Definition: Where data is stored geqgraphically (on-prem, cloud, etc.) Example: LOCATION DATA CENTER looks like map location Memory Trick: LOCATION looks like map location DATA MAINTENANCE Definition: Ensuring data remains accurate and usable over time + Updates: [aa —— Keep data in =A current = Backup + Backups: Creatinga * Patching: Fixing copy for recovery data vulnerabilities Validation: |fA,° Memory Trick: Verifiing |\¢3)| Data MAINTENANCE data accuracy |. \SS = DATA MAINTAINED DATA RETENTION & DESTRUCTION DEFINITIONS Data Retention: Peretain to retain Data Remanence: Residual data remain after deletion RETENTITENTION & DESTRUCTION Retention data » Preserving data bolanced/legal needs Destruction: Iriverse removal after deleton © a longer neede:) MEMORY TRICK Think of the life cycle of data: COLLECT > RETAIN — DESTROY Preserving data based on business/legal needs Trreversibly remove data that is longer needed Secure options include shredding, degaussing 0 overwriting DATA DESTRUCTION LIFECYCLE ie RETENTION LIFECYCLE Residual data on storage media after deletion A security risk Effective erasue methods: * Clearing (overwriting) * Purging (degaussing) * Destroying (physical destruction) DETERMINING APPROPRIATE RECORDS RETENTION Definition: A process to establish how long records should be kept based on business, legal, & regulatory requirements. Factors: + Legal requirements » Business needs + Cost of retention Records Retention Records Retained Period Guidelines: * Retain records ad only as long as needed * Consult applicable laws & regulations + Review retention periods regularly + Document retention decisions Memory Aid: “Law, needs, & costs” - the factors to determine retention period RECORDS RETENTION BEST PRACTICES guidelines for managing record storage and disposal RETENTION SCHEDULES es A: plan for how long records are kept Exampple: > contracts = for 7 years LEGAL AND REGULATORY REQUIREMENTS Laws Specify how long to retain certain records Ex: HIPAA: sets HIPAA= 6 years RX, ACCESSIBILITY NEEDS = Keep p records for usability for usability, audits Ex: Tax records until audit risk decreases =} STORAGE METHODS z _ Long-term records stould be stored securely __ Minimal risk of loss /damage (S- DISPOSAL METHODS Discard records securely TIPS: Avoid aver-retention (due legal risks) * Don’t retain all data * Create policies with input from legal/compliance professionals Once rete ntion requi rements | end: schrhedding, wipe Tips: Avoid over-retention* Don't retain all data Domain2 DATA STATES Data at Rest: Data that is stored and not being actively used or transmitted Eg. fil.: files on a server, DATA EE) database records > Sorat Data in Transit: Data that is being moved from one location to another EG: transiting over a network, DATA being transferred via USB A Memory trick: Transit = Traveling, Data is traveling Data in Use: Data that is being accessed or processed by a system E.g., being read from memory, DATA, | modified by an application Lore Memory trick: Use = Utilizing, Data is being utilized Security Techniques * Encryption — encrypt data stored on disks * Masking — obscure sensitive data in memory * Access Control — restrict access to active data Memory trick: RUT —Rest, Use, Transit STANDARDS SELECTION Definition: Choosing appropriate security frameworks to meet an organization's data protection needs. Purpose Standards provide guidelines to ensure consistent and effective data security practices. Examples 1S0/lec 27001 Sverlap of — International standard for information security management systems — NIST SP 800-53 U.S. standards for implementing security controls —PCI DSS —Standards for securing payment card Memory Trick data Think of selecting -GDPR-EU law on data Standards as : : choosing the right protection and privacy “quards” to protect Ss your data. fr re Data Protection Methods Encryption: Encoding information so only authorized users can read it. ___ Example: HELLO — KHOOR (Caesar cipfer) ___Lock your data_with a secret key. Data Masking: Obscuring sensitive data to protect privacy __ Examples: Credit Card: 1234 5678-***-6789 _ Name: tte Stetee Memory trick: Put a mask on sensitive data. Data Loss Prevention (DLP): Protecting data from unauthorized disclosure Examples: Blocking USB drives ____ Monitoring emails Memory trick: Restricting cloud oS DLP = Don't Let our data Passe

You might also like