0 ratings 0% found this document useful (0 votes) 15 views 15 pages Data Classification & Categorization
The document outlines the processes of data classification and categorization, defining how to determine the sensitivity and organization of information. It details the roles and responsibilities in data management, asset inventory, and the importance of data retention and destruction practices. Additionally, it emphasizes the need for appropriate security standards and methods to protect data throughout its lifecycle.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here .
Available Formats
Download as PDF or read online on Scribd
Go to previous items Go to next items
Save Data Classification & Categorization For Later
_ DATA CLASSIFICATION AND
____ DATA CATEGORIZATION
_ Definition: Process of determining the sensitivity
level of information. _ a
Example: Confidential patient records classified as _
EIQ oe es ae oa
Memory Trick: Think “how sensitive’!
Data Categorization: Process of organizing informa-
tion into groups or classes :
Example: Grouping data by type (e.g. financial, legal)
Memory Trick: Matrix
Sas aE
—-€lassification answers “how sensitive is the data 7”
Categorization answers “what-type-of-data is it?”
Examples of Sensitive Data: Examples of —
* Trade secrets Categories
* Financial-information + Business es
«Intellectual property «Legal oe
___¢ Pll (Personally Identifiabe ___» Customer
___ Information)
« Research ae
__Examples of Categories:
___* Business
+ Legal
e CuctamerVDetinition : Asset classification groupes
assets based on sensitivity or importance
lypes: PUBLIC
+ Public: data can be shared
(Inx: Press reiease ) INTERNAL
CONFIDENTIAL
¢ Internal: limited to organization
RESTRICTED
(Ex: Employee policies)
* Confidential must protection
(Ex: Trade secrets)
¢ Restricted: highly sensitive data
(Ex: Classified information)
Business Value Logic —> Sensitive / important
assets higher value
Memory Trick:
/e\. Remember
/o\ Fr\ Cats
J RLS Zit Ne In
/ Firm> least \ {PP ___\ PajamasMARKING ano LABELING
requirements
Marking «Labeling
identifying sensitive informa-
tion with visible designation
Example: Ex: “CONFIDENTIAL”
printed on a document
Typical Labels Chart
Bacaiing
process of managing
and protecting assets
| 4 | Restricted |
Handling
process of managing
and protecting assets
Memory Aid: 4}
&M : :
ae & Manage Identify > Classify > Protect
(information)DATA CLASSIFICATION
AND DATA CATEGORIZATION
DEFINITION: Classifying information
according to its level of sensitivity & impor-
tance.
PURPOSE: To protect info by applying
appropriate controls
Data Data Categorization
Classification (Steps backward)
(Sensible backward) °
* Label with a
Identify —>| Category
* Assess
* Assess
+ Identify
* Label with a
Classification
EXAMPLE: es)
» lop Secret”— classification
applied to document with joins)
sensitive content
MAMORY TRICK:
—Use Data Categorization to organize info
into categories, THEN apply Data
Classification based on sensitivity
MEMORY TRICK: Use Data Categorization
to organize info into categories, THEN
apply Data Classification based on sensitiv-INFORMATION AND ASSET
OWNERSHIP
DEFINITION: Assigning roles and
responsibilities for information and
asset management
ROLES INFOSEC MAPPING
— Owner: establishes Owner = Management
requirements Custodian = IT Personnel
— Custodian: protect User = Employees
User: follow policies
OWNERSHIP LIFECYCLE Aca
iT owner
7
owners i
: Monitor
ea & review
charge!
5 End-of-
Ownership
REMEMBER!
— owners are in charge
implies authority!ASSET_INVENTORY
DEFINITION: A comprehensive list of an
organization's assets (e.g., hardware,
software, data)
COMPONENTS: Assign labels or identifiers
to each asset
LOGGING: Record details about assets in
an inventory system
TRACKING: Monitor assets throughout
their lifecycle
ASSET INVENTORY
TAGGING LOGGING | | TRACKING
G
EXAMPLE: A company maintains an
inventory of all laptops, servers, software
licenses, and sensitive data
WHY IMPORTANT: Tied to asset lifecycle
(purchase, use, disposal)
2. Supports security controls (e.g., access
management)ASSET MANAGEMENT
POLICIES
Example:
MEMORY AID:
Rules for managing assets
throughout their lifecycle
An asset management policy
may specify how assets should
be classified, used, and disposed of.
Policies provide a PLAN.
LIFECYCLES Phases an asset goes
Example:
MEMORY AID:
TRANSFER
Example:
MEMORY AID:
through from acquisition
to disposal
Hardware assets typically go
through planning, procurement,
maintenance, maintenance,
and disposal
The steps of a lifecycle a
represent its cycle ce
Transitioning assets between
owners or locations
A computer may be transferred
to a new department, building,
or company
TRANS fer indicates CHANGEDATA ROLES
DEFINITION: Data roles are responsibilities
__assigned to individuals for managing
and protecting data.
Sa DATA ROLES:
_DATA OWNER DATA DATA
“Initiates, clasify CONTROLLER CUSTODIAN
and makes Determines how Stores and
decisions data data useved safeguardes
data
DATA PROCESSOR
Processes data on
behalf of the controller
__EXAMPLES: An executive (owner))
__develops policies for HR data
___Acompliance officer (controller) oversees
data handling practices
IT staff (custodians) maintain and back up data
MEMORY AID: Data
a -
R ae R es R ce O.C.P.C.
OWNER CONTROLLER PROCESSOR CUSTODIAN ee roles
ee ey ike a chain
Retermining adac - command
records rerention for dataDATA LOCATION
Definition: Where data is
stored geqgraphically
(on-prem, cloud, etc.)
Example: LOCATION DATA CENTER
looks like map
location
Memory Trick:
LOCATION looks like map location
DATA MAINTENANCE
Definition: Ensuring data remains accurate
and usable over time
+ Updates: [aa ——
Keep data in =A
current =
Backup
+ Backups: Creatinga * Patching: Fixing
copy for recovery data vulnerabilities
Validation: |fA,° Memory Trick:
Verifiing |\¢3)| Data MAINTENANCE
data accuracy |. \SS = DATA MAINTAINEDDATA RETENTION & DESTRUCTION
DEFINITIONS
Data Retention:
Peretain to retain
Data Remanence:
Residual data remain
after deletion
RETENTITENTION
& DESTRUCTION
Retention
data
» Preserving data
bolanced/legal needs
Destruction: Iriverse
removal after deleton
© a longer neede:)
MEMORY TRICK
Think of the life
cycle of data:
COLLECT > RETAIN
— DESTROY
Preserving data based
on business/legal needs
Trreversibly remove data
that is longer needed
Secure options include
shredding, degaussing
0 overwriting
DATA DESTRUCTION
LIFECYCLE
ie
RETENTION
LIFECYCLE
Residual data on storage
media after deletion
A security risk
Effective erasue methods:
* Clearing (overwriting)
* Purging (degaussing)
* Destroying (physical
destruction)DETERMINING APPROPRIATE
RECORDS RETENTION
Definition: A process to establish how long
records should be kept based on business,
legal, & regulatory requirements.
Factors:
+ Legal requirements
» Business needs
+ Cost of retention
Records
Retention
Records
Retained
Period
Guidelines:
* Retain records ad
only as long as needed
* Consult applicable laws & regulations
+ Review retention periods regularly
+ Document retention decisions
Memory Aid: “Law, needs, & costs” - the
factors to determine retention periodRECORDS RETENTION
BEST PRACTICES
guidelines for managing record storage and disposal
RETENTION SCHEDULES es
A: plan for how long records are kept
Exampple: > contracts = for 7 years
LEGAL AND REGULATORY REQUIREMENTS
Laws Specify how long to retain certain records
Ex: HIPAA: sets HIPAA= 6 years RX,
ACCESSIBILITY NEEDS =
Keep p records for usability for usability, audits
Ex: Tax records until audit risk decreases =}
STORAGE METHODS z
_ Long-term records stould be stored securely __
Minimal risk of loss /damage (S-
DISPOSAL METHODS
Discard records securely
TIPS:
Avoid aver-retention
(due legal risks)
* Don’t retain all data
* Create policies
with input from
legal/compliance
professionals
Once rete ntion requi rements |
end: schrhedding, wipe
Tips: Avoid over-retention*
Don't retain all dataDomain2 DATA STATES
Data at Rest: Data that is stored and not
being actively used or transmitted
Eg. fil.: files on a server, DATA EE)
database records > Sorat
Data in Transit: Data that is being moved
from one location to another
EG: transiting over a network, DATA
being transferred via USB A
Memory trick: Transit = Traveling, Data is traveling
Data in Use: Data that is being accessed
or processed by a system
E.g., being read from memory, DATA, |
modified by an application Lore
Memory trick: Use = Utilizing, Data is being utilized
Security Techniques
* Encryption — encrypt data stored on disks
* Masking — obscure sensitive data in memory
* Access Control — restrict access to active data
Memory trick: RUT —Rest, Use, TransitSTANDARDS SELECTION
Definition: Choosing appropriate security
frameworks to meet an organization's data
protection needs.
Purpose Standards provide guidelines to
ensure consistent and effective data security
practices.
Examples 1S0/lec 27001 Sverlap of
— International standard
for information security
management systems
— NIST SP 800-53
U.S. standards for
implementing security
controls
—PCI DSS —Standards for
securing payment card
Memory Trick
data Think of selecting
-GDPR-EU law on data Standards as
: : choosing the right
protection and privacy “quards” to protect
Ss your data.
fr reData Protection Methods
Encryption: Encoding information so
only authorized users can read it.
___ Example: HELLO — KHOOR (Caesar cipfer)
___Lock your data_with a secret key.
Data Masking: Obscuring sensitive
data to protect privacy
__ Examples: Credit Card: 1234 5678-***-6789 _
Name: tte Stetee
Memory trick: Put a mask on sensitive data.
Data Loss Prevention (DLP): Protecting
data from unauthorized disclosure
Examples: Blocking USB drives
____ Monitoring emails
Memory trick: Restricting cloud oS
DLP = Don't Let our data Passe