The secure handling and classification of organizational data, as well as usage, access, and monitoring requirements, should be governed by a central Data Classification & Handling Policy.
Control Type: Administrative
Control Function: Protective
Description: Data is the oil of digital business, and it is probably the most valuable asset an organization possesses. Even smaller organizations produce tons of new data everyday, and there needs to be protective measures in place to secure it. Organizations should already have an inventory of the major pieces of data that power their environment, as well as security classifications assigned to it. The methodology for data classification can be either the US Government model (Unclassified, Confidential, Secret, Top Secret), or the general corporate model (Public, Internal, Confidential, Restricted). In addition to a thorough inventory and classification of data currently used by the organization, there also needs to be a policy in place that governs how future data will be classified and handled. This policy should be drafted with the input of senior management, data owners, and cybersecurity SMEs. The policy should be published throughout the organization and used as part of onboarding training for all roles that handle any form of company data.
What should be addressed in a Data Classification & Handling Policy:
- Purpose & Scope: the role of the policy and what data is considered in scope of organizational governance
- Classification Levels: the selected classification model (US Government or Corporate) and the definitions for each level
- Classification Criteria: guidance on what pieces of data belong in which classification level, as well as criteria for classifying data that is brand new to the environment
- Access Restrictions: which departments or individual employees are allowed to access what categories of data, as well as any special exceptions and their rationale.
- Roles & Responsibilities: outlines the responsibilities for data management amongst end users, data owners, data custodians, data stewards, and any other relevant cybersecurity roles
- Labelling, Marking, & Storage Requirements: guidelines on how data should be recorded and moved to storage once it has been classified.
- Data Security Requirements: states the required security controls for data in each classification level (encryption at rest, role based access control, redundant storage, physical security mechanisms, etc)
- Data Lifecycle: considerations/requirements for specific pieces or categories of data at each stage of the Data Lifecycle (Generation, Collection, Storage, Processing, Management, Analysis, Visualization & Interpretation, Destruction).
- Regulatory & Legal Requirements: clearly notes any pieces of data that are subject to specific laws/regulations (HIPAA, GDPR, PCI-DSS, etc), as well as the specific requirement sunder them.
- Ongoing Monitoring & Improvement: outlines the mechanisms in place for monitoring data usage and access, as well as a basic schedule for policy reviews and changes
The Data Lifecycle

