Data Classifications
Summary
PDF p.417Data classification and typing schemas tag data assets to manage them through their lifecycle. These schemas often categorize data based on confidentiality levels, such as public, confidential, secret, and top secret. They also classify information assets like proprietary, private/personal, sensitive, and restricted data.
In plain words
Supplementary — not from your PDFClassification schemas tag data so it can be managed through its lifecycle. A confidentiality scale runs public (no restriction), confidential (staff and trusted third parties under NDA), secret (serious harm if disclosed) and top secret (grave harm). Information asset classes include proprietary (company IP), private/personal (PII), sensitive (data that could harm individuals, as defined by GDPR) and restricted (highly confidential, tightly controlled).
Detailed explanation
PDF p.417-
Confidentiality-Based Classification
-
Public (Unclassified)
- Definition: No restrictions on viewing.
- Risk: No risk if disclosed, but risk if modified or unavailable.
-
Confidential
- Definition: Sensitive information, viewable by organization personnel and trusted third parties under NDAs.
- Risk: Does not require national security-level protection.
-
Secret
- Definition: Information that could cause serious national security damage if disclosed.
- Access: Restricted to individuals with a need to know.
-
Top Secret
- Definition: Highest classification, unauthorized disclosure could cause exceptionally grave national security damage.
- Access: Extremely restricted and monitored.
-
Public (Unclassified)
-
Information Asset Classification
-
Proprietary
- Definition: Intellectual property (IP) created and owned by the company.
- Examples: Product/service information, formulas, processes.
- Risk: Target for competitors and foreign governments, counterfeiting opportunities.
-
Private/Personal Data
- Definition: Information related to individual identity.
- Examples: PII such as names, addresses, social security numbers, financial information, health records.
-
Sensitive
- Definition: Personal data that could harm individuals if made public.
- Examples: Religious beliefs, political opinions, trade union membership, gender, sexual orientation, racial/ethnic origin, genetic data, health information.
- Regulation: Defined by GDPR.
-
Restricted
- Definition: Highly confidential information requiring stringent controls and limited access.
- Risk: Significant harm if disclosed or accessed by unauthorized individuals.
-
Proprietary
Important terms
taken from the text above- Public (Unclassified)
- No restrictions on viewing.
- Confidential
- Sensitive information, viewable by organization personnel and trusted third parties under NDAs.
- Secret
- Information that could cause serious national security damage if disclosed.
- Top Secret
- Highest classification, unauthorized disclosure could cause exceptionally grave national security damage.
- Proprietary
- Intellectual property (IP) created and owned by the company.
- Private/Personal Data
- Information related to individual identity.
- Sensitive
- Personal data that could harm individuals if made public.
- Regulation
- Defined by GDPR.
- Restricted
- Highly confidential information requiring stringent controls and limited access.
Examples & real-world scenarios
Supplementary — not from your PDF- A public marketing brochure classified 'public'.
- An employee's health record classified 'sensitive'.
- Source code classified 'proprietary'.
Scenario
A file holding staff religious and health details is more than ordinary personal data. Under GDPR it is 'sensitive' and needs stronger controls than a normal contact list.
Common mistakes
Supplementary — not from your PDF- Confusing 'confidential' (business) with 'sensitive' (special-category personal data).
- Leaving data unclassified, so no one knows how to protect it.
Practical skills
Supplementary — not from your PDF- Assign a classification level to a data example.
What I should remember
Key Points PDF p.417-
Confidentiality-Based Classification
- Public: No viewing restrictions, risk if modified/unavailable.
- Confidential: Sensitive, viewable by organization personnel/trusted third parties.
- Secret: Serious national security risk if disclosed, restricted access.
- Top Secret: Highest classification, grave national security risk, extremely restricted access.
-
Information Asset Classification
- Proprietary: Company-owned IP, target for competitors/governments.
- Private/Personal Data: PII, sensitive data like health records.
- Sensitive: Personal data that could harm individuals, regulated by GDPR.
- Restricted: Highly confidential, stringent controls, limited access.