Data Inventory and Classification
To help develop and implement effective data security controls, consider first conducting an inventory of the data and information your company is collecting, storing and sharing and the underlying operating systems, applications and software it is dependent upon. After the inventory is completed, you can classify the information and systems by sensitivity level. Based on the outcome of the classification, you can then consider data access privileges and controls commensurate with the importance or sensitivity of the information or systems. The process of inventorying and classifying data will involve a continuous assessment to help ensure that your company is aware of and provides adequate protections and security controls for all the data it collects, stores and shares at any point in time.
The business manager
A recommended method for conducting inventory and classifying information is to assign the responsibility to a business manager of each department within the company who has in-depth knowledge of the information and systems used in its day-to-day operations. Once completed, the business manager is responsible for keeping the inventory current.
Conducting the data inventory
A data inventory can help provide you with as complete a picture as possible of the information a company possesses or controls. When completed, all sensitive information can be grouped into categories to help confirm it is being secured in accordance to legal or regulatory requirements. Examples of how sensitive information may be categorized include:
- Personally Identifiable Information: Often referred to as PII, this information can include such things as first and last names, home addresses, credit card and bank account numbers, taxpayer identification numbers, medical records and Social Security numbers. It also can include driver’s license number, and home phone numbers, among other personally identifiable data.
- Intellectual property: This category can include proprietary and sensitive business information such as financial records, product designs, human resources records and internal correspondence and reports. It also can include intellectual property of others with whom the company has a business relationship.
- Customer information: This can include payment information such as payment card numbers and verification codes, billing and shipping addresses, email addresses, and purchasing history, among other data.
Classifying the data
Once inventoried and the sensitive information has been grouped in categories, the data can then be classified. Based on the classification, the Chief Information Security Officer (CISO) should establish the level of protection, both administrative and technological, that must be provided commensurate with the importance or sensitivity of the data. Four common data classifications are:
- Restricted (highly sensitive): This classification applies to the most sensitive business information that is intended strictly for use by the senior management team or other designated persons within the company. Its unauthorized disclosure could adversely impact the company, business partners, vendors and/or customers in the short and long term.
- Confidential (sensitive): This classification applies to information about or belonging to customers, employees and the business that a company may be obligated to protect. Consider restricting access to this data by business department and/or designated persons.
- Internal use only: This classification applies to sensitive information that is generally accessible by a wide internal audience and is intended for use only within a company. While its unauthorized disclosure to outsiders should be against policy and may potentially have a negative impact, the accidental or intentional disclosure of the information is not expected to significantly impact a company, employees, business partners, vendors or others.
- Public (general): Information that is freely available or is intended for distribution outside a company.
Conduct periodic classification reviews
Periodically reassessing the classification of the data can help ensure all new information is properly classified and can also help identify information that ceases to be sensitive or critical after extended periods of time and can be placed at a lower classification or can be disposed.
Implement an information retention and disposal policy
Often business departments may not realize they are taking an inventory of and/or otherwise keeping unnecessary data until they conduct an audit. In addition, they can unknowingly increase their data security and privacy risk by collecting data not needed for business purposes and retaining information that could be disposed. An information retention policy can provide guidance on what types of information should be retained, how long it should be retained and procedures for disposing or destruction of unneeded data.