Docy Child

DATA-1 Data Classification

Estimated reading: 2 minutes 631 views

What is this control about?

Data classification is the primary means by which data is protected based on its need for secrecy, sensitivity, or confidentiality. It is inefficient to treat all data the same when designing and implementing a security system. Some systems need more security than others.  Each organization must identify all the systems in use and classify the data stored within these systems by assigning a criteria of relevance. The criteria by which data is classified varies based on the organization performing the classification. Using whatever criteria is appropriate for each organization, data is evaluated and an appropriate data classification label is assigned to it.

TrustCloud has made this process approachable and classify systems into four categories:

  • Customer Confidential
  • [Company] Restricted
  • [Company] Confidential
  • Public

This classification can be adjusted as needed within the policy.

Available tools in the marketplace

 No tools recommendation for this section’

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • Data Classification policy

Control implementation

Note: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefit of automation

For a manual implementation: 

Define and document a process for personnel to quickly classify data

Classify all data and system and maintain an inventory

Review and refresh the inventory frequently

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide the most recently updated data classification policy

Evidence example

From the suggested action above, an example is provided below.

  1. Provide the most recently updated data classification policy.

No screenshot deemed necessary, as template provided serves as artifact example.

Join the conversation

Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.