Skip to content

06 Data Classification

Organizations cannot protect information effectively if they do not understand:

What data they have, where it exists, how sensitive it is, who owns it, and how it should be handled.

This is the purpose of Data Classification.

A practical enterprise data-governance model looks like:

Data Discovery
Data Inventory
Data Ownership
Classification
Labeling
Handling Requirements
Access Control
Encryption
DLP
Retention
Monitoring
Continuous Governance

Data classification connects privacy, cybersecurity, compliance, cloud security, records management, and information governance.

By the end of this lesson, you will be able to:

  • Explain data classification.

  • Understand why organizations classify information.

  • Identify structured and unstructured data.

  • Understand data discovery.

  • Build a data inventory.

  • Define classification levels.

  • Differentiate Public, Internal, Confidential, and Restricted information.

  • Identify personal and sensitive information.

  • Understand data ownership.

  • Define labeling requirements.

  • Establish handling requirements.

  • Map classifications to access controls.

  • Map classifications to encryption requirements.

  • Understand Data Loss Prevention.

  • Apply classification to cloud environments.

  • Integrate classification with retention.

  • Map regulatory requirements to data categories.

  • Test classification controls.

  • Build enterprise classification artifacts.

Data Classification is the process of:

Identifying
Categorizing
Labeling
Protecting

information based on factors such as:

Sensitivity
Business Value
Confidentiality
Legal Requirements
Privacy Requirements
Security Risk
Business Impact

The goal is simple:

Apply protection appropriate to the value and sensitivity of the information.

Consider two files:

File A
Public Product Brochure

and:

File B
Customer Database
Containing Financial Information

Applying exactly the same controls to both would make little sense.

Instead:

Public Information
Lower Protection Requirements

while:

Highly Sensitive Information
Stronger Protection Requirements

3. Classification Enables Risk-Based Security

Section titled “3. Classification Enables Risk-Based Security”

Without classification:

All Data
Same Controls

This creates either:

Under-Protection

or:

Over-Protection

Classification enables:

Data Sensitivity
Risk
Appropriate Control

4. Classification Is Not Only a Security Activity

Section titled “4. Classification Is Not Only a Security Activity”

Data classification affects:

Privacy
Cybersecurity
GRC
Legal
Cloud
IAM
DLP
Records Management
Incident Response
Backup
Third-Party Risk

Data moves through a lifecycle.

Create / Collect
Store
Use
Share
Archive
Delete

Classification should influence controls throughout this lifecycle.

Before classifying information, organizations must understand what data exists.

This process is:

Data Discovery

Enterprise information may exist in:

Databases
File Servers
Employee Laptops
Email
Cloud Storage
SaaS Platforms
Data Lakes
Source Code Repositories
Backups
Collaboration Platforms
Mobile Devices
Paper Records

A major challenge is:

Shadow Data

Information may exist outside approved systems.

Examples:

Personal Cloud Drives
Local Downloads
Spreadsheets
USB Devices
Email Attachments
Unapproved SaaS Platforms

Structured data normally follows a defined schema.

Examples:

SQL Database
CRM Database
ERP Database
HR Database
Transaction Database

Unstructured information includes:

Documents
PDFs
Emails
Presentations
Images
Chat Messages
Source Files

Unstructured data can be significantly harder to discover and classify.

After discovery, build:

01 Enterprise Data Inventory

Example:

Data Asset System Owner Data Type Classification
Customer DB CRM Sales Customer PI Confidential
Payroll HRIS HR Employee PI Restricted
Website Content CMS Marketing Public Public
Source Code Git Engineering IP Confidential

Do not confuse:

System

with:

Data Asset

For example:

Microsoft SQL Server

is a technology/system.

Inside it may exist:

Customer Data
Financial Data
Employee Data
Transaction Data

with different classifications.

Every significant data asset should have an accountable:

Data Owner

The owner is generally responsible for decisions involving:

Classification
Access
Use
Sharing
Retention
Protection

A useful distinction:

Data Owner
Business Accountability

while:

Data Custodian
Technical Administration

Example:

HR Director
Data Owner
IT Database Administrator
Data Custodian

Create:

02 Data Owner Register

Use:

Data Asset Owner Custodian System Classification

Organizations can design different classification models.

A practical four-level model is:

Public
Internal
Confidential
Restricted
Restricted
Confidential
Internal
Public

Sensitivity increases upward.

Public information can generally be disclosed publicly without material harm.

Examples:

Published Website Content
Press Releases
Public Marketing Materials
Published Job Advertisements
Public Documentation

Typical controls may include:

Integrity Protection
Change Approval
Availability
Version Control

Public does not mean:

No Security Required

For example, unauthorized modification of public website content still creates risk.

Internal information is intended primarily for internal organizational use.

Examples:

Internal Procedures
Meeting Notes
Internal Announcements
Organization Charts
Internal Training Material

Unauthorized disclosure may cause:

Limited Business Impact

but normally would not create catastrophic harm.

Confidential information could cause significant harm if improperly disclosed.

Examples:

Customer Information
Business Strategy
Contracts
Financial Information
Source Code
Security Architecture
Employee Information

Typical controls:

Need-to-Know Access
Authentication
Encryption
Logging
Sharing Restrictions
DLP

Restricted is typically the organization’s highest classification.

Examples may include:

Authentication Secrets
Private Cryptographic Keys
Highly Sensitive Personal Data
Payment Card Data
Critical Security Secrets
Highly Sensitive Financial Data

Typical controls may include:

Strict Need-to-Know
MFA
Privileged Access Management
Encryption
DLP
Detailed Logging
Restricted Sharing
Strong Retention Controls

Create:

03 Data Classification Matrix
Level Sensitivity Disclosure Impact Example
Public Low Minimal Website
Internal Moderate Limited Internal procedure
Confidential High Significant Customer information
Restricted Very High Severe Credentials

Classification should not depend on:

Employee Guessing

Provide clear criteria.

Ask:

Would Disclosure Cause Harm?
Is It Regulated?
Does It Contain Personal Data?
Is It Commercially Sensitive?
Could It Enable Cyberattack?
Would Loss Affect Customers?
Would Disclosure Create Legal Exposure?

Consider:

Confidentiality Impact
Integrity Impact
Availability Impact

For example:

Private Encryption Key

has extremely high confidentiality impact.

Meanwhile:

Emergency Operating Procedure

may have high availability importance.

Some data requires protection because of regulation.

Examples:

PCI DSS
→ Account Data
HIPAA
→ PHI / ePHI
GDPR
→ Personal Data
CCPA
→ Personal Information
Privacy Laws
→ Sensitive Information

Create:

04 Regulatory Data Register

Use:

Data Regulation System Classification Owner

Personal data can include information relating to an identifiable individual.

Examples:

Name
Email
Address
Employee ID
IP Address
Device Identifier
Location Data

depending on the applicable privacy framework.

Certain personal information requires greater protection.

Examples may include:

Health Information
Biometric Information
Financial Credentials
Government Identifiers
Precise Geolocation
Certain Demographic Information

depending on applicable law.

Create:

05 Sensitive Data Inventory

Use:

Data Category Regulation System Classification

Classification programs should also protect:

Source Code
Algorithms
Designs
Research
Product Roadmaps
Trade Secrets
Engineering Documentation

These may not always be regulated personal information but can have enormous business value.

Examples:

Passwords
API Keys
Tokens
Certificates
Private Keys
Database Credentials
Cloud Access Keys

should generally receive very strong protection.

36. Secrets Should Not Be Treated Like Documents

Section titled “36. Secrets Should Not Be Treated Like Documents”

Weak:

API Key
Spreadsheet
Confidential

Stronger:

API Key
Secrets Manager
Restricted Access
Rotation
Audit Logging

Organizations should establish a:

Data Classification Policy

or:

Information Classification Standard

A classification standard should define:

Classification Levels
Classification Criteria
Data Owners
Labeling
Handling
Storage
Transmission
Sharing
Retention
Disposal
Exceptions

Create:

06 Enterprise Data Classification Standard

Suggested structure:

1 Purpose
2 Scope
3 Roles
4 Classification Levels
5 Classification Criteria
6 Labeling
7 Handling Requirements
8 Access
9 Storage
10 Transmission
11 Sharing
12 Retention
13 Disposal
14 Exceptions
15 Compliance

Once classified, information may receive a:

Label

Examples:

PUBLIC
INTERNAL
CONFIDENTIAL
RESTRICTED

Document:

Cloud Security Architecture

Label:

CONFIDENTIAL

The label communicates handling expectations.

Labels may appear in:

Document Headers
Document Footers
Email Headers
Metadata
File Properties
Database Metadata
Cloud Labels
DLP Systems

Users may manually choose:

Classification Label

when creating information.

Example:

Create Document
Select:
CONFIDENTIAL

Modern tools can automatically detect:

Credit Card Numbers
Government IDs
Health Information
Credentials
Personal Information
Keywords
Patterns

and apply classification.

Document Created
Content Scanned
Sensitive Pattern Found
Classification Applied
Security Policy Enforced

Automated systems may use:

Pattern Matching
Regular Expressions
Machine Learning
Context Analysis
Exact Data Match
Fingerprinting

Example:

16-Digit Number

does not automatically mean:

Payment Card Number

Classification systems require tuning.

More dangerous:

Sensitive Data Exists
Classification Engine
Does Not Detect It

Therefore automated classification should be tested.

Classification becomes useful only when it changes how information is handled.

Create:

07 Data Handling Matrix
Control Public Internal Confidential Restricted
Public Sharing Yes No No No
Authentication Optional Yes Yes Yes
Encryption at Rest Optional Recommended Required Required
Encryption in Transit Recommended Required Required Required
External Sharing Yes Controlled Approved Highly Restricted
Logging Basic Standard Enhanced Enhanced
DLP No Optional Yes Yes

Exact requirements should reflect organizational risk.

Classification should influence:

Who Can Access Data?

Example:

Public
→ Anyone
Internal
→ Workforce
Confidential
→ Authorized Business Roles
Restricted
→ Explicitly Authorized Personnel

For sensitive information:

User
Business Need
Approval
Minimum Access

Even if an employee works for the organization:

Employee
Access to All Confidential Data

Create:

08 Classification Access Matrix

Use:

Classification Role Access Approval Review

Classification can determine encryption requirements.

Example:

Restricted
Encryption at Rest
+
Encryption in Transit

Protect stored data in:

Database
Disk
Object Storage
Backup
Laptop
Mobile Device

Protect data moving through:

HTTPS
TLS
VPN
Secure API
Encrypted File Transfer

Highly sensitive information also requires strong:

Cryptographic Key Management

including:

Generation
Storage
Access
Rotation
Revocation
Destruction

Data Loss Prevention (DLP) technologies help detect and prevent inappropriate movement of sensitive information.

Sensitive Data
DLP
Detect
Alert / Block / Encrypt

DLP can monitor:

Email
Endpoint
Web Upload
Cloud Storage
USB
Collaboration Platforms

Employee attempts:

Customer Database
Personal Gmail

DLP detects:

CONFIDENTIAL

and:

Blocks Transfer

Create:

09 Classification DLP Matrix

Use:

Classification Channel Action Exception Owner

Example:

CONFIDENTIAL

email may trigger:

Encryption
External Recipient Warning
Forwarding Restriction
DLP Inspection

For Confidential information:

External Sharing
Business Need?
Authorized Recipient?
Approved Channel?
Encryption?

Restricted data may require:

Explicit Approval
Secure Portal
Encryption
Recipient Authentication
Logging

Sensitive information copied to:

USB

creates significant risk.

Possible policy:

Restricted Data
No Removable Media

unless formally approved.

Classification also affects physical information.

Example:

Restricted Document
Secure Printing
Controlled Collection
Locked Storage
Secure Destruction

Classification is not only digital.

Examples:

Printed Contracts
Medical Records
Personnel Files
Financial Documents

also require protection.

Sensitive paper records may require:

Cross-Cut Shredding
Secure Disposal Vendor
Destruction Certificate

Electronic information may require:

Secure Erasure
Cryptographic Erasure
Media Destruction

depending on risk.

Classification should connect to:

Retention

but:

Classification and retention are different concepts.

Classification answers:

How Sensitive Is It?

Retention answers:

How Long Should We Keep It?

Create:

10 Data Retention & Classification Matrix

Use:

Data Classification Retention Trigger Disposal
Customer Contract

Classification:

Confidential

Retention:

Contract Term
+
Applicable Legal Period

Modern enterprise information frequently resides in:

AWS
Azure
Google Cloud
SaaS

Classification must therefore extend into cloud environments.

Examples:

Object Storage
Managed Databases
Data Warehouses
Data Lakes
Snapshots
Backups

Create:

11 Cloud Data Classification Register

Use:

Cloud Resource Data Classification Owner Encryption

Classification may be represented through:

Tags
Labels
Metadata
Resource Policies

Example:

classification = restricted

Classification metadata can trigger security policies.

classification=restricted
Encryption Required
Public Access Blocked
Logging Enabled
Backup Required

Example:

Restricted Customer Data
Object Storage
Public Access Enabled

This represents:

Classification
+
Configuration
+
Security

failure.

Sensitive information can also appear in:

CRM
Ticketing Platform
HR Platform
Collaboration Tool
AI Application

Organizations need visibility beyond infrastructure they directly manage.

A modern classification program must address:

Generative AI

Example:

Employee
Copies Restricted Source Code
Public AI Service

Potential issues:

Data Leakage
IP Exposure
Privacy Risk
Third-Party Processing
Contractual Risk

Classification can drive:

AI Usage Rules

Example:

Classification Public AI Tool
Public Allowed
Internal Controlled
Confidential Restricted
Restricted Prohibited

Actual policy should depend on enterprise-approved AI services and controls.

Source code may contain:

Intellectual Property
Credentials
Architecture Information
Security Logic
Customer Information

Therefore repositories should also participate in classification governance.

Example:

Developer Commit
AWS Access Key
Repository Scanner
Secret Detected
Commit Blocked
Credential Rotated

A common mistake:

Production Database
= Restricted

but:

Database Backup
= Unclassified

Wrong.

A useful principle:

A copy of sensitive data normally inherits the sensitivity of the source data.

Similarly:

Restricted Database
Snapshot
Restricted

Logs can contain:

User IDs
IP Addresses
Email Addresses
Tokens
Request Data
Application Data

Logs therefore also require classification.

Example:

Security Logs
Confidential

depending on organizational policy.

Another major risk:

Production Customer Data
Copied to Development

Developers may now have sensitive production information.

Prefer:

Synthetic Data
Masked Data
Tokenized Data
De-Identified Data

where appropriate.

Example:

4111 1111 1111 1111

becomes:

XXXX XXXX XXXX 1111

Tokenization replaces sensitive information with a substitute value.

Sensitive Value
Tokenization
Token

Classification helps determine incident severity.

Example:

Lost Laptop

Question:

What Data Was Stored?

If:

Public Data Only

risk may be limited.

If:

Restricted Customer Data

incident severity changes dramatically.

Security Event
Data Involved
Classification
Regulatory Impact
Incident Severity

Before sharing information with a vendor:

What Classification
Will They Receive?

Create:

12 Third-Party Data Sharing Register

Use:

Vendor Data Classification Purpose Protection

Contracts may need requirements involving:

Confidentiality
Encryption
Access Control
Incident Notification
Retention
Deletion
Subprocessors

Classification may also interact with:

Data Residency
Data Sovereignty
Cross-Border Transfer

Example:

Restricted Customer Data
Approved Region Only

Sometimes a business cannot immediately meet a handling requirement.

Example:

Legacy Application
Cannot Encrypt
Restricted Data

Do not silently ignore the standard.

Use:

Exception
Risk Assessment
Compensating Control
Approval
Expiration

Create:

13 Data Classification Exception Register

Use:

Exception Data Risk Control Owner Expiry

Classification can change.

Example:

Confidential
Product Roadmap

after public product launch may become:

Public

Workflow:

Existing Classification
Business Change
Owner Review
Reclassification
Controls Updated

Organizations may establish:

Annual Review
Event-Driven Review
System Change Review
Regulatory Change Review

GRC should test whether classification exists only:

On Paper

or operates technically.

Population:

120 Business Systems

Inventoried:

105

Potential finding:

15 Systems
Without Data Inventory

Sample:

50 Sensitive Data Assets

Results:

43 Have Owners
7 Have No Owner

Potential:

Data Governance Gap

Sample:

100 Sensitive Documents

Results:

82 Correctly Classified
12 Incorrect
6 Unclassified

Calculate:

Classification Accuracy
=
82%

Requirement:

Restricted Data
Must Be Encrypted at Rest

Population:

40 Restricted Data Stores

Encrypted:

38

Potential finding:

2 Restricted Stores
Not Encrypted

Sample:

30 Confidential Files
Shared Externally

Verify:

Business Need
Approval
Recipient
Encryption
Expiration

Create controlled test:

Restricted Test Data
Attempt Email to
External Account

Expected:

Blocked

Actual:

Allowed

Potential:

DLP Control Failure

Identify:

Restricted Cloud Buckets

Verify:

Public Access Disabled
Encryption Enabled
Logging Enabled
Approved Region
Access Restricted

Policy:

Customer Data
Retention:
7 Years

Actual:

Oldest Record:
14 Years

Potential:

Retention Control Gap

Review:

AI Application Logs

for:

Confidential Data
Restricted Data
Source Code
Customer PI

Create:

14 Data Classification Gap Register

Use:

Finding Classification Risk Severity Owner Due

115. Root Cause Example — Unclassified Data

Section titled “115. Root Cause Example — Unclassified Data”

Finding:

Customer Export Files
Are Unclassified

Why?

Files Generated
Automatically

Why?

Application Does Not
Apply Metadata

Why?

Classification Was Not
Included in System Design

Root cause:

Data classification requirements were not integrated into the application development lifecycle.

Apply Confidential
Classification
to Existing Files
Update Application
Automatically Apply
Classification Metadata

118. Root Cause Example — Public Cloud Storage

Section titled “118. Root Cause Example — Public Cloud Storage”

Finding:

Restricted Customer Data
Stored in Public Bucket

Why?

Engineer Enabled
Public Access

Why?

No Preventive Policy

Root cause:

Cloud controls do not enforce storage restrictions based on data classification.

Classification Tag
Cloud Policy
Prevent Public Access

Track:

Metric Target
Data Assets Inventoried 100%
Sensitive Assets Classified 100%
Data Assets With Owners 100%
Restricted Data Encrypted 100%
Approved External Sharing 100%
DLP Coverage 100%
Overdue Exceptions 0
Unclassified Sensitive Data 0
Classified Data Assets
────────────────────── × 100
Total Data Assets
Assets With Owners
────────────────── × 100
Total Data Assets
Encrypted Restricted Stores
─────────────────────────── × 100
Restricted Data Stores
Sensitive Data Assets
Without Classification
Restricted Data
Shared Externally
Without Approval
Confidential / Restricted
Cloud Resources
with Public Access
Sensitive Data
Beyond Approved
Retention Period

128. Practical Activity — Build Classification Model

Section titled “128. Practical Activity — Build Classification Model”

Use fictional organization:

CloudPay

Define:

Public
Internal
Confidential
Restricted

and create handling requirements for each.

Classify:

Company Website
Internal Procedure
Employee Directory
Customer Database
Credit Card Data
AWS Root Credentials
Source Code
Security Architecture
Press Release
Payroll Data

130. Practical Activity — Identify Owners

Section titled “130. Practical Activity — Identify Owners”

Assign owners to:

Customer Data
Employee Data
Financial Data
Source Code
Security Logs

CloudPay has:

Bucket A
Marketing Images
Bucket B
Customer Statements
Bucket C
Database Backups
Bucket D
Application Logs

Determine:

Classification
Encryption
Public Access
Logging
Retention

Create policies for:

Payment Card Data
Customer PI
Source Code
Credentials

across:

Email
Web
USB
Cloud Storage

133. Practical Activity — Vendor Sharing

Section titled “133. Practical Activity — Vendor Sharing”

Vendor receives:

Customer Name
Email
Purchase History

Determine:

Classification
Purpose
Required Contract
Encryption
Retention
Deletion

Employee wants to paste:

Production Application
Source Code

into a public AI tool.

Determine:

Classification
Risk
Policy
Approved Alternative
  • classification policy established.

  • classification levels defined.

  • classification criteria documented.

  • roles and responsibilities assigned.

  • exception process established.

  • structured data discovered.

  • unstructured data discovered.

  • cloud data included.

  • SaaS data included.

  • shadow data considered.

  • data assets inventoried.

  • systems identified.

  • data types documented.

  • regulatory requirements mapped.

  • data owners assigned.

  • custodians identified.

  • ownership reviews performed.

  • Public defined.

  • Internal defined.

  • Confidential defined.

  • Restricted defined.

  • sensitive data classified.

  • labeling standard established.

  • documents labeled.

  • emails addressed.

  • metadata supported.

  • automated classification considered.

  • access requirements defined.

  • storage requirements defined.

  • transmission requirements defined.

  • external sharing requirements defined.

  • printing requirements defined.

  • disposal requirements defined.

  • encryption mapped to classification.

  • IAM mapped to classification.

  • DLP mapped to classification.

  • logging mapped to classification.

  • secrets protected separately.

  • cloud resources classified.

  • classification metadata implemented.

  • public access controlled.

  • encryption validated.

  • regions assessed.

  • shared data classified.

  • vendors identified.

  • contractual protections established.

  • retention and deletion addressed.

  • AI handling rules established.

  • sensitive-data restrictions defined.

  • approved AI platforms identified.

  • AI usage monitored where appropriate.

  • retention periods defined.

  • classification connected to retention.

  • deletion controls implemented.

  • classification accuracy tested.

  • encryption tested.

  • DLP tested.

  • cloud controls tested.

  • external sharing tested.

  • exceptions reviewed.

If:

Everything
=
Confidential

then effectively:

Nothing
=
Meaningfully Classified

Mistake 2 — Classification Exists Only in Policy

Section titled “Mistake 2 — Classification Exists Only in Policy”

Documents and systems remain:

Unlabeled
Unprotected
Unmonitored

Mistake 3 — Classification Is Left Entirely to Users

Section titled “Mistake 3 — Classification Is Left Entirely to Users”

Users may classify inconsistently.

Combine:

User Judgment
+
Automation
+
Clear Rules

Sensitive data increasingly exists outside traditional data centers.

Backups contain the same sensitive information as production.

Logs can contain personal information and credentials.

Mistake 7 — Test Environments Are Ignored

Section titled “Mistake 7 — Test Environments Are Ignored”

Production information is copied into weakly protected development environments.

Mistake 8 — Labels Do Not Trigger Controls

Section titled “Mistake 8 — Labels Do Not Trigger Controls”
RESTRICTED

is meaningless if users can still:

Email It Anywhere
Make It Public
Copy It to USB

Without ownership, classification decisions become unclear.

Mistake 10 — AI Is Missing From the Handling Standard

Section titled “Mistake 10 — AI Is Missing From the Handling Standard”

Modern classification programs must govern how sensitive information is used with AI systems.

Policy
Four Labels
Employee Training
Discovery
Inventory
Ownership
Classification
Labeling
IAM
Encryption
DLP
Cloud Enforcement
Third-Party Governance
Retention
Monitoring
Continuous Testing

A GRC analyst supporting Data Classification may:

  • maintain the classification standard.

  • coordinate enterprise data discovery.

  • maintain data inventories.

  • identify regulatory data.

  • coordinate classification decisions.

  • maintain data-owner registers.

  • define handling requirements.

  • map classification to security controls.

  • review cloud data classification.

  • review third-party data sharing.

  • coordinate DLP requirements.

  • review classification exceptions.

  • assess AI data handling.

  • test classification controls.

  • track remediation.

  • maintain evidence.

  • report classification KPIs and KRIs.

GRC connects:

Privacy
Cybersecurity
Legal
Data Governance
Cloud
IAM
DLP
Engineering
AI Governance
Business Owners
Internal Audit
Sensitive Data
Identified Manually
Classification Policy
Four Levels
Handling Standard
Data Inventory
Ownership
Labels
DLP
Control Testing
Automated Classification
Cloud Enforcement
IAM Integration
DLP Integration
Continuous Discovery
Automated Classification
Policy-as-Code
Real-Time DLP
Continuous Compliance

For every data asset ask:

What Is This Data?
Where Is It?
Who Owns It?
How Sensitive Is It?
Is It Regulated?
What Happens If
It Is Disclosed?
What Happens If
It Is Modified?
What Happens If
It Is Unavailable?
Who Needs Access?
Should It Be Encrypted?
Can It Be Shared?
Can It Leave
the Organization?
Can It Be Used
with AI?
How Long
Should We Keep It?
How Should
We Destroy It?
Can We Detect
Improper Movement?
Can We Prove
Controls Are Working?

For every cloud resource ask:

What Data
Does It Contain?

For every external transfer ask:

What Classification
Is Leaving
Our Environment?

For every new technology ask:

Can It Store,
Process,
or Expose
Sensitive Data?

That is the practical mindset behind enterprise data classification.

  • Data classification categorizes information according to sensitivity, value, regulatory requirements, and potential impact.

  • Organizations should discover data before attempting to govern it.

  • Data inventories establish visibility into information assets.

  • Every significant data asset should have an accountable owner.

  • A practical classification model uses Public, Internal, Confidential, and Restricted.

  • Classification should drive technical and operational controls.

  • Labels alone do not protect information.

  • Access control, encryption, DLP, logging, and sharing controls should align with classification.

  • Copies, backups, snapshots, and test data must also be considered.

  • Cloud and SaaS environments must participate in classification governance.

  • Regulatory information should be mapped to applicable compliance requirements.

  • Data classification and retention are related but different.

  • AI platforms introduce another important data-handling channel.

  • Classification should integrate with incident response and third-party risk management.

  • GRC helps translate classification policy into measurable and testable controls.

Before continuing, make sure you can answer:

  1. What is data classification?

  2. Why is classification important?

  3. What is data discovery?

  4. What is the difference between structured and unstructured data?

  5. What is a data inventory?

  6. What is a Data Owner?

  7. What is the difference between a Data Owner and Data Custodian?

  8. What are the four common classification levels?

  9. What is Public information?

  10. What is Internal information?

  11. What is Confidential information?

  12. What is Restricted information?

  13. How should regulatory data affect classification?

  14. What is data labeling?

  15. What is automated classification?

  16. What is a Data Handling Matrix?

  17. How should classification affect encryption?

  18. What is DLP?

  19. Why must backups be classified?

  20. How should classification govern AI usage?

➡️ Next: 07 — Data Retention

In the next lesson, you will move from determining how sensitive information is to determining how long information should exist and when it must be securely disposed of.

You will examine:

Business Requirements
Legal Requirements
Regulatory Requirements
Data Categories
Retention Periods
Retention Triggers
Legal Holds
Archive
Deletion
Secure Disposal
Retention Exceptions
Automated Enforcement
Continuous Monitoring

You will also build practical artifacts including a Data Retention Policy, Records Retention Schedule, Regulatory Retention Register, Legal Hold Register, Data Disposal Standard, Retention Exception Register, Cloud Retention Matrix, SaaS Retention Register, and Retention Compliance Dashboard.