Home > Financial Services Information Security News > Drafting data classification policies and guidelines
Financial Services Information Security News:
EMAIL THIS
QUESTION & ANSWER

Drafting data classification policies and guidelines

By Editorial staff
17 Jan 2008 | SearchFinancialSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Shon Harris suggests ways to draft an internal procedure on how to handle confidential data. She discusses data classification polices, steps to develop and roll out a data classification program, and what your guidelines should cover.

I need to write an internal procedure on how to handle confidential data. Can you offer some suggestions?

Shon Harris:

The goals of data classification are listed below:

  • Availability, integrity and confidentiality are provided at the necessary levels for all identified assets
  • Return on investment by implementing controls where they are needed the most
  • Map data protection levels with organizational needs
  • Mitigate threats of unauthorized access and disclosure
  • Comply with legal and regulation requirements

The steps to develop and roll out a data classification program are:

  1. Compile an inventory of all information assets

  2. Define levels of protection for information assets

  3. Define a classification criteria

  4. Develop information classification policy

  5. Define information handling and labeling procedures

  6. Assign responsibility for classification to the owner of information

  7. Assign a security classification to all information assets

  8. Classify information according to sensitivity and how much protection is required

  9. Apply the classification system to documents, records, data files, and disks.

  10. Develop information handling procedures for each class of information

  11. Develop information labeling procedures for each class of information

  12. Integrate into security awareness and training programs

You should have a data classification policy that covers the following:

  • Information as assets of individual business units

  • Declare business unit managers as information owners

  • Declare IT as data custodians

  • Classification scheme

  • Definitions for each classification

  • Criteria for each classification

  • Roles and responsibilities of classification

Your written procedures and guidelines should address the following;

  • How to classify information
  • How to change classification level if needed
  • How to communicate classification change to IT
  • Periodic review of
    • Current classification levels and mapping to business needs
    • Current access rights and privileges
    • Protection levels that current controls are using

The NIST 800-60 document may be too "DoD centric" and an overkill for your needs, but this document has the necessary guidelines to develop and maintain a structured data classification program.

Sun provides a more digestible and understandable approach, which can be found at http://www.sun.com/blueprints/tools/samp_sec_pol.pdf

Lastly, this link provides detailed guidelines for how to treat different types of data.


Tags: Data classification methods and guidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Data classification methods and guidelines
How to secure data backup
Download presentations from Financial Information Security Decisions 2009
Data governance and classification
Data encryption: Pre-implementation best practices
Data encryption: Q&A with Eric Leighninger
Protecting data in a merger and acquisition
Event data analysis
By addressing data privacy, companies avoid public scrutiny
How to classify security for enterprise file folders
Encryption best practices

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Financial Security News Topics: Compliance, Management Strategy, Security Technology
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts