A Data Classification Policy Is The First Step To Data Loss Prevention
Having a data loss prevention product in place is critical for organizations today, but one should not even tempt the idea of implementing that product until they have an effective and workable data information security classification policy in place. Your DLP program will rely heavily on the administrative and technical controls provided by data classification software.
What Is A Data Classification Policy?
A data classification policy (also common referred to as a data security classification policy) makes it possible for all sensitive information within an organization to be handled correctly and according to the risk is poses to an organization. Every piece of sensitive information in an organization come with a “risk level” label which then allows your DLP to determine:
1. Which methods are best to protect that information; and
2. Which allowable resources will be used
3. The level of encryption necessary
4. The storage/transmittal requirements of that data
How Can Data Be Classified?
Organizations can have as many or as few risk classification levels in place as they deem necessary, but most will have the following three in place:
Public Data Classification
Data digitally stamped with a public classification label is information which is available to the general public and which is intended to be distributed outside of an organization. Some examples of this would include:
· Press releases
· Sales brochures
· Job announcements
Any information which falls under this category is produced for the public and can be freely distributed without harming your organization.
“Business Use Only” Data Classification
Information which falls under this category is used in business processes and, if exposed to the public, destroyed or modified, will not result in significant harm to the organization, its employees, business partners or customers. Some good examples of “business use only” data includes:
· Company phone lists
· Internal policy manuals
Confidential Data Classification
This label applies to data which is used in sensitive business processes. Any unauthorized modification, disclosure or destruction of information in this category will have an adverse affect on the organization, its employees, business partners and/or customers. Examples of confidential data include:
· Personally identifiable information
· Intellectual property
· Contractual negotiations
· Bank account numbers
Save Yourself Time With A Data Classification Solution
Tagging and labelling every piece of data which exists on your network today is extremely time consuming if not downright impossible. That is why data classification solutions exist.
A data classification solution is an enterprise-level tool which is incredibly complex and far-reaching. The most reliable tools on the market are usually hybrid tools which are intuitive, always learning and automatic while giving the option of manual classification.
When looking into your options, look for one which is:
· Automatic and offers transparent classification
· Allows for manual user-determined classification
· Has a recommendation option which will suggest appropriate classification options for you to confirm
Most importantly, in order to save time, the solution should automate the selection of the classification for each instance (whether that be manual classification, automatic classification or user prompted classification) based on the type of data which is being classified.













