Skip to content

ITIS-468-47605: Certified Information Systems Security Professional (CISSP) Cert Exam Prep

Fall 2026

Data Classification and Handling

Why classify?

Classification lets an organization apply the right amount of protection to the right data. Over-protecting everything is expensive; under-protecting anything is dangerous. Each classification level carries required handling rules for labelling, storage, transmission, and destruction.

  • Commercial levels: public, sensitive, private, confidential.
  • Military/government levels: unclassified, sensitive but unclassified, confidential, secret, top secret.
  • Classification criteria: value, age, useful life, legal requirements, and damage if disclosed.

Roles and responsibilities

  • Data owner — a manager who is accountable for the data, assigns classification, and approves access.
  • Data custodian — IT staff who implement and maintain the controls the owner requires (backups, patching).
  • System owner — accountable for the system that processes the data.
  • User — follows operating procedures and the acceptable use policy.
  • Auditor — independently verifies that controls work as intended.

Data lifecycle and remanence

Data must be protected from creation through destruction. Data remanence is the residual representation of data that remains after deletion — the reason 'delete' is never enough for sensitive media.

  • Clearing (overwriting) — protects against ordinary recovery tools; media can be reused internally.
  • Purging — degaussing or cryptographic erase; media can leave the organization.
  • Destruction — shredding, incineration, pulverizing; the only option for the most sensitive media.
  • Retention schedules must satisfy legal, regulatory, and business needs — and then data should be disposed of.
Walkthrough: labelling a data set — Embed placeholder.