Data Classification and Handling
Why classify?
Classification lets an organization apply the right amount of protection to the right data. Over-protecting everything is expensive; under-protecting anything is dangerous. Each classification level carries required handling rules for labelling, storage, transmission, and destruction.
- Commercial levels: public, sensitive, private, confidential.
- Military/government levels: unclassified, sensitive but unclassified, confidential, secret, top secret.
- Classification criteria: value, age, useful life, legal requirements, and damage if disclosed.
Roles and responsibilities
- Data owner — a manager who is accountable for the data, assigns classification, and approves access.
- Data custodian — IT staff who implement and maintain the controls the owner requires (backups, patching).
- System owner — accountable for the system that processes the data.
- User — follows operating procedures and the acceptable use policy.
- Auditor — independently verifies that controls work as intended.
Data lifecycle and remanence
Data must be protected from creation through destruction. Data remanence is the residual representation of data that remains after deletion — the reason 'delete' is never enough for sensitive media.
- Clearing (overwriting) — protects against ordinary recovery tools; media can be reused internally.
- Purging — degaussing or cryptographic erase; media can leave the organization.
- Destruction — shredding, incineration, pulverizing; the only option for the most sensitive media.
- Retention schedules must satisfy legal, regulatory, and business needs — and then data should be disposed of.