About this program
Do you actually classify data — and is the classification reflected in access control, encryption and retention? Quick snapshot.
Risks addressed
- High Confidential data treated like public data u2014 over-shared
- Medium No owners u2014 nobody decides who can access what
- High Restricted data exfiltrated without detection
- Medium Data kept indefinitely, increasing breach blast radius
Controls (6)
-
Classification scheme published
HighThis control requires the organization to develop, approve, and publish a formal data classification scheme that defines categories of information based on sensitivity, criticality, and regulatory requirements. The scheme must specify classification levels (e.g., Public, Internal, Confidential, Restricted), criteria for…
How to test + evidence
Testing procedure: A simple, agreed scheme (e.g. Public / Internal / Confidential / Restricted) is documented.
Evidence to collect: Classification policy.
-
Owners assigned per data type
HighThis control requires formal assignment of accountable data owners for each defined data classification type or category within the organization's inventory. Data owners are responsible for determining access rights, classification levels, retention policies, and acceptable use for their assigned data…
How to test + evidence
Testing procedure: Each data type has a named information owner.
Evidence to collect: Data owner register.
-
Labels applied to documents at source
MediumThis control ensures that classification labels (e.g., Public, Internal, Confidential, Restricted) are assigned to documents, records, and data assets at the point of creation or initial receipt into the organization's custody. Labeling at source prevents ambiguity, ensures consistent handling from…
How to test + evidence
Testing procedure: Office / Google docs apply labels; spot-check sample of recent docs.
Evidence to collect: Labelling tool config + samples.
-
Access controls reflect classification
HighThis control ensures that access permissions, authentication requirements, and authorization levels are directly tied to the sensitivity classification of data and systems (e.g., public, internal, confidential, restricted). Organizations establish access control matrices or role-based access control (RBAC) schemes that enforce…
How to test + evidence
Testing procedure: Confidential / Restricted data is access-restricted, encrypted, and audited.
Evidence to collect: ACL extracts + encryption posture.
-
Retention rules per classification
MediumThis control requires organizations to define and enforce data retention periods that are explicitly mapped to data classification levels (e.g., public, internal, confidential, restricted). Each classification tier receives specific retention durations and destruction schedules based on regulatory, legal, business, and…
How to test + evidence
Testing procedure: Retention policy maps classification to retention period.
Evidence to collect: Retention policy.
-
DLP / outbound monitoring on Restricted data
HighData Loss Prevention (DLP) systems monitor and control the movement of sensitive data classified as Restricted across network boundaries, endpoints, and cloud services. The control uses content inspection, pattern matching, and policy enforcement to detect and block unauthorized transmission of…
How to test + evidence
Testing procedure: DLP rules detect/block exfil of Restricted-labelled data through email / cloud / removable media.
Evidence to collect: DLP policy export.