Data classification policy (data classification policy template, what is data classification policy): the labels, what each one obliges, and why three is usually right

A data classification policy assigns every piece of information the organisation holds to one of a small number of labels, and makes each label carry its own handling requirements. That is the whole idea, and its value is entirely in the second half: a classification scheme with no consequences attached to the labels is an exercise in tidying, and it will be abandoned within a year.

Three labels, usually

Public, internal, confidential. Some organisations add a fourth for a genuinely restricted category, and a very few need more. The temptation is to add levels for precision, and it is worth resisting: every additional label multiplies the number of handling rules and reduces the chance that anybody classifies anything correctly. Three labels applied consistently beat five applied approximately.

What each label obliges

For each one, say who may access it, how it may be shared, whether it may leave company systems, how long it is kept and how it is destroyed. This is the part that makes classification worth doing, because it converts a label into a decision somebody can make without asking. NIST's media sanitization guidance frames the same idea from the disposal end: the sanitization decision follows from the confidentiality categorisation of the information, so classification and destruction are two halves of one policy.

Who classifies, and when

The person who creates or receives the information, at the moment they do. Retrospective classification projects fail. What works is a default label for everything, so unclassified information is not unprotected, plus a rule for the cases that need raising above it. Internal is the usual default, which means the only decisions anybody has to make are the two ends.

How it connects to everything else

Retention periods hang off the label. Access control hangs off the label. The answers to a customer's security questionnaire hang off the label. That is why this is usually the second policy worth writing after acceptable use: several other documents get shorter once it exists, because they can refer to a label rather than re-describing the information each time.

Questions people ask about data classification policy

Do we need to classify existing data?

Not all of it. Set a default, classify new information as it arrives, and reclassify old material only where a real decision depends on it.

Who owns the scheme?

One named person. Classification schemes drift when everybody may add a label, and drift is how you end up with five labels nobody can distinguish.

Is a template useful here?

The labels and their handling rules transfer well between organisations. What does not transfer is which of your information sits in which label.

Sources

Related answers

Build the policy freeKeep the record of who agreed