Information Asset Identification and Classification
Information asset classification refers to the classification of information assets based on their criticality to the business. These assets can be classified as confidential, private, or public. This classification helps organizations provide the appropriate level of protection for their assets. More resources should be utilized for the protection of confidential data compared to public data.
Benefits of Classification
- Classification helps to reduce the risk of under-protection of assets. Assets are protected in proportion to their criticality.
- Classification helps to reduce the cost of over-protection of assets.
Understanding the Steps Involved in Classification
A CISM aspirant should understand the following steps for the successful implementation of an information classification program:
Step 1: Create an inventory of all information assets the organization possesses.
Step 2: Establish ownership...