Start with your data
I covered how to classify the risk of loss of data and its impact in Chapter 10. When you are thinking about classifying your data, you need to consider the impact of the loss of the data. As a quick refresher, let’s review impact:
- Low impact is considered a minor inconvenience if the data is released. It could be names and telephone numbers that are already public in a telephone book or white pages.
- Moderate impact can be more substantial, such as financial losses due to identity theft, denial of benefits, or public humiliation.
- High impact could be catastrophic, with serious financial losses and even loss of life. High impact typically has to do with law enforcement.
Defining data classification should not fall on the Chief Information Security Officer (CISO). Rather, it is the responsibility of the data privacy officer, compliance, or legal teams to establish data classification levels and data protection strategies. The CISO’...