17.07.2015 Views

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2 – Data Classification and Rolesseverity, will be implemented. The following are the descriptions of our sampleclass definitions:• Low Sensitivity (General Public)Information that is publicly available through other civil sources, orthat has been specifically designated as public information byregulation or corporate policy.• Medium Sensitivity (Internal Disclosure Only)Information that would cause minor damage to the organization orsubject if disclosed externally from the organization. The damagereferenced in this description includes exposure to litigation,compromise to security of assets, reputation of organization and itsassociates, elimination of competitive advantage, and violation ofregulation, industry standard or corporate policy. This damagepotential will be determined in conjunction with corporate legalcounsel. If the class is undeterminable, this is considered the defaultclass.• High Sensitivity (Restricted to Specific Personnel)Information that would cause major damage to the organization orsubject if disclosed externally from the organization. The damagereferenced in this description includes exposure to litigation,compromise to security of assets, reputation of organization and itsassociates, elimination of competitive advantage, and violation ofregulation, industry standard or corporate policy. This damagepotential will be determined in conjunction with corporate legalcounsel. This class includes information that is designated explicitly assensitive or identifiable through regulation, industry standard orcorporate policy.Notice that each class clearly establishes the authorities on which theclassification is based. In this case, the classification is based on regulationsthat are provided by the government, the establishment of industry standards byassociated organizations and the internal policies that are established within thecompany. This provides the analyst with the resources and objectivity neededto implement the classification.The fact that we have defined the "Medium" sensitivity class as the default,rather than "Low" or "High", instructs the security analyst that the disclosure ofall data should be restricted to internal personnel unless otherwise justified.The definitions of who is permitted to view each level of sensitivity data areintentionally broad at this stage. In the next step of the process, we start tospecify the particular groups and individuals that are granted access to thisclass of data.40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!