17.07.2015 Views

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2 – Data Classification and RolesUse this catalog view like any other view or table. It can join to other tablesand be filtered on any column contained within the catalog view.Refining the Sensitivity ClassesAlthough a good start, the classifications in our simplified example are often alittle too general to be useful in a real-world commercial business environment.Often the measurements of potential damage to an organization or subject ofthe sensitive data have more complex levels of measurements than simply"minor" and "major". Also, the internal structure of a commercial business canbe rather complex. Simply restricting data to "Internal Use Only" may be a toogeneral and sorely insufficient restriction.Disclosure Damage PotentialIn a real-world scenario, the differentiation of the levels of potential damage tothe organization or the subject of the sensitive data can be rather complex. Hereis an example of a series of classes that might be more suitable for use in acommercial setting:Public (General Public) – Information that is publicly available through othercivil sources or specifically designated by regulation or corporate policy of itspublic information status.Damage Potential: Information that if improperly disclosed presents noexposure to lawsuits, fines, criminal prosecutions, loss of competitiveadvantage, or loss of consumer confidence.Private (Internal Personnel Only) – Information restricted in terms ofdisclosure though regulation or corporate policy.Damage Potential: Information that if improperly disclosed presents minorexposure to lawsuits, fines, criminal prosecutions, loss of competitiveadvantage, or loss of consumer confidence.Confidential (Specific Personnel Only) – This class includes information thatis designated explicitly as sensitive or identifiable through regulation, industrystandard or corporate policy.Damage Potential: Information that if improperly disclosed presents significantexposure to lawsuits, fines, criminal prosecutions, loss of competitiveadvantage, or loss of consumer confidence.58

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!