false
OasisLMS
Login
Catalog
Training Course 1
APPENDIX B - Data Classification and Handling Guid ...
APPENDIX B - Data Classification and Handling Guidelines
Back to course
Pdf Summary
The document is Oakleaf’s Data Classification and Handling Guidelines, which define a four-level information classification scheme: Public, Private, Confidential, and Restricted. Key points: - <strong>Restricted</strong> is the most sensitive category, usually governed by legal or contractual obligations. It includes items like PII/NPI, certain contracts, and other highly sensitive data. Unauthorized disclosure could cause significant damage. - <strong>Confidential</strong> covers highly sensitive internal business information such as employee PII/NPI, accounting, payroll, and financial data. Unauthorized disclosure could cause moderate damage. - <strong>Private</strong> is information owned by or entrusted to Oakleaf that should not be released publicly but may be shared with authorized parties when needed. Unauthorized disclosure would usually cause minimal or no damage. - <strong>Public</strong> information can be freely shared internally and externally with no expected harm from disclosure. General rules: - Information created or received by employees is <strong>Private by default</strong> unless classified higher or approved for public release. - When data of mixed sensitivity is combined, the <strong>most restrictive classification</strong> applies. - Restricted, Confidential, and Private data may be shared with third parties only when business need and proper controls exist. - Data should not be converted to a less secure format or medium without equivalent protections. - Exceptions require CEO and CISO approval. The document also defines <strong>NPI/PII</strong> as a person’s name combined with sensitive identifiers such as SSN/TIN/NIN, passport or resident card numbers, driver’s license numbers, financial account numbers, or ePHI. It provides detailed handling requirements for each classification, covering storage, transmission, email, printing, copying, faxing, mailing, disposal, labeling, and third-party access. In general, stricter classifications require encryption, limited access, secure transmission methods, labeling, and tighter controls; Public data has minimal restrictions. Finally, it lists examples of classified data across client, employee, sales/marketing, networking, and financial information.
Keywords
data classification
information handling
restricted data
confidential data
private data
public data
PII
NPI
encryption
third-party access
×
Please select your language
1
English