SlideShare a Scribd company logo
Work Smart by Microsoft IT
Classifying and Protecting Your
Business Information
Customization note: This document is based on the experience of Microsoft IT and contains
guidance and/or step-by-step instructions that can be reused, customized, or deleted entirely if
they do not apply to your organization’s environment or installation scenarios.
All forms of information, including ideas and concepts, have potential business value.
Whether you are exchanging emails, sharing documents, or having a phone conversation, it
is your responsibility to help protect your company’s confidential information. The greater
the information’s value, the more security controls you should put in place to protect it.
This guide provides an overview on how to properly classify business information and data
according to the potential impact of unintentional disclosure: High, Moderate, and Low
Business Impact. It also introduces some solutions that are available to help protect your
information before you transmit, share, store, or dispose of it.
Topics in this guide include:
Classifying your
information
Protecting your
information
Classification and
data dissemination
guidelines
Recommended
security practices
For more information
2 | Classifying and Protecting Your Business Information
Classifying your information
Information can be classified into three areas, according to the potential impact of its
unintentional disclosure: High Business Impact (HBI), Moderate Business Impact (MBI), and
Low Business Impact (LBI).
Table 1. Information classifications
HBI HBI applies to any information including emails, documents, messages and phone
conversations that, if disclosed without authorization, could result in immediate,
direct or considerable impact to the company, the information owner and
customers. HBI information should only be shared with those on a “need-to-know”
basis. HBI includes Highly Sensitive Personally Identifiable Information (HSPII).
MBI MBI applies to information that, if disclosed, could cause indirect, limited impact
the company, the asset’s owner and valued customers. MBI information should only
be accessible to those people who have a legitimate business need to view the
information. MBI includes Personally Identifiable Information (PII).
LBI LBI classification applies to information assets that, if disclosed without
authorization, could cause limited, or no material loss to the company, the asset
owner, or relying parties.
Important: The guidance provided in this document is for example purposes and every
organization is unique. In the following sections, please be aware that your company’s HBI, MBI,
and LBI information and data could require more or less restrictive classification levels.
Classification of some common information types
Below is table of guidelines that might be helpful in determining a type of data's
classification level.
Table 2. Guidelines to help determine data classification level
Data includes the following info: HBI MBI LBI
Email Address
X
Social Security Number
X
Documents regarding process or procedure
X
Private cryptographic keys
X
Username and Passwords
X
Publicly accessible information X
Company trade secrets
X
Financial information related to revenue
generation
X
List of Phone Numbers
X
Employee Zip Codes X
Numeric ID sequences / PINs
X
3 | Classifying and Protecting Your Business Information
Tips:
 Use the more restrictive classification if data falls into more than one classification level
or if you are unsure of its classification.
 Treat information as HBI if it does not have a classification, but is marked “confidential.”
Important Notes:
 It is your responsibility to understand the business value of your information and to apply
the correct classification and protection.
 Remove HBI or MBI information from your computer before retiring it or sending it offsite
for repairs.
 Remember to check your company policies as their classification levels may vary from the
examples provided in the table above.
Protecting your information
Now that you know how to classify your information, you will learn what tools are available
to ensure that your data is protected when it is sent, shared, stored, backed up, or deleted.
This guide provides an overview of four technologies that can be used to help protect
information.
 Information Rights Management. An Office feature of Rights Management Services
(RMS), IRM enables you to apply specific access permissions to documents, workbooks,
and presentations to prevent unauthorized forwarding, printing, or copying; and to set
expiration dates after which files no longer are available. More information about IRM is
available at http://technet.microsoft.com/en-us/library/cc179103.aspx.
 Secure/Multipurpose Internet Mail Extensions (S/MIME). With S/MIME you can
encrypt and/or digitally sign your email messages. Encrypting your messages converts
data with a cipher text so that only people who you specify can read it. Digitally signing
an email message helps ensure that no tampering occurs while your message and its
attachments are in transit. More information about S/MIME is included in the Message
Encryption and Filtering topic at http://technet.microsoft.com/en-
us/library/jj891023.aspx.
 BitLocker Drive Encryption. BitLocker Drive Encryption is a data protection feature
available in Windows Vista, Windows 7, and Windows 8. BitLocker encrypts the hard
drives on your computer to provide enhanced protection against data theft or exposure
on computers and removable drives that are lost, stolen, or decommissioned. More
information about BitLocker is available at http://technet.microsoft.com/en-
us/library/hh831713.aspx. BitLocker To Go provides drive encryption to prevent
unauthorized access on your portable storage drives. This includes the encryption of
USB flash drives, SD cards, external hard disk drives, and other removable drives
formatted by using the NTFS, FAT, or exFAT file systems.
4 | Classifying and Protecting Your Business Information
 Encrypted File System (EFS). If your computer is not BitLocker compatible, you can
use Encrypted File System (EFS) to encrypt specific files and folders by using a
certificate. EFS requires that users with whom you share information enter the
appropriate decryption key before they can access the encrypted content. More
information about EFS is available at http://windows.microsoft.com/en-
us/windows/what-is-encrypting-file-system#1TC=windows-7.
The following table provide some guidelines about which technology you should use to
protect the HBI or MBI information that you transmit, share, or store on your computer:
Table 3. Preferred technology used to transmit, share, and store business information
IRM S/MIME EFS BitLocker
Transmit with internal
email
Preferred Acceptable N/A N/A
Transmit with external
email
Works only with
other federated
RMS
organizations
Preferred N/A N/A
Share using SharePoint
Online
Preferred N/A N/A N/A
Storing on computer
Acceptable with
BitLocker
N/A Acceptable with
BitLocker
Required
Storing on removable
media
Acceptable N/A Acceptable Preferred
Notes:
 Information about applying Information Rights Management to a list or library is available at
http://office.microsoft.com/en-us/sharepoint-server-help/apply-information-rights-
management-to-a-list-or-library-HA010154148.aspx
 More information about Information Rights Management is available in “What’s New with
Information Rights Management in SharePoint and SharePoint Online?” at
http://blogs.office.com/2012/11/09/whats-new-with-information-rights-management-in-
sharepoint-and-sharepoint-online/
5 | Classifying and Protecting Your Business Information
Classification and data dissemination
guidelines
The following table provides some classification-level guidelines for sending, sharing,
storing, backing up, and disposing of business information.
Table 4. Guidelines for sending, sharing, storing, backing up, and disposing of business information
Action HBI MBI LBI
Send data (via file
transfer or email)
 Requires asset owner
approval to forward,
export, or copy.
 Requires encryption for
internal and external
delivery.
 Requires encryption with
S/MIME or IRM for email.
 Requires encryption for
transfer outside of
organization.
 Requires encryption with
S/MIME for email sent
outside the corporate
network.
No special
requirements.
Share
(via O365 SharePoint
Online)
 Use IRM to restrict
forwarding, copying, and
printing.
 Restrict permissions to
those identified by asset
owner.
 Requires formal
agreement, which legal
approves, for third
parties, such as business
partners.
 Restricts permissions to
those with legitimate
business needs only.
 Requires formal
agreement, which legal
approves, for third
parties, such as business
partners.
No special
requirements.
Store
(server, PC, CD, USB)
 Requires encryption
(BitLocker).
 Allows storage on
handheld devices only if
device supports strong
encryption and
authentication security
controls.
 May require encryption
(as determined by the
asset owner).
No special
requirements.
Back up
 Performed only by
authorized personnel and
stored only at a location
approved by IT Security.
 Encrypt storage media.
 Store in a physically
secure location in which
backups are logged and
access is controlled and
monitored.
No special
requirements.
Dispose of
 Cross-shred or incinerate
paper documents.
 Destroy tapes and other
magnetic media. Request
that hard disk drives be
destroyed.
 Follow your organization
policies for the
appropriate disposal of
retired hardware and
media.
 Cross-shred or
incinerate paper
documents.
 Destroy tapes and other
magnetic media.
 Remove data on hard
disks that you plan to
reuse or retire.
 Destroy inoperable hard
disk drives.
No special
requirements.
6 | Classifying and Protecting Your Business Information
Recommended security practices
Use the Microsoft Office System Document Inspector
If you plan to share an electronic copy of a Microsoft Office Word document with clients or
colleagues, it is a good idea to review the document for hidden data or personal
information that might be stored in the document itself or in the document properties
(metadata). Document Inspector is a built-in tool that can be used to scan your data before
sharing it with others.
For more information on how to use Document Inspector, see Remove hidden data and
personal information by inspecting documents at http://office.microsoft.com/en-us/word-
help/remove-hidden-data-and-personal-information-by-inspecting-documents-
HA010354329.aspx.
Guard confidential information
Do not discuss confidential information in public places.
Beware of multiple network connections
Never concurrently connect your computer to your corporate network and the Internet, or
any other network that your company does not manage. This compromises your company's
network security.
Review list of group recipients
Think globally before posting any content. Before you send or reply to email, post to
Yammer, One Drive, or any another social website, or post data to SharePoint, make sure
that the information is appropriate for disclosure to everyone who has access to the email
or website.
Use Outlook Web Access
Use Outlook Web Access (OWA) to check your email from your home computer. Be careful
if you access corporate resources by using kiosks and other public locations, even though
OWA, as key strokes may be monitored if the public network does not have the correct
configuration.
Do not leave documents or presentations unattended
Remove all documents after meetings, and erase whiteboards.
Beware of posting on walls or bulletin boards
If your document is HBI, do not post it in hallways or on bulletin boards.
7 | Classifying and Protecting Your Business Information
For more information
This guide provides foundational knowledge to help you make better decisions about
securing your data. Other guides are available to teach you how to help protect your
information. Visit the Modern IT Experience featuring IT Showcase at
http://microsoft.com/microsoft-IT and search for the following Work Smart titles:
 Securing your business information
 Secure collaboration using SharePoint Online
 Securing your computer
 Protecting data with Windows 8 BitLocker
The following content may be of interest to you as well:
 Introduction to IRM for email messages
http://office.microsoft.com/en-us/outlook-help/introduction-to-irm-for-email-
messages-HA102749366.aspx
 Video: Getting Started with Encrypting File System in Windows 7
http://technet.microsoft.com/en-us/windows/how-do-i-get-started-with-the-
encrypting-file-system-in-windows-7.aspx
 International Data Protection Standards
http://download.microsoft.com/download/B/8/2/B8282D75-433C-4B7E-B0A0-
FFA413E20060/international_privacy_standards.pdf
 Work Smart by Microsoft IT
http://aka.ms/customerworksmart
This guide is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR
STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. © 2014 Microsoft Corporation. All rights reserved.

More Related Content

PDF
Hadoop application architectures - using Customer 360 as an example
PDF
A Study in Borderless Over Perimeter
PPTX
Identity & Access Management - Securing Your Data in the 21st Century Enterprise
PPTX
Cloud Security
PPTX
Identity & access management
PPTX
Identity and access management
PDF
Azure Security Overview
PPTX
3 Modern Security - Secure identities to reach zero trust with AAD
Hadoop application architectures - using Customer 360 as an example
A Study in Borderless Over Perimeter
Identity & Access Management - Securing Your Data in the 21st Century Enterprise
Cloud Security
Identity & access management
Identity and access management
Azure Security Overview
3 Modern Security - Secure identities to reach zero trust with AAD

What's hot (20)

PPTX
An Introduction to HL7 FHIR
PPTX
Introduction to FHIR™
PDF
Threat Modeling Everything
PDF
Presentation v mware v-cloud director
PPTX
MS. Cybersecurity Reference Architecture
PPTX
EDR(End Point Detection And Response).pptx
PDF
Thoughtspot Pitch Deck
PPTX
An introduction to SOC (Security Operation Center)
PPTX
Identity and Access Management (IAM)
PDF
IBM InfoSphere Guardium overview
PDF
Top 10 Reasons to Learn Cybersecurity | Why Cybersecurity is Important | Edureka
PPTX
cloud-migrations.pptx
PPT
Data Protection Presentation
PPTX
DG_Architecture_Training.pptx
PDF
Road to NODES Workshop Series - Intro to Neo4j
PDF
PaloAlto Enterprise Security Solution
PDF
Microsoft Zero Trust
PPTX
5 Steps to a Zero Trust Network - From Theory to Practice
PPTX
Splunk Security Session - .conf Go Köln
PDF
Cybersecurity Roadmap Development for Executives
An Introduction to HL7 FHIR
Introduction to FHIR™
Threat Modeling Everything
Presentation v mware v-cloud director
MS. Cybersecurity Reference Architecture
EDR(End Point Detection And Response).pptx
Thoughtspot Pitch Deck
An introduction to SOC (Security Operation Center)
Identity and Access Management (IAM)
IBM InfoSphere Guardium overview
Top 10 Reasons to Learn Cybersecurity | Why Cybersecurity is Important | Edureka
cloud-migrations.pptx
Data Protection Presentation
DG_Architecture_Training.pptx
Road to NODES Workshop Series - Intro to Neo4j
PaloAlto Enterprise Security Solution
Microsoft Zero Trust
5 Steps to a Zero Trust Network - From Theory to Practice
Splunk Security Session - .conf Go Köln
Cybersecurity Roadmap Development for Executives
Ad

Viewers also liked (8)

PPTX
Walmart-Mattel: Supply Chanin Management Best Practices
PDF
BlogWell New York Social Media Case Study: Walmart, presented by Lisa Thurber
PPTX
IDENTIFICATION OF SOURCES OF INFORMATION, SEARCHING AND CLASSIFYING INFORMATION
PPTX
P& G case study analysis
PPTX
Mis case study - Procter & Gamble
PPTX
Operation Management for Walmart
PPTX
p&g marketing strategies
PPTX
Procter and gamble (P&G)
Walmart-Mattel: Supply Chanin Management Best Practices
BlogWell New York Social Media Case Study: Walmart, presented by Lisa Thurber
IDENTIFICATION OF SOURCES OF INFORMATION, SEARCHING AND CLASSIFYING INFORMATION
P& G case study analysis
Mis case study - Procter & Gamble
Operation Management for Walmart
p&g marketing strategies
Procter and gamble (P&G)
Ad

Similar to Classifying Data to Help Secure Business Information - Template fromMicrosoft (20)

DOCX
Securing Business-Information from Microsoft -Presented by Atidan
PDF
Data Lost Prevention (DLP).pdf
DOCX
The Financial Balance Sheet Part I This slidesh.docx
PDF
08. ICV sastanak (Microsoft) Nikola Šoškić OFFICE 2013
PDF
08. icv sastanak (microsoft) nikola office 2013
PDF
Is It Possible to Prevent Data Leaks in an Effective Manner.pdf
PDF
Fast & Secure Data Access Anytime, Anywhere
PDF
How Tally Addons Enhance Data Security and Privacy
PPT
Responsible for information
DOCX
Term assignment
PDF
Protecting Data Privacy Beyond the Trusted System of Record
PDF
Trusted information protection
PPTX
Top 5 Ways How Accounting Firms Can Protect Their Client Data
PDF
Share point encryption
PDF
Siem requirement.pdfsd
PDF
Can You Tell Me About Some Effective Ways to Prevent Data Leakage?
PPTX
Global Security and Compliance Community conference 2021
PDF
7 Practices To Safeguard Your Business From Security Breaches!
PDF
En msft-scrty-cntnt-e book-protectyourdata
PPTX
For CyberSecurity.pptx which helps students whose are want to learn
Securing Business-Information from Microsoft -Presented by Atidan
Data Lost Prevention (DLP).pdf
The Financial Balance Sheet Part I This slidesh.docx
08. ICV sastanak (Microsoft) Nikola Šoškić OFFICE 2013
08. icv sastanak (microsoft) nikola office 2013
Is It Possible to Prevent Data Leaks in an Effective Manner.pdf
Fast & Secure Data Access Anytime, Anywhere
How Tally Addons Enhance Data Security and Privacy
Responsible for information
Term assignment
Protecting Data Privacy Beyond the Trusted System of Record
Trusted information protection
Top 5 Ways How Accounting Firms Can Protect Their Client Data
Share point encryption
Siem requirement.pdfsd
Can You Tell Me About Some Effective Ways to Prevent Data Leakage?
Global Security and Compliance Community conference 2021
7 Practices To Safeguard Your Business From Security Breaches!
En msft-scrty-cntnt-e book-protectyourdata
For CyberSecurity.pptx which helps students whose are want to learn

More from David J Rosenthal (20)

PDF
Microsoft Teams Phone - Calling Made Simple
PDF
Whats New in Microsoft Teams Calling November 2021
PDF
Whats New in Microsoft Teams Hybrid Meetings November 2021
PDF
Viva Connections from Microsoft
PDF
Protect your hybrid workforce across the attack chain
PDF
Microsoft Viva Introduction
PDF
Microsoft Viva Learning
PDF
Microsoft Viva Topics
PDF
A Secure Journey to Cloud with Microsoft 365
PDF
Azure Arc Overview from Microsoft
PDF
Microsoft Windows Server 2022 Overview
PDF
Windows365 Hybrid Windows for a Hybrid World
PDF
Windows 11 for the Enterprise
PDF
Microsoft Scheduler for M365 - Personal Digital Assistant
PDF
What is New in Teams Meetings and Meeting Rooms July 2021
PDF
Modernize Java Apps on Microsoft Azure
PDF
Microsoft Defender and Azure Sentinel
PDF
Microsoft Azure Active Directory
PDF
Nintex Worflow Overview
PDF
Microsoft Power BI Overview
Microsoft Teams Phone - Calling Made Simple
Whats New in Microsoft Teams Calling November 2021
Whats New in Microsoft Teams Hybrid Meetings November 2021
Viva Connections from Microsoft
Protect your hybrid workforce across the attack chain
Microsoft Viva Introduction
Microsoft Viva Learning
Microsoft Viva Topics
A Secure Journey to Cloud with Microsoft 365
Azure Arc Overview from Microsoft
Microsoft Windows Server 2022 Overview
Windows365 Hybrid Windows for a Hybrid World
Windows 11 for the Enterprise
Microsoft Scheduler for M365 - Personal Digital Assistant
What is New in Teams Meetings and Meeting Rooms July 2021
Modernize Java Apps on Microsoft Azure
Microsoft Defender and Azure Sentinel
Microsoft Azure Active Directory
Nintex Worflow Overview
Microsoft Power BI Overview

Recently uploaded (20)

PDF
Approach and Philosophy of On baking technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Modernizing your data center with Dell and AMD
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Machine learning based COVID-19 study performance prediction
PDF
Encapsulation theory and applications.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPT
Teaching material agriculture food technology
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
cuic standard and advanced reporting.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
Approach and Philosophy of On baking technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Unlocking AI with Model Context Protocol (MCP)
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Empathic Computing: Creating Shared Understanding
Modernizing your data center with Dell and AMD
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Machine learning based COVID-19 study performance prediction
Encapsulation theory and applications.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Mobile App Security Testing_ A Comprehensive Guide.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Teaching material agriculture food technology
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
cuic standard and advanced reporting.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Digital-Transformation-Roadmap-for-Companies.pptx

Classifying Data to Help Secure Business Information - Template fromMicrosoft

  • 1. Work Smart by Microsoft IT Classifying and Protecting Your Business Information Customization note: This document is based on the experience of Microsoft IT and contains guidance and/or step-by-step instructions that can be reused, customized, or deleted entirely if they do not apply to your organization’s environment or installation scenarios. All forms of information, including ideas and concepts, have potential business value. Whether you are exchanging emails, sharing documents, or having a phone conversation, it is your responsibility to help protect your company’s confidential information. The greater the information’s value, the more security controls you should put in place to protect it. This guide provides an overview on how to properly classify business information and data according to the potential impact of unintentional disclosure: High, Moderate, and Low Business Impact. It also introduces some solutions that are available to help protect your information before you transmit, share, store, or dispose of it. Topics in this guide include: Classifying your information Protecting your information Classification and data dissemination guidelines Recommended security practices For more information
  • 2. 2 | Classifying and Protecting Your Business Information Classifying your information Information can be classified into three areas, according to the potential impact of its unintentional disclosure: High Business Impact (HBI), Moderate Business Impact (MBI), and Low Business Impact (LBI). Table 1. Information classifications HBI HBI applies to any information including emails, documents, messages and phone conversations that, if disclosed without authorization, could result in immediate, direct or considerable impact to the company, the information owner and customers. HBI information should only be shared with those on a “need-to-know” basis. HBI includes Highly Sensitive Personally Identifiable Information (HSPII). MBI MBI applies to information that, if disclosed, could cause indirect, limited impact the company, the asset’s owner and valued customers. MBI information should only be accessible to those people who have a legitimate business need to view the information. MBI includes Personally Identifiable Information (PII). LBI LBI classification applies to information assets that, if disclosed without authorization, could cause limited, or no material loss to the company, the asset owner, or relying parties. Important: The guidance provided in this document is for example purposes and every organization is unique. In the following sections, please be aware that your company’s HBI, MBI, and LBI information and data could require more or less restrictive classification levels. Classification of some common information types Below is table of guidelines that might be helpful in determining a type of data's classification level. Table 2. Guidelines to help determine data classification level Data includes the following info: HBI MBI LBI Email Address X Social Security Number X Documents regarding process or procedure X Private cryptographic keys X Username and Passwords X Publicly accessible information X Company trade secrets X Financial information related to revenue generation X List of Phone Numbers X Employee Zip Codes X Numeric ID sequences / PINs X
  • 3. 3 | Classifying and Protecting Your Business Information Tips:  Use the more restrictive classification if data falls into more than one classification level or if you are unsure of its classification.  Treat information as HBI if it does not have a classification, but is marked “confidential.” Important Notes:  It is your responsibility to understand the business value of your information and to apply the correct classification and protection.  Remove HBI or MBI information from your computer before retiring it or sending it offsite for repairs.  Remember to check your company policies as their classification levels may vary from the examples provided in the table above. Protecting your information Now that you know how to classify your information, you will learn what tools are available to ensure that your data is protected when it is sent, shared, stored, backed up, or deleted. This guide provides an overview of four technologies that can be used to help protect information.  Information Rights Management. An Office feature of Rights Management Services (RMS), IRM enables you to apply specific access permissions to documents, workbooks, and presentations to prevent unauthorized forwarding, printing, or copying; and to set expiration dates after which files no longer are available. More information about IRM is available at http://technet.microsoft.com/en-us/library/cc179103.aspx.  Secure/Multipurpose Internet Mail Extensions (S/MIME). With S/MIME you can encrypt and/or digitally sign your email messages. Encrypting your messages converts data with a cipher text so that only people who you specify can read it. Digitally signing an email message helps ensure that no tampering occurs while your message and its attachments are in transit. More information about S/MIME is included in the Message Encryption and Filtering topic at http://technet.microsoft.com/en- us/library/jj891023.aspx.  BitLocker Drive Encryption. BitLocker Drive Encryption is a data protection feature available in Windows Vista, Windows 7, and Windows 8. BitLocker encrypts the hard drives on your computer to provide enhanced protection against data theft or exposure on computers and removable drives that are lost, stolen, or decommissioned. More information about BitLocker is available at http://technet.microsoft.com/en- us/library/hh831713.aspx. BitLocker To Go provides drive encryption to prevent unauthorized access on your portable storage drives. This includes the encryption of USB flash drives, SD cards, external hard disk drives, and other removable drives formatted by using the NTFS, FAT, or exFAT file systems.
  • 4. 4 | Classifying and Protecting Your Business Information  Encrypted File System (EFS). If your computer is not BitLocker compatible, you can use Encrypted File System (EFS) to encrypt specific files and folders by using a certificate. EFS requires that users with whom you share information enter the appropriate decryption key before they can access the encrypted content. More information about EFS is available at http://windows.microsoft.com/en- us/windows/what-is-encrypting-file-system#1TC=windows-7. The following table provide some guidelines about which technology you should use to protect the HBI or MBI information that you transmit, share, or store on your computer: Table 3. Preferred technology used to transmit, share, and store business information IRM S/MIME EFS BitLocker Transmit with internal email Preferred Acceptable N/A N/A Transmit with external email Works only with other federated RMS organizations Preferred N/A N/A Share using SharePoint Online Preferred N/A N/A N/A Storing on computer Acceptable with BitLocker N/A Acceptable with BitLocker Required Storing on removable media Acceptable N/A Acceptable Preferred Notes:  Information about applying Information Rights Management to a list or library is available at http://office.microsoft.com/en-us/sharepoint-server-help/apply-information-rights- management-to-a-list-or-library-HA010154148.aspx  More information about Information Rights Management is available in “What’s New with Information Rights Management in SharePoint and SharePoint Online?” at http://blogs.office.com/2012/11/09/whats-new-with-information-rights-management-in- sharepoint-and-sharepoint-online/
  • 5. 5 | Classifying and Protecting Your Business Information Classification and data dissemination guidelines The following table provides some classification-level guidelines for sending, sharing, storing, backing up, and disposing of business information. Table 4. Guidelines for sending, sharing, storing, backing up, and disposing of business information Action HBI MBI LBI Send data (via file transfer or email)  Requires asset owner approval to forward, export, or copy.  Requires encryption for internal and external delivery.  Requires encryption with S/MIME or IRM for email.  Requires encryption for transfer outside of organization.  Requires encryption with S/MIME for email sent outside the corporate network. No special requirements. Share (via O365 SharePoint Online)  Use IRM to restrict forwarding, copying, and printing.  Restrict permissions to those identified by asset owner.  Requires formal agreement, which legal approves, for third parties, such as business partners.  Restricts permissions to those with legitimate business needs only.  Requires formal agreement, which legal approves, for third parties, such as business partners. No special requirements. Store (server, PC, CD, USB)  Requires encryption (BitLocker).  Allows storage on handheld devices only if device supports strong encryption and authentication security controls.  May require encryption (as determined by the asset owner). No special requirements. Back up  Performed only by authorized personnel and stored only at a location approved by IT Security.  Encrypt storage media.  Store in a physically secure location in which backups are logged and access is controlled and monitored. No special requirements. Dispose of  Cross-shred or incinerate paper documents.  Destroy tapes and other magnetic media. Request that hard disk drives be destroyed.  Follow your organization policies for the appropriate disposal of retired hardware and media.  Cross-shred or incinerate paper documents.  Destroy tapes and other magnetic media.  Remove data on hard disks that you plan to reuse or retire.  Destroy inoperable hard disk drives. No special requirements.
  • 6. 6 | Classifying and Protecting Your Business Information Recommended security practices Use the Microsoft Office System Document Inspector If you plan to share an electronic copy of a Microsoft Office Word document with clients or colleagues, it is a good idea to review the document for hidden data or personal information that might be stored in the document itself or in the document properties (metadata). Document Inspector is a built-in tool that can be used to scan your data before sharing it with others. For more information on how to use Document Inspector, see Remove hidden data and personal information by inspecting documents at http://office.microsoft.com/en-us/word- help/remove-hidden-data-and-personal-information-by-inspecting-documents- HA010354329.aspx. Guard confidential information Do not discuss confidential information in public places. Beware of multiple network connections Never concurrently connect your computer to your corporate network and the Internet, or any other network that your company does not manage. This compromises your company's network security. Review list of group recipients Think globally before posting any content. Before you send or reply to email, post to Yammer, One Drive, or any another social website, or post data to SharePoint, make sure that the information is appropriate for disclosure to everyone who has access to the email or website. Use Outlook Web Access Use Outlook Web Access (OWA) to check your email from your home computer. Be careful if you access corporate resources by using kiosks and other public locations, even though OWA, as key strokes may be monitored if the public network does not have the correct configuration. Do not leave documents or presentations unattended Remove all documents after meetings, and erase whiteboards. Beware of posting on walls or bulletin boards If your document is HBI, do not post it in hallways or on bulletin boards.
  • 7. 7 | Classifying and Protecting Your Business Information For more information This guide provides foundational knowledge to help you make better decisions about securing your data. Other guides are available to teach you how to help protect your information. Visit the Modern IT Experience featuring IT Showcase at http://microsoft.com/microsoft-IT and search for the following Work Smart titles:  Securing your business information  Secure collaboration using SharePoint Online  Securing your computer  Protecting data with Windows 8 BitLocker The following content may be of interest to you as well:  Introduction to IRM for email messages http://office.microsoft.com/en-us/outlook-help/introduction-to-irm-for-email- messages-HA102749366.aspx  Video: Getting Started with Encrypting File System in Windows 7 http://technet.microsoft.com/en-us/windows/how-do-i-get-started-with-the- encrypting-file-system-in-windows-7.aspx  International Data Protection Standards http://download.microsoft.com/download/B/8/2/B8282D75-433C-4B7E-B0A0- FFA413E20060/international_privacy_standards.pdf  Work Smart by Microsoft IT http://aka.ms/customerworksmart This guide is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. © 2014 Microsoft Corporation. All rights reserved.