SlideShare a Scribd company logo
- Internal -
IS/DPP Baseline Training
E-learning – Part 3 – Data & Classification
2
- Internal - Page
Confidentiality
3
- Internal - Page
Confidentiality
4
- Internal - Page
Confidentiality
Website content, approved media releases, marketing materials, …Public
Website content, approved media releases, marketing materials, …
5
- Internal - Page
Confidentiality
Public
6
- Internal - Page
Confidentiality
Internal
Public
Departmental memos, information on bulletin boards, training
materials, policies, procedures, instructions, phone/email directories,…
7
- Internal - Page
Confidentiality
Website content, approved media releases, marketing materials, …
Restricted
Internal
Public
Personal data, customer correspondence, staff
data, internal audit reports, …
8
- Internal - Page
Confidentiality
Website content, approved media releases, marketing materials, …
Restricted
Internal
Public
Secret
Passwords and other
authentication credentials,
new products, mergers,…
9
- Internal - Page
10
- Internal - Page
Confidentiality
Integrity
11
- Internal - Page
Confidentiality
Integrity
Availability
12
- Internal - Page
Confidentiality
Availability
Privacy
Integrity
13
- Internal - Page
Control
Data
Subject
Processing personal data
Data
Controller
Finality Legitimacy
Transparency Organisation
Proportional
end-to-end
Data Protection Act / GDPR
14
- Internal - Page
Data
Subject
Processing personal data
Data
Controller
Data Protection Act / GDPR
1. What would your reaction be
if we did it to your personal data?
15
- Internal - Page
Data
Subject
Processing personal data
Data
Controller
Data Protection Act / GDPR
1. What would your reaction be
if we did it to your personal data?
2. What would the reaction be of
somebody who likes his privacy,
if we did it to his/her personal data?
16
- Internal - Page
Data
Subject
Processing personal data
Data
Controller
Data Protection Act / GDPR
1. What would your reaction be
if we did it to your personal data?
2. What would the reaction be of
somebody who likes his privacy,
if we did it to his/her personal data?
3. What would the reaction of
the public be if what we do to
personal data is in detail explained
on the front page of tomorrow’s
newspaper?
17
- Internal - Page
Data
Subject
Processing personal data
Data
Controller
Data Protection Act / GDPR
1. What would your reaction be
if we did it to your personal data?
2. What would the reaction be of
somebody who likes his privacy,
if we did it to his/her personal data?
3. What would the reaction of
the public be if what we do to
personal data is in detail explained
on the front page of tomorrow’s
newspaper?
18
- Internal - Page
Full Set of Data Classifications: PATRIC
Category Classifications
Privacy
Use the (personal) data in line with the original purpose
 (original) purpose
Availability
Ensure that information is available to authorized persons
 Non-Essential, Essential, Critical and Highly Critical
Traceability
Modifications can be traced back
 Non-Traceable, Sensitive and Critical
Retention
Retained & disposed in line with law & business objectives
 No Retention, Short-Term, Mid-Term and Long-Term
Integrity
Prevent accidental, unauthorized and deliberate alteration or
deletion
 Accurate, Vital and Absolute
Confidentiality
Prevent unauthorized disclosure
 Public, Internal, Restricted and Secret
Company specific
19
- Internal - Page
Full Set of Data Classifications: PATRIC
Category Classifications
Privacy
Use the (personal) data in line with the original purpose
 (original) purpose
Availability
Ensure that information is available to authorized persons
 Non-Essential, Essential, Critical and Highly Critical
Traceability
Modifications can be traced back
 Non-Traceable, Sensitive and Critical
Retention
Retained & disposed in line with law & business objectives
 No Retention, Short-Term, Mid-Term and Long-Term
Integrity
Prevent accidental, unauthorized and deliberate alteration or
deletion
 Accurate, Vital and Absolute
Confidentiality
Prevent unauthorized disclosure
 Public, Internal, Restricted and Secret
Company specific
20
- Internal - Page
Key Takeaways
 ABC Group classifies on different levels :
personal data and PATRIC.
 All information has a classification, even if it is
not explicit.
 You should classify.
 Confidentiality distinguishes different circles:
public, internal, restricted and secret, wherein
personal data is always at least “restricted”.
30 sec IS/DPP survival kit
WrapUp

More Related Content

PDF
Threat Modeling for Journalists
PPTX
Privacy Discusssion GM667 Saint Mary's University of MN
PPTX
How to Use Open Source Intelligence (OSINT) in Investigations
PDF
How to Write a Privacy Policy For Your Blog?
PPT
Investigating online conducting pre-interview research
PPTX
Transparency gdpr
PDF
2014-04-16 Protection of Personal Information Act Readiness Workshop
PPTX
IS/DPP for staff #3a - Data
Threat Modeling for Journalists
Privacy Discusssion GM667 Saint Mary's University of MN
How to Use Open Source Intelligence (OSINT) in Investigations
How to Write a Privacy Policy For Your Blog?
Investigating online conducting pre-interview research
Transparency gdpr
2014-04-16 Protection of Personal Information Act Readiness Workshop
IS/DPP for staff #3a - Data

Similar to IS/DPP for staff #3b - Data Classification (20)

PPT
Data privacy & social media
PPTX
Storm on the Horizon: Data Governance & Security vs. Employee Privacy
PPTX
IS/DPP for staff #1 - intro
PPTX
GDPR training
 
PDF
data privacy handbook: A starter guide to data privacy compliance
PDF
GDPR - Sink or Swim
PPTX
Privacy Secrets Your Systems May Be Telling
PPTX
Privacy Secrets Your Systems May Be Telling
PDF
data-privacy-egypt-what-you-need-know-en.pdf
PDF
Fundamentals of Privacy
PPTX
week 7.pptx
PDF
GDPR & SAP: practical data governance & management activities
PPTX
Training Procurement
PPT
Legal And Regulatory Dp Challenges For The Financial Services Sector
PPTX
Exploring Data Privacy - SQL Saturday Louisville 2011
PDF
Data Privacy: A runbook for engineers 1st Edition Nishant Bhajaria
PPT
This is a ppt about the privacy.i dont own any content.
PDF
Information Privacy?! (GDPR)
PPTX
LW GDPR and Cyber Security.pptx
PDF
TLabs - deutsche telekom
Data privacy & social media
Storm on the Horizon: Data Governance & Security vs. Employee Privacy
IS/DPP for staff #1 - intro
GDPR training
 
data privacy handbook: A starter guide to data privacy compliance
GDPR - Sink or Swim
Privacy Secrets Your Systems May Be Telling
Privacy Secrets Your Systems May Be Telling
data-privacy-egypt-what-you-need-know-en.pdf
Fundamentals of Privacy
week 7.pptx
GDPR & SAP: practical data governance & management activities
Training Procurement
Legal And Regulatory Dp Challenges For The Financial Services Sector
Exploring Data Privacy - SQL Saturday Louisville 2011
Data Privacy: A runbook for engineers 1st Edition Nishant Bhajaria
This is a ppt about the privacy.i dont own any content.
Information Privacy?! (GDPR)
LW GDPR and Cyber Security.pptx
TLabs - deutsche telekom
Ad

More from Tommy Vandepitte (20)

DOCX
DPIA template
DOCX
Gegevensbescherming-clausule in (overheids)opdracht
PPTX
20190131 - Presentation Q&A on legislation's influence (on travel management)
PPTX
GDPR toegepast op huur-verhuur (Dutch)
PPTX
Controller-to-processor agreements
PPTX
Gegevensbescherming makelaars
PPTX
EEAS - Cultivate your data protection
PPTX
Presentation for the LSEC GDPR event - 20171130
PPTX
Training privacy by design
PPTX
GDPR voor steden en gemeenten (Dutch)
PPTX
GDPR project board deck (example)
PPTX
IS/DPP for staff #8 - Monitoring
PPTX
IS/DPP for staff #7 - Incidents
PPTX
IS/DPP for staff #6 - Acceptable use
PPTX
IS/DPP for staff #5b - Passwords
PPTX
IS/DPP for staff #5a - Access
PPTX
IS/DPP for staff #2 - Why?
PPTX
Training Information Asset Owners
DOCX
Example general terms and conditions PenTest (NL)
DOCX
Beleid informatiebeveiligingsincidenten stad
DPIA template
Gegevensbescherming-clausule in (overheids)opdracht
20190131 - Presentation Q&A on legislation's influence (on travel management)
GDPR toegepast op huur-verhuur (Dutch)
Controller-to-processor agreements
Gegevensbescherming makelaars
EEAS - Cultivate your data protection
Presentation for the LSEC GDPR event - 20171130
Training privacy by design
GDPR voor steden en gemeenten (Dutch)
GDPR project board deck (example)
IS/DPP for staff #8 - Monitoring
IS/DPP for staff #7 - Incidents
IS/DPP for staff #6 - Acceptable use
IS/DPP for staff #5b - Passwords
IS/DPP for staff #5a - Access
IS/DPP for staff #2 - Why?
Training Information Asset Owners
Example general terms and conditions PenTest (NL)
Beleid informatiebeveiligingsincidenten stad
Ad

Recently uploaded (20)

PDF
01-Introduction-to-Information-Management.pdf
PDF
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
PPTX
Cell Types and Its function , kingdom of life
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PDF
Classroom Observation Tools for Teachers
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PDF
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PDF
102 student loan defaulters named and shamed – Is someone you know on the list?
PDF
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PDF
Chinmaya Tiranga quiz Grand Finale.pdf
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PPTX
GDM (1) (1).pptx small presentation for students
PPTX
Lesson notes of climatology university.
PPTX
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
PPTX
Final Presentation General Medicine 03-08-2024.pptx
PDF
VCE English Exam - Section C Student Revision Booklet
01-Introduction-to-Information-Management.pdf
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
Cell Types and Its function , kingdom of life
O5-L3 Freight Transport Ops (International) V1.pdf
Classroom Observation Tools for Teachers
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
STATICS OF THE RIGID BODIES Hibbelers.pdf
102 student loan defaulters named and shamed – Is someone you know on the list?
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
Pharmacology of Heart Failure /Pharmacotherapy of CHF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
Chinmaya Tiranga quiz Grand Finale.pdf
Supply Chain Operations Speaking Notes -ICLT Program
GDM (1) (1).pptx small presentation for students
Lesson notes of climatology university.
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
Final Presentation General Medicine 03-08-2024.pptx
VCE English Exam - Section C Student Revision Booklet

IS/DPP for staff #3b - Data Classification

  • 1. - Internal - IS/DPP Baseline Training E-learning – Part 3 – Data & Classification
  • 2. 2 - Internal - Page Confidentiality
  • 3. 3 - Internal - Page Confidentiality
  • 4. 4 - Internal - Page Confidentiality Website content, approved media releases, marketing materials, …Public Website content, approved media releases, marketing materials, …
  • 5. 5 - Internal - Page Confidentiality Public
  • 6. 6 - Internal - Page Confidentiality Internal Public Departmental memos, information on bulletin boards, training materials, policies, procedures, instructions, phone/email directories,…
  • 7. 7 - Internal - Page Confidentiality Website content, approved media releases, marketing materials, … Restricted Internal Public Personal data, customer correspondence, staff data, internal audit reports, …
  • 8. 8 - Internal - Page Confidentiality Website content, approved media releases, marketing materials, … Restricted Internal Public Secret Passwords and other authentication credentials, new products, mergers,…
  • 10. 10 - Internal - Page Confidentiality Integrity
  • 11. 11 - Internal - Page Confidentiality Integrity Availability
  • 12. 12 - Internal - Page Confidentiality Availability Privacy Integrity
  • 13. 13 - Internal - Page Control Data Subject Processing personal data Data Controller Finality Legitimacy Transparency Organisation Proportional end-to-end Data Protection Act / GDPR
  • 14. 14 - Internal - Page Data Subject Processing personal data Data Controller Data Protection Act / GDPR 1. What would your reaction be if we did it to your personal data?
  • 15. 15 - Internal - Page Data Subject Processing personal data Data Controller Data Protection Act / GDPR 1. What would your reaction be if we did it to your personal data? 2. What would the reaction be of somebody who likes his privacy, if we did it to his/her personal data?
  • 16. 16 - Internal - Page Data Subject Processing personal data Data Controller Data Protection Act / GDPR 1. What would your reaction be if we did it to your personal data? 2. What would the reaction be of somebody who likes his privacy, if we did it to his/her personal data? 3. What would the reaction of the public be if what we do to personal data is in detail explained on the front page of tomorrow’s newspaper?
  • 17. 17 - Internal - Page Data Subject Processing personal data Data Controller Data Protection Act / GDPR 1. What would your reaction be if we did it to your personal data? 2. What would the reaction be of somebody who likes his privacy, if we did it to his/her personal data? 3. What would the reaction of the public be if what we do to personal data is in detail explained on the front page of tomorrow’s newspaper?
  • 18. 18 - Internal - Page Full Set of Data Classifications: PATRIC Category Classifications Privacy Use the (personal) data in line with the original purpose  (original) purpose Availability Ensure that information is available to authorized persons  Non-Essential, Essential, Critical and Highly Critical Traceability Modifications can be traced back  Non-Traceable, Sensitive and Critical Retention Retained & disposed in line with law & business objectives  No Retention, Short-Term, Mid-Term and Long-Term Integrity Prevent accidental, unauthorized and deliberate alteration or deletion  Accurate, Vital and Absolute Confidentiality Prevent unauthorized disclosure  Public, Internal, Restricted and Secret Company specific
  • 19. 19 - Internal - Page Full Set of Data Classifications: PATRIC Category Classifications Privacy Use the (personal) data in line with the original purpose  (original) purpose Availability Ensure that information is available to authorized persons  Non-Essential, Essential, Critical and Highly Critical Traceability Modifications can be traced back  Non-Traceable, Sensitive and Critical Retention Retained & disposed in line with law & business objectives  No Retention, Short-Term, Mid-Term and Long-Term Integrity Prevent accidental, unauthorized and deliberate alteration or deletion  Accurate, Vital and Absolute Confidentiality Prevent unauthorized disclosure  Public, Internal, Restricted and Secret Company specific
  • 20. 20 - Internal - Page Key Takeaways  ABC Group classifies on different levels : personal data and PATRIC.  All information has a classification, even if it is not explicit.  You should classify.  Confidentiality distinguishes different circles: public, internal, restricted and secret, wherein personal data is always at least “restricted”. 30 sec IS/DPP survival kit WrapUp

Editor's Notes

  • #2: Welcome to the third part of the baseline training IS/DPP. Herein we look at data and the different classifications we give it in order to be able to better handle it.
  • #3: Like confidentiality, both entailing keeping unauthorized people out and requiring from authorized persons to handle the information confidentially. An example of a fail is the list of Amex cardholders and their spend being leaked on the internet via wikileaks or pastebin.
  • #4: The classification “confidentiality” takes into account the impact on the ABC Group in case of disclosure or breach. The author of the data should classify it. If you receives unclassified data, you should.
  • #5: The first level is “public”. It is information intended for public use. So it can be communicated outside the ABC Group.
  • #6: All non public data, is “confidential”. That is further divided into three “circles of trust”, which contain ever smaller numbers of people.
  • #7: Internal data is meant for staff only. It is information that is used to support and perform normal business operations. External staff may have access to it, but then they should be bound by a non-disclosure commitment.
  • #8: Restricted data is only to be made available on a specific need-to-know basis, which means that it must be job-related for you. Personal data in principle is restricted.
  • #9: Secret data is the highest level of confidentiality. It is sometimes also indicated as “strictly confidential” or “for your eyes only”. The author must have indicated you as an addressee otherwise you are not authorized to have it. It also means that a recipient has no margin to autonomously forward the information.
  • #10: Most information security frameworks refer to CIA. CIA does not stand for the US Central Intellegence Agency but for
  • #11: Confidentiality (which we already discussed) Integrity: which entail preventing accidental, unauthorized and deliberate alteration or deletion of data. An example of a fail is a customer succeeding in changing his card limit thus messing up our authorization process.
  • #12: and Availability: which goes to ensuring that information is available to authorized persons when required to fulfill their job. An example of a fail is the data being lost due to a short power fail and being unable to give a workable backup, e.g. losing and entire week of work.
  • #13: Due to the data protection legislation, we also add “privacy” to the “classifications”. That is respecting the (original) purpose for which the personal data was collected.
  • #14: Here we revert to the “finality” requirement under the data protection legislation, and the expectations of the data subject. The finality requirement indicates that during the entire lifecycle of the personal data the purpose must be respected.
  • #15: The expectations of the data subject, without going into detail of the technical legislation, can be captured in a quick 3 questions test. The first: What would your reaction be if we did it to your personal data?
  • #16: The second: What would the reaction be of somebody who likes his privacy, if we did it to his/her personal data?
  • #17: The third: What would the reaction of the public be if what we do to personal data is in detail explained on the front page of tomorrow’s newspaper?
  • #18: If on one of those three questions we have to answer : “Well, the reaction may be (seriously) negative.” We should likely reconsider. You can imagine that transparency at the moment of collection of the data is a very imporant element here.
  • #19: We complete the set of data classifications with two more, namely Traceability: that is ensuring that modifications can be traced back to the individual that made the modification (which we refer to as “non-repudiation”) to enable compliance with regulations and standards.
  • #20: and Retention: that is ensuring that information is retained and disposed in line with legal and regulatory requirements and business objectives