Data Classification Basics

Data Classification Basics

Label data correctly by sensitivity level.

What Is Data Classification Basics?

Classification decides which protections apply to which data, and the hard cases are never the obvious ones. This exercise puts you in a sorting workflow with items that resist easy labels: a press release that is Confidential until it is Public, newsletter addresses covered by privacy law, source code for an internal tool, salary data forwarded in a reply-all. For each level you will see what handling actually requires, covering storage, sharing, encryption and disposal.

What You'll Learn in Data Classification Basics

Data Classification Basics — Training Steps

  1. Welcome to Prism Analytics

    Today you'll complete the annual data classification training - a requirement for all employees who handle company information. Understanding how to classify data correctly is essential for protecting both the company and its clients.

  2. Why Classification Matters

    Not all data is created equal. A press release and a client's financial records require very different levels of protection. Data classification helps everyone in the organization understand: What data they're handling How sensitive it is What protections are required Who can access it Without proper classification, employees might accidentally share confidential information or waste resources over-protecting public data.

  3. Training Notification

    Alice receives an email from the Information Security team about the mandatory annual data classification training.

  4. Accessing the Security Portal

    Alice clicks the link to access the Security Training Portal. This centralized system contains all security training materials and compliance tracking.

  5. The Four Classification Levels

    The Security Training Portal displays the four data classification levels used at Prism Analytics: Public - Information intended for public release Internal - General business information for employees only Confidential - Sensitive business or client information Restricted - Highly sensitive data with strict controls Each level has specific handling requirements that increase with sensitivity.

  6. Public and Internal Data

    The first level is Public data - information explicitly approved for external release. Examples: Published press releases Marketing brochures and website content Public job postings Published annual reports Handling: No special protections required Can be shared freely with anyone Still requires approval before publishing The second level is Internal data - general business information meant for employees only. Examples: Internal policies and procedures Org charts and employee directories Meeting notes and project plans Internal announcements Handling: Share only with employees who need it Do not post publicly or share externally Use company email for distribution No special encryption required

  7. Confidential Data

    The third level is Confidential data - sensitive information that could harm the business or clients if disclosed. Examples: Client contracts and proposals Financial reports and forecasts Business strategies and plans Non-public product information Employee performance reviews Handling: Encrypt when sending externally Password-protect sensitive documents Verify recipient identity before sharing Use secure file sharing, not personal email Mark documents as 'Confidential'

  8. Restricted Data

    The highest level is Restricted data - highly sensitive information requiring the strictest controls. Examples: Personal identifiable information (PII): SSN, passport numbers Payment card data (PCI) Health records (PHI) Authentication credentials and encryption keys Trade secrets and intellectual property Handling: Always encrypted at rest and in transit Access limited to specific approved individuals Audit logging required for all access Immediate reporting of any unauthorized access Special disposal procedures required

  9. Classification Practice

    The portal presents a document for you to classify. Document: A spreadsheet containing the names, email addresses, and phone numbers of all employees in the marketing department. Think about: Who should have access to this? What would happen if it were leaked?

  10. Training Complete

    The portal confirms Alice has completed the data classification training. Her compliance record has been updated. The system displays a quick reference guide for the classification levels that Alice can access anytime.

Security Framework Coverage

CIS Controls

  • CIS 3 Data Protection
  • CIS 14.4 Train Workforce on Data Handling Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.DS Data Security