课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Information classification

Information classification

- [Narrator] Organizations use data classification policies to help users understand the security requirements around handling different types of information. Data classification policies describe the security levels of information used in an organization and the process for assigning information to a particular classification level. The different security categories or classifications used by an organization determine the appropriate storage, handling and access requirements for classified information. Security classifications are assigned based upon both the sensitivity of the information and the criticality of that information to the enterprise. Classification schemes vary, but all basically try to group information into high, medium, and low sensitivity levels, and differentiate between public and private information. For example, the military uses the familiar Top secret, Secret, Confidential, and Unclassified scheme. A business, on the other hand, might use friendlier terms to…

内容