false
OasisLMS
Login
Catalog
Training Course 1
APPENDIX B - Data Classification and Handling Guid ...
APPENDIX B - Data Classification and Handling Guidelines
Back to course
Pdf Summary
The guidelines establish four information classifications, with handling requirements increasing according to sensitivity: - <strong>Restricted:</strong> The most sensitive information, typically subject to legal or contractual requirements. Examples include client and employee PII/NPI, health information, financial account details, and certain contracts. Unauthorized disclosure could cause significant harm. Encryption is required for storage and transmission; storage on mobile devices or in cloud services is prohibited. Instant messaging, faxing, and ordinary FTP are prohibited. Printing requires business justification and senior-management approval, and third-party access requires executive approval and an NDA. - <strong>Confidential:</strong> Highly valuable, sensitive business information, including employee PII/NPI and accounting, payroll, and financial data. Disclosure could cause moderate harm. Encryption is required for fixed storage and external transmission and for email; mobile-device storage is prohibited. Secure cloud storage is permitted. Printing requires senior-management permission, and third-party release requires the information owner’s approval. - <strong>Private:</strong> Oakleaf-owned or entrusted information that may be shared with authorized parties who have a business need, but not released publicly. It is the default classification for information created or received at work. Encryption is generally recommended, and access controls are required. Instant messaging and FTP are prohibited. - <strong>Public:</strong> Information approved for unrestricted internal and external sharing; unauthorized disclosure poses no business risk. When information of different sensitivity levels is combined, the entire asset takes the highest classification. Restricted, Confidential, and Private information must not be released publicly. Information may be shared externally only when there is a business need and appropriate controls are in place; media or formats must provide equivalent security. PII/NPI generally means a person’s name or initials together with an identifier such as a government ID, driver’s license, financial account number, or protected health information. The document also specifies controls for labeling, printing, disposal, mailing, and access, varying by classification. Exceptions require CEO and CISO approval, and client-specific security requirements must be followed.
Keywords
Restricted
Confidential
Private
Public
information classification
PII
NPI
encryption requirements
access controls
data handling
×
Please select your language
1
English