Why Data Classification Should Drive Your Security Strategy

There are two types of businesses in the world today: those that run on data and those that will run on data. Data security now sits at the top of nearly every organization‘s priority list. But with such a high volume of data coming into most businesses every day, how can information security professionals quickly identify which data is the highest priority for protection? After all, security costs time and money, and not all types of data are as sensitive or vulnerable as others. It is for this very reason that data discovery and classification techniques are making a significant resurgence. In fact, global analyst houses such as Forrester and Gartner have emphasized that a renewed focus on data classification is now foundational to establishing an effective data security strategy. Data classification is a process of consistently categorizing data based on specific and pre-defined criteria so that it can be efficiently and effectively protected. In addition to simplifying security strategies, data classification can greatly assist companies in meeting governance, compliance or regulation mandates such as PCI DSS and GDPR, as well as protecting important intellectual property. Here are some of the most common misperceptions around data classification: It’s easier to manage the data deluge with classification. Considering how fast volumes of new data are accelerating, an InfoSec professional responsible for protecting an organization’s digital assets must take a new approach to stay ahead of the challenge. Classification enables them to avoid the inefficiency of taking a “one size fits all” approach, or the risk of arbitrarily choosing what data to expend resources protecting. Every business has different data classification needs to address, so a strategy must be tailored accordingly. The following five-point action plan can be used to create the foundation of an effective strategy for nearly any business. What are the goals, objectives and strategic intent? Each organization must clearly communicate how classification can support increased revenue, trim costs and reduce risk to achieve buy-in from the executive leadership team. Once this has been accomplished, it is equally important to make sure users are aware of data classification policies and to ensure they understand why a program is being put in place. An effective policy must also balance the confidentiality and privacy of employees and users against the integrity and availability of the data being protected. A policy that is too stringent can alienate staff and impede their ability to carry out their jobs, but if it’s too lax, the very data the business is trying to protect could be put at risk. It is important to establish where the boundaries will be early on; otherwise, data classification efforts can quickly grow out of control. This is particularly important when considering partners and third parties. In setting up a scope for their data classification program, organizations must consider how far into their network they aim to reach, and whether it is even feasible. It is equally important to consider legacy and archived data. Where is this data and how will it be protected? Finally, make sure to note anything that’s out of scope and ensure this is evaluated and adjusted regularly.


