Data Classification Policy
Data Classification Policy
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 1 of 9
Synopsis:
The goal of this policy is to enhance the States ability to protect data
and information through data classification.
Authority:
Applicability:
Effective Date:
POC for Changes:
Approval By:
Approved On:
03/01/2006
Expiration Date:
None
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 2 of 9
TABLE OF CONTENTS
Section
Page
I.
Policy
II.
Definitions
III.
IV.
V.
Listing of Appendices
I.
Policy
EXECUTIVE SUMMARY
This policy requires Data Stewards to classify all of the data used by their
organization. It describes the roles and responsibilities of a Data Steward, the four
types of data classifications and the minimum set of classifications. Generally, it lays
the groundwork for the proper classification and handling of data used by the State.
Further insight into this policy may be obtained through your organizations IRM
(Information Resource Manager) or the DTI CRS (Customer Relationship Specialist)
assigned to your organization.
This policy does not limit or redefine FOIA (Freedom of Information Act) laws or
regulations. In case of any conflict, the law shall prevail.
PURPOSE
This policy provides instruction for State organizations to better handle, secure,
access, and use data. Sound business judgment and practices must be applied, and
the State must comply with applicable Federal, State and Local laws and regulations,
as well as any agency-specific guidelines then in effect. Examples of such are
Federal HIPAA and Gramm-Leach-Bliley (GLB), Federal Information Security
Management Act (FSMA), Privacy Act, PCI DSS, etc.1 This policy will be reviewed
HIPAA is the United States Health Insurance Portability and Accountability Act of 1996, PL 104-191.
The Financial Modernization Act of 1999, also known as the Gramm-Leach-Bliley Act or GLB Act
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 3 of 9
and revised periodically. However, the State is obligated to comply with new laws or
regulations coming into effect between revisions.
This policy is expected to be referenced by other State policies and standards that
will further define the implications of the data classification. As such, the actual data
classification designations will have far-reaching effects on various aspects of
Information Technology throughout the State.
The National Institute of Standards and Technology (NIST) has drafted a
comprehensive approach to data classification and the risks that are associated with
different levels of data classification. Specifically, it addresses the integrity and
availability of data as well as confidentiality, which is the focal point of this policy.
Over time, this policy will be influenced by NIST standards. The reading of the NIST
draft Guide for Mapping Types of Information and Information Systems to Security
Categories SP 800-60 is encouraged.
DATA OWNER and DATA STEWARD
For various reasons, including legal considerations, the States data is owned by the
State of Delaware. At a practical level, each State organization (agency, Governor,
Legislature, Judiciary and School District) generates or gathers data through various
means. The head of each State organization is the primary Data Steward for all data
controlled by the organization, but they may delegate the Data Steward role to
another employee in the organization with appropriate knowledge and authority to
carry out the responsibilities as defined in this policy. The CIO of the State of
Delaware is to be notified in writing of such delegation. Refer to the Enterprise
Standards and Policies and notably to the Delaware Information Security Policy for
further insight.
DATA CLASSIFICATIONS
The Data Steward is responsible for classifying all data under the organizations
control into one of the following classes.
State of Delaware Public Information available to the general public; eligible
for public access.
State of Delaware Confidential Information covered by one or more laws.
The disclosure of this information could endanger citizens, corporations,
business partners and others. The types of information might be covered
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 4 of 9
Classification
State of Delaware
Confidential
State of Delaware
Confidential
State of Delaware
Confidential
State of Delaware
Confidential
State of Delaware
Confidential
State of Delaware
Confidential
State of Delaware
Confidential
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 5 of 9
PRIMARY RESPONSIBILITIES
In addition to ensuring that data is properly classified, the Data Stewards primary
responsibility is to ensure that the data is appropriately protected. In this regard,
Data Stewards will be required by this and other policies or standards to perform
various tasks such as approving system and data access requests, communicating
data classification and appropriate use throughout the organization, approving data
exchange agreements, overseeing data usage, and participating in audits.
Each Data User is responsible to understand the classification of data to which they
have access, and to ensure that they comply with all policies, standards and
guidelines established to protect the data.
The statewide policies and standards pertaining to data protection can be found at
the DTI website. Local guidelines are established by the state organization itself. For
a complete list, please contact your organizations Information Resource Manager
(IRM).
SPECIFIC DUTIES
The Data Steward will:
1. Analyze all computerized data for appropriate data classification at regular
intervals as the data/databases are updated or changed. The Data Steward
maintains a working knowledge of the data under their care and aligns the
organizations data classification selections with it.
2. Ensure, in conjunction with the organizations Information Security Officer
(ISO), the implementation and enforcement of appropriate security control
procedures commensurate with the data classification.
3. Review and evaluate recommended protection requirements of computerized
data with respect to both integrity and confidentiality.
4. Authorize Data User access to computerized data. This process is coordinated
through the Information Security Officer (ISO) and the use of the Service
Manager Automated Security Request System.
5. Evaluate and approve requests for data transfers to or from another party.
The protocol mandates the Sending Data Steward (or equivalent if outside the
State) to clearly communicate to the Receiving Data Steward (or equivalent if
outside the State) the classification of the data to be transferred, and to
obtain a written or otherwise binding document whereby the Receiving Data
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 6 of 9
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 7 of 9
II.
Definitions
Sending Data Steward The Data Steward (or equivalent if outside the
State) of the source data being sent.
Receiving Data Steward The Data Steward (or equivalent if outside the
State) of the data being received.
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 8 of 9
STATE OF DELAWARE
DEPARTMENT OF TECHNOLOGY AND INFORMATION
III.
IN-DataClass-001
Revision Number:
Enterprise Policy
Page: 9 of 9
IV.
Date
V.
Other Documents
A Data Classification Guideline has been published and it is hereby noted. If there is
any conflict between the Data Classification Guideline and this policy, the policy shall
prevail. To obtain more information, please reference the Enterprise Standards and
Policies and notably the Delaware Information Security Policy for further insight.