Data classification and identification

Updated at:
Copy as MD

Classify and grade your data assets to meet compliance requirements, enable graded protection, and strengthen internal data security controls.

Data classification and grading form the foundation of graded data protection. As a long-term technical and management effort, establishing classification policies, templates, and rules helps organize data assets and provides better solutions for compliance and internal security control.

Laws in the Chinese mainland require a data classification and grading system. Each region and department must follow this system to identify important data within its jurisdiction, industry, or field and apply special protection accordingly.

Relevant laws and regulations include:

  • Data Security Law

  • Personal Information Protection Law

  • Network Security Law

Industry-specific guidelines include:

  • Financial institutions: JR/T 0197-2020 Data Security Classification and Grading of Financial Data

  • Securities and futures industry: JR/T 0158-2018 Data Classification and Grading in the Securities and Futures Industry

  • Telecommunications and carrier industry: YD/T 3813-2020 Data Classification and Grading Methods for Basic Telecommunication Enterprises

  • Financial personal information: JR/T 0171-2020 Technical Specifications for Personal Financial Information Protection

Methods for defining data classification

You can define data classification through the following approaches:

  • Define classification based on existing frameworks in your industry.

  • Apply industry classification and grading standards, fine-tuned for your specific business needs in finance, securities, or telecommunications.

  • Build a custom classification framework based on a data resource directory, with categories such as customer, company, and business data.

  • Establish grading standards with professional data consultants to ensure alignment with business data and legal requirements.

  • Develop an enterprise framework for data classification and grading through research with data consultants.

  • This requires analyzing the organization's structure, business data, and relevant national, industry, and regional regulations with professional consultants.

  • Coordinate with business, legal, and IT departments to create the classification framework and grading standards.

Data identification in a cloud environment

Regulations require data to be classified as personal data or important data. Personal data is further divided into sensitive and non-sensitive categories.

  1. Sensitive personal data: defined in GB/T 35273-2020 Personal Information Security Specification.

  2. Non-sensitive personal data: also defined in GB/T 35273-2020 Personal Information Security Specification.

  3. Important data: defined by each business based on its operational, business, and employee data.

In a cloud environment, data is stored across OSS, RDS, ECS cloud disks, and big data platforms. Identification is difficult because data is scattered, varies in format, and lacks uniform classification standards.

Follow these steps to identify and classify data in your cloud environment:

  1. Map your data storage methods and paths. Consolidate storage paths where possible.

  2. Prioritize personal and sensitive personal information. These have standard definitions, and data security regulations focus heavily on personal information.

  3. Define what constitutes important data for your business and create identification templates.

  4. Automate identification by creating classification templates, scanning tools, and reports.

Graded protection measures

Graded protection measures help build appropriate data security capabilities. Data security protection must evolve continuously. A graded framework lets you flexibly adjust security controls based on your data protection requirements.

Information is typically divided into three types:

  • Customer information (C): names, phone numbers, hobbies, and addresses.

  • Business information (S): product designs, materials, supply chain, packaging, pricing strategies, SKU planning, and promotions.

  • Company information (B): orders, HR data, revenue, and accounts receivable.

Information protection has four levels:

L1

L2

L3

L4

Public

Internal

Confidential

Secret

Public

Internal

Confidential

Secret

The following table shows recommended data grades by combining information type with protection level.

Information type

Level

Public information (L1)

Internal information (L2)

Confidential information (L3)

Secret information (L4)

Customer information (C)

Public customer information (C1)

Shareable customer information (C2)

Private customer information (C3)

Secret customer information (C4)

Business information (S)

Public business information (S1)

Internal business information (S2)

Confidential business information (S3)

Secret business information (S4)

Company information (B)

Public company information (B1)

Internal company information (B2)

Confidential company information (B3)

Secret company information (B4)

The following table lists protection measures for each level:

Data security level

L1

L2

L3

L4

Description

Public

Internal

Confidential

Secret

Graded control measures

• Basic access control

• Plaintext display

• Encrypted access channel

• Access control

• Data download permissions

• Data download and distribution

• Data encryption

• Encrypted access channel

• Encrypted data storage

• Strict access control approval flows

• Data download permission control

• Data exfiltration audit and monitoring

• Endpoint protection and trust

• Security detection

• Encrypted privileged access channel

• Encrypted data storage

• Special permission approval

• VDI-based viewing

• Download prohibited

• Endpoint protection and trust

Data security protection is systematic and evolves with business needs and customer attributes. When creating a graded protection framework, consider the impact on your business. Building data security capabilities requires ongoing design, planning, and implementation based on actual conditions.