availability, it offers a high level of assurance that the data, objects, and resources are
accessible to authorized subjects. Availability includes efficient uninterrupted access to
objects and prevention of denial of service (DoS) attacks. Availability also implies that the
supporting infrastructure-including network services, communications, and access
control mechanisms-is functional and allows authorized users to gain authorized access.
For availability to be maintained on a system, controls must be in place to ensure
authorized access and an acceptable level of performance, to quickly handle
interruptions, to provide for redundancy, to maintain reliable backups, and to prevent
data loss or destruction.
Most security policies, as well as business continuity planning (BCP) , focus on the use of
fault tolerance features at the various levels of access/storage/security (i.e., disk, server,
site) with the goal of eliminating single points of failure to maintain availability of critical
systems. (Stewart et al., 2004)
6. Data Classification
Data classification, or categorization, is the primary means by which data is protected based on
its need for secrecy, sensitivity, or confidentiality. It is inefficient to treat all data the same way
when designing and implementing a security system because some data items need more
security than others. Securing everything at a low security level means
sensitive data is easily accessible. Securing everything at a high security level
is too expensive and restricts access to unclassified, noncritical data. Data
classification is used to determine how much effort, money, and resources
are allocated to protect the data and control access to it. Data classification,
or categorization, is the process of organizing items, objects, subjects, and
so on into groups, categories, or collections with similarities. These
similarities could include value, cost, sensitivity, risk, vulnerability, power, privilege, possible
levels of loss or damage, or need to know.
The primary objective of data classification schemes is to formalize and stratify the process of
securing data based on assigned labels of importance and sensitivity. Data classification is used
to provide security mechanisms for storing, processing, and transferring data. It also addresses
how data is removed from a system and destroyed.
The following are some benefits of using a data classification scheme:
It demonstrates an organization’s commitment to protecting valuable resources and
assets;
It assists in identifying those assets that are most critical or valuable to the organization;
It lends credence to the selection of protection mechanisms ;
It is often required for regulatory compliance or legal restrictions ;
It helps to define access levels, types of authorized uses, and parameters for
declassification and/or destruction of resources that are no longer valuable.
Lebanese National Security Policy Guidelines v1.7
Page
15 |