The criteria by which data is classified vary based on the organization performing the
classification. However, you can glean numerous generalities from common or standardized
classification systems:
Usefulness of the data;
Timeliness of the data;
Value or cost of the data;
Maturity or age of the data;
Lifetime of the data (or when it expires);
Association with personnel;
Data disclosure damage assessment (that is, how the disclosure of the data would affect
the organization);
Data modification damage assessment (that is, how the modification of the data would
affect the organization);
National security implications of the data;
Authorized access to the data (that is, who has access to the data);
Restriction from the data (that is, who is restricted from the data);
Maintenance and monitoring of the data (that is, who should maintain and monitor the
data);
Storage of the data.
Using whatever criteria is appropriate for the organization, data is evaluated, and an
appropriate data classification label is assigned to it. (Stewart et al., 2004)
Lebanese National Security Policy Guidelines v1.7
Page
16 |