Endorsed
12.
13.
(iii)
Promoting interoperability of standards by ensuring that data provided is
in a structured, commonly used and machine-readable format.
B.
Principle on Data Use and Access Control
The Principle on data use and access control promotes accountability in data
processing, which is a key component in data governance. This would include:
(i)
Using and/or processing data only for purposes that are reasonable and
appropriate; and which are not contrary to laws or national policies;
(ii)
Assigning different access controls and levels of authorisations to
personnel for access to different types or classifications of data; and
(iii)
Ensuring that access to data should be adequate, relevant, and
transparent.
C.
Principle on Data Security
The Principle on data security establishes the need to safeguard data, and any
storage centres the data sits within, as well as the systems and platforms that
handle the data. This would include:
(i)
Taking appropriate measures, including technical, procedural and
physical measures, to ensure that they protect the confidentiality,
integrity and availability of any data in their possession, or control against
risks such as loss or unauthorised access, use, modification, disclosure,
or destruction; and
(ii)
Addressing data breaches promptly and effectively, by containing the
breach and implementing mitigating measures to rectify the breach and
where relevant, in accordance with national policies on data breach
notifications.
Initiative under Strategic Priority 1: ASEAN Data Classification Framework
14.
Data governance principles on data life cycle and ecosystem may differ
depending on, among other things, the types of data. The level of protection
required and accorded under the Principles may apply the same approach and
considerations. For example, certain types of data (e.g. sensitive personal
data) require higher levels of protection, such as by having stricter access
controls or more stringent handling and disclosure requirements compared to
data that is publicly available.
15.
To afford data the necessary and adequate level of protection, it will be useful
to have a common data classification framework, which sets out broad
categories of data, descriptions of what each category entails and development
of security requirements for each data classification level.
4