Data classification
The big question is, should we encrypt all our data? Can we encrypt all our data? Should all data be encrypted using the same encryption methods?
This is where data classification comes into play and will also play a role when we start moving into AIP. Data classification can be defined as a process of organizing data by categories, therefore making it easier to be used and protected more efficiently.
While we are not going to cover this in depth in this book, we are going to see a high-level overview here.
We can separate all data in our organization into three different levels of sensitivity:
- Low sensitivity: Public websites, press releases
- Medium sensitivity: Emails and documents with no confidential data
- High sensitivity: Financial records, intellectual property
We might have information with low sensitivity that should be available to the public and, therefore, for them to be able to read the content directly, it should not be...