Data Classification & Handling
- A data classification policy defines how information is categorized, handled, and shared by value, sensitivity, criticality, and regulatory requirement.
- Access to sensitive data is limited to authorized users through role-based, least-privilege controls.
- Public-facing systems are architected to prevent disclosure of nonpublic information, with review and approval before public release.
Framework Alignment: NIST CSF PR.DS, ID.AM; CIS Control 3; CMMC Level 1 (AC); GDPR Art. 5, 25; ISO 27001:2022 A.5.12, A.5.13