<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.officience.com/index.php?action=history&amp;feed=atom&amp;title=Information_Classification</id>
	<title>Information Classification - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.officience.com/index.php?action=history&amp;feed=atom&amp;title=Information_Classification"/>
	<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Information_Classification&amp;action=history"/>
	<updated>2026-08-10T06:35:52Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Information_Classification&amp;diff=1047&amp;oldid=prev</id>
		<title>Duykhang.nguyen: Created page with &quot;== Introduction == The purpose of this document is to support the classification of data to allow for the protection of Officience data, or data held by Officience, in terms o...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Information_Classification&amp;diff=1047&amp;oldid=prev"/>
		<updated>2019-10-28T16:17:42Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Introduction == The purpose of this document is to support the classification of data to allow for the protection of Officience data, or data held by Officience, in terms o...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Introduction ==&lt;br /&gt;
The purpose of this document is to support the classification of data to allow for the protection of Officience data, or data held by Officience, in terms of confidentiality, integrity, and availability&lt;br /&gt;
&lt;br /&gt;
== Scope ==&lt;br /&gt;
This policy covers all information held by and on behalf of Officience, whether digital or paper. The handling rules will apply to members of the company including staff and to the third parties processing or handling company information where the company holds information on behalf of another organization with its own information classification, the agreement will be reached as to which set of handling rules will apply.&lt;br /&gt;
&lt;br /&gt;
== Responsibilities ==&lt;br /&gt;
=== Members of Officience ===&lt;br /&gt;
All information owners are responsible for ensuring that this policy is adopted and that sensitive information they produce is appropriately protected and marked with the appropriate classification. &lt;br /&gt;
Officience members must respect the security classification of any information as defined, and must report any data loss or unauthorized disclosure, access or alteration of classified information to the ITS or to the Information Security Team as quickly as possible (with reference to the Information Security Incident Management Procedure. &lt;br /&gt;
&lt;br /&gt;
=== Information Security Team ===&lt;br /&gt;
Responsible for advising on and recommending information security standards on data classification.&lt;br /&gt;
&lt;br /&gt;
== Training and Awareness ==&lt;br /&gt;
Employees will be made aware of this policy through communications, training and awareness events. &lt;br /&gt;
&lt;br /&gt;
== Information Classification ==&lt;br /&gt;
# Information created and received by Officience should be classified according to the sensitivity of its contents. Classification and controls should take account of organization needs for sharing or restricting information, and the associated impacts and risks, e.g. unauthorized access or damage to the information.&lt;br /&gt;
# Collections of diverse information should be classified as to the most secure classification level of an individual information component with aggregated information.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Data Classification !! Description !! Example Data Types&lt;br /&gt;
|-&lt;br /&gt;
!&amp;#039;&amp;#039;&amp;#039;Confidential&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|A subset of information handled by Officience where the inappropriate use of the information could have damaging consequences for Officience, for an individual (or group of individuals), or other organizations.&lt;br /&gt;
Consequences if the information is mishandled: Unauthorized disclosure likely to result in significant adverse impact, embarrassment or penalties to Officience, its stakeholders, employees, or members of the public.&lt;br /&gt;
|&lt;br /&gt;
* Business contract&lt;br /&gt;
* Customer-related documents&lt;br /&gt;
* Customer information&lt;br /&gt;
* Employee medical record&lt;br /&gt;
* Specified by customers&lt;br /&gt;
* Network infrastructure&lt;br /&gt;
* System configurations (servers, routers, switches, etc.)&lt;br /&gt;
* System accounts credentials&lt;br /&gt;
* Information that could be used to compromise the security of Officience information such as internal IP addresses, details of security measures and versions of security products&lt;br /&gt;
* Commercial or market -sensitive information such as details of potential supplier bids prior to contract award, pricing schedules, customer details, details of unique aspects of a business model, tender information for unsuccessful bidders&lt;br /&gt;
* Personally Identifiable Information&lt;br /&gt;
* Financial information&lt;br /&gt;
* Risk registers&lt;br /&gt;
* Major security or business continuity issues;&lt;br /&gt;
|-&lt;br /&gt;
!&amp;#039;&amp;#039;&amp;#039;Internal&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|This information applies to less sensitive business information which is intended for use within Officience and shall not be distributed outside of Officience. Its unauthorized disclosure could adversely impact Officience, its employees, and/or its customers but the impact would not be devastating. Information, which is considered to be private to the organization, is included in this classification&lt;br /&gt;
|&lt;br /&gt;
* Project documents&lt;br /&gt;
* Internal policies and procedures&lt;br /&gt;
* Operational information, e.g. relating to organizational change planning, contentious negotiations&lt;br /&gt;
|-&lt;br /&gt;
!&amp;#039;&amp;#039;&amp;#039;Public&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|This classification applies to information which has been explicitly approved by Officience management for release to the public. By definition, there is no such thing as unauthorized disclosure of this information and it may be viewed by anyone, anywhere inside/outside Officience without potential harm.&lt;br /&gt;
|&lt;br /&gt;
* Non person-identifiable information&lt;br /&gt;
* Marketing materials (ie Offy handbook, service brochure…)&lt;br /&gt;
* advertisement &lt;br /&gt;
* Job opening&lt;br /&gt;
* Announcement &lt;br /&gt;
* Press releases&lt;br /&gt;
|}&lt;br /&gt;
== Data Handling Guideline ==&lt;br /&gt;
=== Data storage ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Location&lt;br /&gt;
!Confidential&lt;br /&gt;
!Internal&lt;br /&gt;
!Public&lt;br /&gt;
|-&lt;br /&gt;
|Officience owned PC storage (for individual use)&lt;br /&gt;
|Following password policy&lt;br /&gt;
Lock screen when unattended&lt;br /&gt;
Must be part of a standard backup policy&lt;br /&gt;
|Following password policy&lt;br /&gt;
Lock screen when unattended&lt;br /&gt;
Must be part of a standard backup policy&lt;br /&gt;
|No special measures&lt;br /&gt;
|-&lt;br /&gt;
|Shared hard drive - Officience PC storage&lt;br /&gt;
|Permitted. &lt;br /&gt;
Must set the permissions for authorized users&lt;br /&gt;
|Permitted&lt;br /&gt;
|Not permitted&lt;br /&gt;
|-&lt;br /&gt;
|Officience owned PC for public use (ie meeting room)&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;High risk of an incidental disclosure&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Log out and shut down the PC&lt;br /&gt;
Apply clean screen and trash bin policy&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;High risk of an incidental disclosure&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Log out and shut down the PC&lt;br /&gt;
Apply clean screen policy&lt;br /&gt;
|No special measures&lt;br /&gt;
|-&lt;br /&gt;
|Personally owned (ie Laptop)&lt;br /&gt;
|Must follow BYOD policy&lt;br /&gt;
|Must follow BYOD policy&lt;br /&gt;
|No special measures&lt;br /&gt;
|-&lt;br /&gt;
|Personally owned Smartphone or tablet&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Not permitted.&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
Maybe used for read-only if the file stored in Cloud&lt;br /&gt;
Device to be protected by strong password, with a maximum of 10 minutes inactivity until device locks.&lt;br /&gt;
|No creation/ editing/ storage of classified material permitted on device&lt;br /&gt;
Maybe used for read-only if the file stored in Cloud&lt;br /&gt;
Device to be protected by strong password, with a maximum of 10 minutes inactivity until device locks.&lt;br /&gt;
|May be used for remote connection to access files&lt;br /&gt;
Creation/ editing/ storage is permitted&lt;br /&gt;
|-&lt;br /&gt;
|Small capacity portable storage devices (e.g. USB, CD,)&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Avoid use where possible&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Consider alternative means of transfer/ access instead ie use shared drive.&lt;br /&gt;
|Use the encrypted USB drive&lt;br /&gt;
Not suitable for long-term storage&lt;br /&gt;
Keep in lockable cabinet/drawer which is locked when unattended&lt;br /&gt;
|Not suitable for long-term storage&lt;br /&gt;
|-&lt;br /&gt;
|Large capacity portable storage devices (i.e. external hard drive)&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Avoid use where possible&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Permitted in limited circumstances only. &lt;br /&gt;
The device must be encrypted. Contact ITS for the encryption.&lt;br /&gt;
|Permitted in limited circumstances only. &lt;br /&gt;
The device must be encrypted. Contact ITS for the encryption.&lt;br /&gt;
|If these are required, contact IT Support&lt;br /&gt;
|-&lt;br /&gt;
|‘Cloud’ storage (ie GDrive)&lt;br /&gt;
|If restricted to authorized recipients&lt;br /&gt;
|If restricted to Officience&lt;br /&gt;
|Could be shared public&lt;br /&gt;
|-&lt;br /&gt;
|Sending from Company hosted email account to another internal email account&lt;br /&gt;
|Marked confidential and double check recipient&lt;br /&gt;
Only share to individual who need to know&lt;br /&gt;
Enable undo send for account&lt;br /&gt;
Avoid auto forwarding to another email account&lt;br /&gt;
|Double check recipient&lt;br /&gt;
Enable undo send for account&lt;br /&gt;
Avoid auto forwarding to another email account&lt;br /&gt;
|Permitted&lt;br /&gt;
|-&lt;br /&gt;
|Sending from Company hosted email account to an external account&lt;br /&gt;
|Only for the individuals that are the owners or the customer of the information &lt;br /&gt;
|Only for limited circumstances if the recipient does not have a Officience email account and for a business purpose&lt;br /&gt;
Only share to individual who need to know&lt;br /&gt;
Double check recipient&lt;br /&gt;
Use password to protect the data. Send password separately or use the password has been discussed before.&lt;br /&gt;
Enable undo send for account&lt;br /&gt;
Avoid auto forwarding to another email account&lt;br /&gt;
|Permitted&lt;br /&gt;
|-&lt;br /&gt;
|Sending from an externally provided personal email account (e.g. Hotmail, Gmail etc)&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|Not permitted unless sending to the company email account&lt;br /&gt;
|-&lt;br /&gt;
|Paper copies&lt;br /&gt;
|Consider: Protection from fire and flood damage&lt;br /&gt;
In restricted access (working area):&lt;br /&gt;
In lockable cabinet/drawer which is locked when not in active use. &lt;br /&gt;
No papers left out unless being actively worked on.&lt;br /&gt;
Segregate from routine files&lt;br /&gt;
In unrestricted access: &amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Alternative: create/convert to the electronic document&lt;br /&gt;
Off-site working: &amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|Consider: Protection from fire and flood damage&lt;br /&gt;
In restricted access (working area)&lt;br /&gt;
Requirement:&lt;br /&gt;
In lockable cabinet/drawer which is locked when not in active use. &lt;br /&gt;
No papers left out unless being actively worked on.&lt;br /&gt;
In unrestricted access:&lt;br /&gt;
In lockable cabinet/drawer which is locked when not in active use. &lt;br /&gt;
No papers left out unless being actively worked on.&lt;br /&gt;
Off-site working: &amp;#039;&amp;#039;&amp;#039;Not permitted&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|No special measures&lt;br /&gt;
|-&lt;br /&gt;
|Printing/scanning/ photocopying&lt;br /&gt;
|Proactively protect against accidental compromise, for example don’t leave in copiers, check all pages retrieved.&lt;br /&gt;
|Proactively protect against accidental compromise, for example don’t leave in copiers, check all pages retrieved.&lt;br /&gt;
|No special measures&lt;br /&gt;
|-&lt;br /&gt;
|Telephone conversation&lt;br /&gt;
|Requirement:&lt;br /&gt;
Ensure conversations cannot be overheard.&lt;br /&gt;
Manage calls to ensure only authorized individual present.&lt;br /&gt;
|Requirement:&lt;br /&gt;
Ensure conversations cannot be overheard.&lt;br /&gt;
Manage calls to ensure only authorized individual present.&lt;br /&gt;
|No special measures&lt;br /&gt;
|}&lt;br /&gt;
=== Data retention and disposal ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Data Classification&lt;br /&gt;
!Physical&lt;br /&gt;
!Digital&lt;br /&gt;
|-&lt;br /&gt;
!Confidential&lt;br /&gt;
|Physical media exceeded the retention period should be shredded (for paper) or destroyed (CD, tape, etc.) so that data on the media cannot be recovered or reconstructed.&lt;br /&gt;
|Data reach the retention period shall be deleted and unrecoverable (e.g. eraser, zero-fill, etc.). Ask IT Support to secure delete if you don’t make sure the data is totally wiped.&lt;br /&gt;
|-&lt;br /&gt;
!Internal&lt;br /&gt;
|Physical media exceeded the retention period should be shredded (for paper) or destroyed (CD, tape, etc.) so that data on the media cannot be recovered or reconstructed.&lt;br /&gt;
|Data reach the retention period shall be deleted and unrecoverable (e.g. eraser, zero-fill, etc.). &lt;br /&gt;
|-&lt;br /&gt;
!Public&lt;br /&gt;
|No protection requirements. Recycle where possible &lt;br /&gt;
|No protection requirements. Recycle where possible &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Duykhang.nguyen</name></author>
	</entry>
</feed>