Talk to us today

Information Classification


1. Classification of Information

All n One information shall receive an appropriate level of protection in accordance with its importance to the organization and shall be classified accordingly. Employees, contractors, consultants, temporary and other workers, agents or representatives at All n One Ltd must classify information (typically emails) in accordance to their importance or sensitivity. The current classification levels are as follows:

 

1.1 High Risk/Highly Sensitive

Summary: Top confidentiality

Use/Description: Data should be classified as “High Risk” when the unauthorized disclosure, alteration or destruction of that data could cause a significant level of risk to the organisation or its affiliates. Examples of “High Risk” data include data protected by law, regulations and data protected by confidentiality agreements. The highest level of security controls should be applied to High Risk Data

 

1.2 Medium Risk

Summary: Medium confidentiality

Use/Description: Data should be classified as “Medium Risk” when the unauthorized disclosure, alteration or destruction of that data could result in a moderate level of risk to the organisation or its affiliates. By default, all company data that is not explicitly classified as high risk or public data should be treated as Medium risk/Sensitive/Private data

 

1.3 Low Risk/Public Data

Summary: Everyone can see this information

Use/Description: Data should be classified as “Low Risk”/Public data when the unauthorized disclosure, alteration or destruction of that data would result in little or no risk to the organisation and its affiliates. Examples of low risk data include press releases, course information and research publications. While little or no controls are required to protects the confidentiality of low risk data, some level of control is required to prevent unauthorized modification or destruction of low risk data

1.4 Email Classification on Emails

The following must be attached to one’s email signatures before sending:

High Risk:

Information Classification: Green ( ) Amber ( ) Red (X)
=
(Highly Sensitive)

 

Medium Risk:

Information Classification: Green ( ) Amber (X) Red ( )
=
(Sensitive)

 

Low Risk/Public:

Information Classification: Green (X) Amber ( ) Red ( )
=
(Public Data)