Choose Your Reading Style
A professional-level summary covering key definitions, frameworks, and exam-relevant points.
Data Classification Levels and Controls
| Level | Examples | Access Control | Handling Requirements |
|---|---|---|---|
| Public | Marketing materials, website content | Open access | No special handling required |
| Internal | Policies, org charts, meeting notes | All employees | Not for external distribution |
| Confidential | Financial data, business strategies | Need-to-know basis | Encryption; access logging |
| Restricted | PII, PHI, payment card data, trade secrets | Strictly limited | Encryption; DLP; audit trail; regulatory compliance |
CDMP Exam Relevance
Data classification is a key concept in the Data Security knowledge area (6% of the CDMP exam). Key exam topics include: the classification levels and their definitions, the relationship between classification and access control, the role of classification in regulatory compliance (GDPR, HIPAA, PCI DSS), and the process for implementing a data classification programme. Classification is also relevant to Data Governance (policies and standards) and Data Lifecycle Management (retention and disposal requirements vary by classification level).