During a security assessment, a company discovers that its documents are automatically labeled Public, Internal, Confidential, or Highly Confidential. Each label triggers different controls such as open access, stricter ACLs, or mandatory encryption. Which data-governance practice is the company using to protect information according to its sensitivity?
Assigning labels such as Public, Internal, and Confidential is an example of data classification. In a classification scheme, information is sorted into predefined sensitivity levels so that matching security controls (encryption, access restrictions, monitoring, etc.) can be applied. Data masking (obfuscation) hides or substitutes the actual values, data retention governs how long information is kept, and data replication simply creates extra copies for availability-none of these involve categorizing data by sensitivity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the primary sensitivity levels used in data classification?
Open an interactive chat with Bash
How does data classification improve security?
Open an interactive chat with Bash
How is data classification different from data obfuscation?