The data classification process encompasses steps to identify, categorize, and manage data. Through classification, organizations can ensure that sensitive information is adequately protected and managed, improving compliance and security.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
A data classification process assigns data to protection, confidentiality, or usage categories and derives appropriate handling rules.
The approach grew from information security, privacy, and records management. Standards and guides such as NIST SP 1800-39 turned manual labelling into a repeatable process for discovering, assessing, and marking sensitive data.
Each datum gets a label such as public, internal, or confidential. The label governs access, storage, sharing, and deletion; regular checks correct misclassification.
A level describing a datum's confidentiality, integrity, or protection need.
A human- or machine-readable assignment to a protection class.
A rule for access, storage, sharing, or deletion.
The process makes protection scalable and auditable. It fails when classes are unclear, owners are missing, or labels do not drive technical access controls.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.