3.7: Establish and Maintain a Data Classification Scheme

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:


Info icon.

Control is new to this version of the control set.

Control Statement

Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise changes occur that could impact this Safeguard.

[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]