false
OasisLMS
Login
Catalog
Training Course 1
APPENDIX B
APPENDIX B
Back to course
Pdf Summary
This document defines Oakleaf’s four-level data classification scheme and the required controls for storing, transmitting, sharing, labeling, and disposing of information based on sensitivity. The classifications are: - <strong>Restricted</strong>: Highest sensitivity, typically driven by legal/contractual requirements (e.g., loan-file NPI/PII, certain contracts). Unauthorized disclosure could cause significant damage (regulatory violations, lawsuits, reputational harm, competitive impact). Strong controls apply: encryption for storage and transmission; strict access approval; no storage/transmission on mobile devices; no cloud storage; no IM or FTP (SFTP allowed); external transfer only via SFTP or encrypted email; printing, copying, faxing heavily restricted (faxing prohibited); certified/tamper-resistant mail; secure shredding/disposal; CEO/Managing Director approval and NDA required for third-party release; mandatory media/hardcopy labeling. - <strong>Confidential</strong>: Highly valuable internal information (e.g., employee PII/NPI, accounting, payroll, financials). Loss could cause moderate damage. Controls are similar to Restricted but slightly less strict: encryption required at rest and for external transmission; secure cloud storage allowed; mobile storage prohibited; IM/FTP prohibited; encrypted email required; printing permitted with senior management approval; owner approval for copying/scanning; NDA recommended for third parties; labeling required. - <strong>Private</strong> (default for most work-related information): Intended for internal/authorized sharing only; not for public release. Loss generally causes minimal/no damage. Encryption is recommended (including on mobile, with remote wipe if possible); no special internal transmission requirements; external encryption recommended; IM/FTP prohibited; shredding recommended; NDA recommended for third-party access; labeling required. - <strong>Public</strong>: Freely shareable with no expected damage if disclosed; minimal handling requirements (optional encryption for email). Release date and classification labeling may be required. General rules include defaulting to Private, classifying combined datasets by the most restrictive element, prohibiting format/media changes that reduce security controls, and allowing exceptions only with CEO and CISO approval. The appendix also defines NPI/PII elements and provides example data types mapped to classifications, noting that client engagement data may require client-specific controls.
Keywords
Oakleaf data classification
Restricted data controls
Confidential information handling
Private data default classification
Public data release
encryption at rest and in transit
SFTP and encrypted email transfer
access approval and NDA requirements
data labeling and disposal (secure shredding)
PII/NPI and legal contractual compliance
×
Please select your language
1
English