it:ad:continuous_delivery:sad:appendices:data_classification:home

IT:AD:Continuous Delivery:SAD:Appendices:Data Classification

Summary

Organisations are not put at risk by Environments, but by the Data used within the Environments.

Ensuring that Production Classified data is removed from environments reduces the organisation's risk.

ApplicationLogicDataOnly a potential risk(to be measured)if the logic containsproprietary IP.Only a potential risk(to be ascertained)if the data issourced fromPROD data instead ofgenerated asneeded for testingdemos and trainingpurposes.

Under no circumstances will cleartext, obfuscated or encrypted copies – whole or subsets – of production data be used in any environment.

Installations that manage production data are classified by the type of data they manage.

Classifications is only applicable to Installations of the system that manage real data.

The highest Data Classification given to the information managed by a solution defines both non-functional requirements and system function requirements that must be met at various stages of the Application Lifecycle, including definition, development, operation and disposal phase.

Data Classification Rating

Data is either Unclassified, or classified as either Policy and Privacy Information or National Security Information1)2):

The rating specified depends on several factors.

Unclassified

UnclassifiedNo reason existsto apply aparticularclassification. For unrestrictedaccess, includingwithout authentication.

Classified

Classified data is of one of two types:

ClassifiedPolicy and Privacy InformationNational Security

Classified as Policy and Privacy Information

The security classifications for material that should be protected because of public interest or personal privacy are:

Policy and Privacy InformationIn ConfidenceCompromise would prejudicethe maintenance of law and orderimpede the effective conductof governmentadversely affect theprivacy of its citizens. Includes *personal* informationas defined by the Privacy Actto be protected fromunauthorised access and/ordisclosure.SensitiveCompromise woulddamage theinterests of New Zealandendanger thesafety of its citizens. Compromise woulddamage national interestsin a significant manner. Includes large collectionsof "In Confidence" records.

Classified as National Security Information

The security classifications for material that should be protected because of national security are:

National SecurityRestrictedConfidentialSecretCompromise would damagenational interestsin a serious manner.Top SecretCompromise woulddamage nationalinterests in anexceptionallygrave manner.

Due to previous abuses of the official classification system, it is highly unlikely that a System remains defined as Unclassified.

Data Classification Impact

The architecturally significant impact of the specified Data Classification are listed below and complied with in the relevant sections of this document:

Requirements:

  • Electronic Data Transmission:
    • REQ-xxxx: Electronically transmitted IN-CONFIDENCE Information MUST be marked as IN-CONFIDENCE.
    • REQ-xxxx: Electronically transmitted RESTRICTED/SENSITIVE/+ Information MUST be marked RESTRICTED or SENSITIVE.
    • REQ-xxxx: Electronically transmitted IN-CONFIDENCE/RESTRICTED/SENSITIVE/+ information MUST be transmitted across external or public networks (including the Internet) without being encrypted.
    • REQ-xxxx: Electronically transmitted IN-CONFIDENCE/+ information MAY be Username/Password protected.
  • Electronic Data storage:
    • REQ-xxxx: All Electronically transmitted IN-CONFIDENCE/RESTRICTED/SENSITIVE/+ information (including data) is to clearly identify the originating Govt agency and data.
    • REQ-xxxx: An appropriate statement SHOULD accompany all IN-CONFIDENCE transmitted data.
    • REQ-xxxx: An appropriate statement MUST accompany all RESTRICTED/SENSITIVE/+ transmitted data.
    • REQ-xxxx: Electronically transmitted RESTRICTED/SENSITIVE information transmitted across public networks (this includes the Internet) within NZ or across any networks overseas must be encrypted using a system approved by GCSB.
  • Electronic Data storage:
    • REQ-xxxx: Electronically stored IN-CONFIDENCE/RESTRICTED/SENSITIVE/+ Electronic files MUST be protected against illicit internal use or intrusion by external parties through two or more of the following mechanisms:
      • User challenge and authentication
      • Logging use at level of individual
      • Firewalls and intrusion detection systems and procedures
      • Server authentication
      • OS-specific/ application-specific security measures
        • Encryption (required for RESTRICTIVE/SENSITIVE or above)

        * Electronic Electronic Disposal:

    • REQ-xxxx: IN CONFIDENCE/RESTRICTIVE/SENSITIVE/+ information MAY be destroyed by using the delete function.
    • REQ-xxxx: IN-CONFIDENCE Electronic media SHOULD be disposed of in a way that makes compromise highly unlikely.
    • REQ-xxxx: RESTRICTIVE/SENSITIVE/+ Electronic media SHOULD be disposed of in a way that makes reconstruction highly unlikely.
      • REQ-xxxx: IN CONFIDENCE/RESTRICTIVE/SENSITIVE/+ media is to be disposed of or sold, it MUST be purged using a GCSB approved secure delete facility or physically destroyed.

      * Paper Storage:

    • REQ-xxxx: IN-CONFIDENCE documents can be secured using the normal building security and door-swipe card systems that aim to simply keep the public out of the administration areas.
    • REQ-xxxx: RESTRICTED and SENSITIVE documents should be stored in compliance with Archives NZ Storage Standard NAS 9901 Storage of Public Records or Archives.
  • Paper Waste Disposal:
    • REQ-xxxx: MUST comply with provisions of Archives Act 1957
    • REQ-xxxx: IN-CONFIDENCE documents are to be disposed of in a way that makes compromise highly unlikely, such as depositing the documents in bins that are taken away for secure destruction.
      • REQ-xxxx: RESTRICTED and SENSITIVE documents are to be disposed of or destroyed in a way that makes reconstruction highly unlikely, such as mechanical shredding.

  • /home/skysigal/public_html/data/pages/it/ad/continuous_delivery/sad/appendices/data_classification/home.txt
  • Last modified: 2023/11/04 02:46
  • by 127.0.0.1