“…To help you start prioritizing what data to protect, consider the classes of data your company interacts with.

Public Data: Data that is intentionally publicly available and does not require access controls, such as details that are shared on your company website

Internal: Data that isn’t publicly available, but it’s also not likely to be sensitive so limited access controls are necessary to protect it. This includes acceptable use policies, employee handbooks, and internal memos.

Confidential: Potentially sensitive data that is used internally such as internal pricing documents and contact information. This class of data needs to stay within the company.

Restricted: Highly sensitive data such as trade secrets, personally identifiable information (PII), and credit card information. If you are in a regulated industry such as healthcare or finance you are likely to have industry-specific regulations for protecting this class of data. Access to restricted data needs to be limited to an as-needed basis, even amongst your team….”

