2.1) Identify and classify information and assets

  1. Data classification
  2. Asset Classification

Sensitive data | Top Secret | Confidential | Proprietary | Protected | Unclassified | PII (Personally Identifiable Information) | PHI (Protected Health Information) | HIPAA (Health Insurance Portability and Accountability Act |

Managing Data Lifecycle = steps to protect data from creation till destruction

Step 01: Asset Inventory = identifying & classifying information & assets (including data, hardware to process data, media to store data). Label assets according to security policy requirements.

