Anitian Enterprise Security
888.ANITIAN
info@anitian.com

Data Classification Services

One of the most daunting problems facing IT departments is the proliferation of data and systems. In large environments, it can become extremely difficult to track, monitor and control data. This problem is compounded with regulatory requirements that demand protection of Personally Identifiable Information and payment card data.

Data classification is a vital step in securing information assets. It establishes a structured approach for assigning data, systems and networks into a small set of classification schemes. Security controls are then applied based on the classification of a system. Systems with a "confidential" or "sensitive" classification would receive greater security protections than those labeled as "public."

Anitian's Data Classification Services help organizations define, implement and monitor a data classification scheme. With more than 15 years of experience in information security and exhaustive expertise with information systems, Anitian is an ideal partner to develop a practical and reliable classification scheme.

Data Classification efforts are ideal for regulatory issues, such as:

  • PCI Compliance
    The storage, use and transmission of the Primary Account Number (PAN) and other associated data is a critical component of PCI compliance. Data classification can help define in-scope systems and aid with compliance efforts.
  • Financial Services
    Data classification can help meet compliance requirements of FFIEC, GLBA, Homeland Security and NCUA standards.
  • Healthcare
    Data classification can help define the location and use of PII and ensure compliance with HIPAA and HITECH.
  • Public Corporations
    Part of SOX compliance is knowing where key financial data resides and ensuring it is kept safe.
  • Government Organizations
    Data classification can help meet the requirements of the Federal Information Systems Management Act (FISMA), as well as DIACAP.
  • Energy and Utility Organizations
    The NERC-CIP standards specifically require data classification efforts, specifically to define what a "critical cyber asset" is and how it is protected.

For more information, please call 888.ANITIAN, or email Anitian Enterprise Security.