false
OasisLMS
Login
Catalog
Training Course 1
APPENDIX A
APPENDIX A
Back to course
Pdf Summary
This document defines Oakleaf’s four-level data classification scheme and the required handling controls for each level: <strong>Restricted, Confidential, Private, and Public</strong>. <strong>Restricted</strong> is the most sensitive information, often driven by legal/contractual requirements (e.g., client loan-file NPI/PII, certain contracts). Unauthorized disclosure would cause <strong>significant damage</strong> (regulatory violations, reputational harm, lawsuits). <strong>Confidential</strong> is internally designated sensitive business information (e.g., employee PII/NPI, accounting, payroll, financials) where loss would cause <strong>moderate damage</strong>. <strong>Private</strong> is the default classification for information created/received in daily work; it may be shared with authorized parties with a business need but not publicly released. <strong>Public</strong> information is approved for general release with no expected damage from disclosure. General practices include: classify new information as <strong>Private by default</strong>; when combining data of different levels, apply the <strong>most restrictive</strong> classification; do not move/export data to a format or medium lacking equivalent controls (e.g., no exporting Restricted data to an unencrypted spreadsheet). Exceptions require <strong>CEO and CISO</strong> approval. The document defines <strong>NPI/PII</strong> as a name plus identifiers such as SSN/TIN/NIN, passport/permanent resident card, driver’s license, financial account/payment card numbers, and <strong>ePHI</strong>. Detailed handling requirements specify controls for storage, transmission, email, printing, copying/scanning, faxing, mail, disposal, labeling, and third-party release. Key distinctions: <strong>Restricted</strong> cannot be stored on mobile devices or in cloud storage; external transmission must be encrypted via <strong>SFTP or encrypted email</strong>; printing/copying/faxing are largely prohibited; third-party release requires <strong>CEO/Managing Director approval</strong> and an <strong>NDA</strong>. <strong>Confidential</strong> similarly restricts mobile storage and requires encrypted external transmission; cloud storage is allowed if secure. <strong>Private</strong> recommends encryption and remote wipe on mobile devices; <strong>Public</strong> has minimal controls. The appendix also provides example data types and notes client engagement data may have client-specific requirements.
Keywords
data classification scheme
Restricted data handling
Confidential information controls
Private by default classification
Public information release
PII NPI ePHI definitions
encryption requirements SFTP encrypted email
mobile device storage restrictions
cloud storage security controls
third-party disclosure approval NDA
×
Please select your language
1
English