Skip to content

Data Classification & Management Procedure

Data Classification & Management Procedure

Version history

Version Number Date Description Created By Approved By
0.1 23/Jan/2024 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Objectives

The objective of this procedure is to ensure that documents and records are appropriately created, captured, accessed, managed, and stored in a manner that reflects business, corporate and regulatory compliance requirements.

This procedure defines classification of data based on its sensitivity, criticality, and the legal & regulatory requirements applicable to the organization and describes the principles for safeguarding data during creation, storage, use, transfer, and disposal / destruction based on its classification.

Scope

Data Management and Classification procedure applies to all information (physical as well as electronic) that is created, obtained, stored, transmitted, processed, and destroyed in the course of business operations of the organization, irrespective of the data location, or the type of device it resides on.

This procedure applies to all documents that is associated with the Information Security management system including documents of external origin with respect to tecciance’s ISMS.

Requirement

Document Classification

All Documents are referred to by appropriate degree of Classification. Four Categories of classification is defined: Client-Confidential, Confidential, Internal-Use, and public data. The classification applies to all documents across the organization and therefore includes policy, procedures, processes, standards, records, and configurations. This also applies to all email communications.

Classification

Level

Description Examples
Client- Confidential Client-Confidential information is the most critical information of tecciance and disclosure or unauthorized access to the same is likely to impact the tecciance business adversely
  • Customer Data / PII of customers stored on production environment.

  • For Example: Name, Age, Contact Address etc., of customers

tecciance -Confidential Restricted information for the consumption of specific individuals / group such as belonging to the management etc.
  • Customer contractual agreements

  • Legal and Regulatory documents

  • Business blueprint / strategy

  • Financial records of tecciance Company Balance sheet

  • Budget files

  • New Product development plans

  • Unpublished financial statements

  • PII, PCI, PHI data of tecciance employees

Internal Use Non-sensitive information for consumption of internal use within tecciance, like the information available on the tecciance Google Drive sites. Any document not classified will be mentioned as Internal Use by default.
  • SOP

  • Policies

  • Procedures

Public Non-sensitive, available to public through tecciance internet websites, news etc.
  • Brochures

  • Blogs

  • Forums

  • tecciance advertisement materials

Information Labelling Guidelines

  • For softcopy, labelling shall be done in the footer and cover page.

  • For Hardcopy, Labelling shall be done in the Cover page of Document.

  • For a homegrown application, labelling shall be provided in the opening screen.

Table 3.0 Information Labelling Guidelines

S. No. Class Name of Label to be marked
Public No label is required
Internal Use Internal Use
tecciance -Confidential tecciance -Confidential
Client-Confidential Client-Confidential

Information Handling Guidelines

Table 4.0 Information Handling Guidelines

Class Copy Storage Transmission (Email / Post/ File Transfer) Disposal
Hardcopy Softcopy Hardcopy Softcopy Hardcopy Softcopy

Public

No restriction No restriction Shared drive No restriction No restriction No restriction No restriction

Internal

No restriction within tecciance No restriction within tecciance Shared drive with authorized employees Restricted within the company’s authorized employees with appropriate maintenance and review of access control tracker Restricted within the company’s authorized employees with appropriate maintenance and review of access control tracker Paper Shredder / Degaussers (for physical machines) Erase / Delete

tecciance -Confidential

With specific consent/ approval of concerned Asset Owner In drawer / cabinet assigned for specific departments / Lock & Key Password protected or Encryption (AES-256 (AES-128 only where 256 is not feasible)) with suitable access control Sealed envelope with marking as “Restricted” Password protected / Encrypted* (using TLS 1.2 or TLS 1.3) Paper Shredder / Degaussers (for physical machines) Erase / Delete

Client - Confidential

With specific consent/ approval of concerned Asset Owner or Customer In drawer assigned for specific departments / Lock & Key

Password protected// Encrypted* (using AES-256 (AES-128 only where 256 is not feasible))

or

Masking critical data fields with suitable access control

Sealed envelope with marking as “confidential” Password protected / Encrypted File Transfer using SFTP service (using TLS 1.2 or TLS 1.3) Paper Shredder / Degaussers (for physical machines) Erase / Delete

Protection of data and privacy

tecciance and tecciance’s senior management shall ensure –

Confidentiality – All sensitive information shall be protected from unauthorized access and disclosure.

Integrity – All information shall be protected from malicious, accidental, or fraudulent alteration / manipulation or destruction.

Availability – Information and information services shall remain available always to authorized users; and adequate measures shall be implemented to prevent denial of service or any kind of loss of data.

tecciance shall implement data protection controls on all its environments (on-premises, cloud environments, virtual desktop environments (such as VDI for end users), mobile devices, devices authorized for work from home (WFH), client environments under tecciance control, test, and R&D environments) that store, transmit or process confidential data that is regulated by national or international legislations, privacy, or cyber laws. tecciance shall implement cryptographic controls on all its applicable environments as per mentioned in ‘tecciance -IT Encryption Policy’. tecciance shall ensure compliance with the applicable laws and regulations, geo-legal compliance of data (and data restrictions) always. tecciance shall implement protective controls as required by suppliers adhering to ‘tecciance -ISMS Supplier Relationship Management Policy & Procedure’. tecciance shall adhere to protection of log information as per ‘tecciance -IT Log Review and Retention Policy’.

Data protection controls shall be implemented on individual systems or hosts. Where such system or host-based implementations are not possible, they shall be deployed on gateways to maximize coverage of data protection.

Responsibility and liabilities in the event of data loss shall be clearly defined in the non-disclosure agreement with external parties.

Sensitive data types

Sensitive data shall comprise of all data that meets one or more of the below requirements:

  • Regulatory information including Personally Identifiable Information (PII)

  • Personal Health Information (PHI)

  • Payment Card Information (PCI)

  • Intellectual property (IP). IP may refer to tecciance IP, or tecciance client IP that is managed by tecciance.

  • Financially sensitive data. This data may be confidential tecciance’s financial information or sensitive financial information meant for individual client representatives only.

  • Information restricted only to internal circulation. Such data may be department restricted data communication or information.

  • Information restricted to specific named group. Such data may be data that is meant for (groups of) individual named users within tecciance.

  • Information received from clients in any form for business purposes by tecciance. Such information may include SoW, pricing, negotiation information, tenders / bids, or MSA related documentation.

tecciance shall implement necessary protective controls as per ‘tecciance -ISMS Privacy and Protection of Personal Data Policy’ for the protection of sensitive personal data.

Data in Motion

Data in motion shall comprise of data that is in transit within tecciance’s controlled networks, Internet, other public networks or tecciance’s client networks.

All data transfer channels shall be blocked by default unless otherwise there is a verified and approved business need. For any approved data transfer channels, controls shall be applied to ensure that all such data egress channels are adequately protected and monitored for data leakage.

Sensitive data shall not be transmitted through email, USB / or portable media storage devices, uploads or downloads from internet or other public networks without adequate protection such as encryption (using TLS 1.2 encryption or above) of the data transfer channel and in-place encryption of data where applicable.

Data/information shall not be shared with third parties without establishing non-disclosure agreements or contracts; specifying information security requirements, their obligations to protect tecciance’s data, their responsibilities for monitoring their own third parties. Wherever reasonable tecciance shall enforce the right to audit and monitor third parties.

Installation of unauthorized software that can tunnel and obfuscation, bypassing network and data security controls shall not be permitted. Unauthorized browser-based utilities, web-based clipboards, anonymous forums or file upload sites, social media file and photo transfer sites and other avenues of potential data loss / theft shall be blocked. tecciance’s IT department shall ensure adequate prevention controls for data in motion. In cases where data transfers are approved, monitoring controls shall deploy to ensure authorized and acceptable use and adhere as per industry standard best practices. Instances such as cloud environments where host-based controls may be unfeasible to implement tecciance’s IT department shall deploy gateway controls for the monitoring and protection of data in motion. tecciance’s IT department shall perform regular data flow analysis to identify potential points of data leakage or abuse within tecciance by third parties to whom such data is exchanged.

Data in use or under process

Data in use or under process shall comprise of data that is being actively accessed by a user(s) or processed by a system; including data that is posted on applications or MIS for processing and data or code that is under execution.

tecciance’s IT Team shall ensure security compliance and adequate protection to data in use by

  • Enforcing strong authentication controls to ensure only authorized personnel have access to systems, software, and applications.

  • Regular identity & privilege management reviews to ensure security and compliance of systems processing sensitive data, databases, and application platforms and to prevent unauthorized access to data.

  • The principle of least privilege shall be applied to such critical systems.

  • Regular vulnerability assessments of applications, databases, and file stores with unstructured data to prevent unauthorized access, malicious attempts to steal or hijack data and minimize the potential of malware and ransomware.

  • Permissions granted to third party software, cloud services to perform read or write on tecciance’s systems (via API calling, web services or token exchange) should be restricted to reliable third parties, and minimal permissions be granted.

  • Techniques of data masking or anonymization shall be used when storing sensitive data on systems where implementation of data security controls is unfeasible.

  • Continuous monitoring of sensitive data flows across tecciance, and external interaction (data sent to third parties for processing) of such data.

  • Sensitive data is appropriately classified.

  • The above shall apply to on-premises systems and applications, applications and databases on cloud environments and tecciance’s client environments that are managed by tecciance.

Data at rest

Data at rest shall comprise of data stored within tecciance’s systems, applications, databases, tecciance’s client systems and applications that are managed by tecciance. This also includes –

  • Data on end user devices including mobile devices authorized under the BYOD policy

  • On premise servers, cloud servers and cloud services (productivity software suites and cloud storage drives)

  • Databases, file shares, intranet sites

  • Portable storage, backup tapes, and removable media

tecciance’s IT department shall implement the following for protection of data at rest –

  • Full disc encryption (using AES-256 (AES-128 only where 256 is not feasible)) of end user hard drives (workstations and laptops) for protection against device theft and loss.

  • Logical partitioning or containerization of data on mobile devices for protection against device theft and loss of device, and to protect against reverse engineered (cracked or rooted) mobile devices.

  • Remote wiping capability shall be implemented on mobile devices to clear stolen or compromised mobile devices of sensitive tecciance’s data.

  • Storage devices such as USB, portable storage media, CD / DVD drives shall be blocked. If USB, portable storage media, CD / DVD drives is allowed as an exception, data will be encrypted (using AES-256 (AES-128 only where 256 is not feasible)).

  • Clipboard functionality (copy-paste) shall be restricted for sensitive data.

  • Sensitive data is appropriately classified, irrespective of storage, database, file share will be encrypted using AES-256 (AES-128 only where 256 is not feasible).

  • Continuous data discovery shall be executed to monitor unauthorized storage of sensitive data, sensitive data storage privilege abuse by authorized users (unjustified hoarding of sensitive data), and to detect and prevent instances of unclassified sensitive data.

  • All physical media shall be wiped irreversibly prior to destruction or disposal.

Data Protection of tecciance’s client environments

tecciance’s client security requirements and contractual obligations take precedence over all tecciance’s security policies and procedures. tecciance’s shall ensure that data protection and privacy expectations of all clients are met with adequate controls. Client contracts and security obligations are fulfilled from all aspects such as (and not limited to) –

  • Data at rest, data in motion & data in use

  • Data retention and data destruction

  • Data segregation

  • Data anonymization or data masking

  • Environmental protection of data processing facilities

  • NDA with third parties

  • Software control

tecciance’s shall perform security due diligence and implement the following controls at all client delivery centres –

  • Ensuring contractual compliance to all security requirements

  • Security incident reporting and management escalations

  • Regular review of data flows, effectiveness of data protection controls and fulfilment of all client privacy requirements

  • Data classification is performed by all client delivery users and that classification is periodically reviewed.

  • Compliance to applicable standards (such as and not limited to HIPAA, HITRUST, PCI, ISO 27001), regulations and laws (such as and limited to EU GDPR, US CCPA, India DPDPA)

  • Demonstrating data protection control effectiveness during audits

  • Performing periodic risk assessments

  • Regular review and revision of client and third-party NDAs

Continuous monitoring & review

tecciance’s IT department shall perform comprehensive (that encompasses on-premises, cloud environments, virtual desktop environments (such as VDI for end users), mobile devices, devices authorized for work from home (WFH), client environments under tecciance’s control, test, and R&D environments) data leakage monitoring to ensure that all events and alerts are recorded and reviewed. Monitoring of data leakage events shall be performed on a continuous basis. Adequate audit trial shall be maintained with chain of custody to facilitate a forensic exercise, as needed. Data discovery shall be performed to ensure data classification, data segregation and data anonymization and masking are performed. R&D and test environments shall be periodically assessed to ensure that there is no sensitive data.

Effectiveness of the data protection controls shall be reviewed on a periodic basis.

Review

This Policy and Procedure shall be reviewed and approved by IS Head once a year or at the time of any major change in existing environment affecting policy, whichever is earlier.

Exceptions

Any exceptions to this Policy and Procedure shall be reviewed and approved by IS Head prior to acceptance.

Control mapping

Mapping to ISO 27001:2022 control (s)

Control No Control Objective
Clause 7.5 Documented Information
A.5.12  Classification of Information 
A.5.13   Labelling of Information 
A.5.14  Information transfer 
A.5.19  Information security in supplier relationships 
A.5.33  Protection of records 
A.5.34  Privacy and protection of PII 
A.8.24  Use of Cryptography 
A.8.15  Logging 

6.

7.

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

Canonical labels (kernel): Public, Internal, Confidential, Restricted. Map legacy names: Internal Use → Internal; tecciance-Confidential → Confidential; Client-Confidential → Restricted.

Restricted is the default for client production data, PHI, payment data, and material under a client confidentiality clause.

Knowledge claims, embeddings, and compiled skills inherit the highest classification of their sources. They are labelled and access-filtered; they are not a second unmarked copy.

Unclassified documents default to Internal, not Public.