How to answer
Do you classify data by sensitivity?
One of the few questions where most small companies genuinely have nothing, and where inventing a scheme is worse than saying so.
Yes. Data is classified as [public, internal, confidential or customer data], and the handling requirements for each are set out in our information security policy. Customer data is the most restricted class and is accessible only to named roles.
Square brackets are yours to fill in. FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Your information security policy or a data classification policy, and your privacy policy.
- Evidence to attach
- Occasionally the classification scheme itself, which is usually a single page and safe to share.
- Where it is asked
- CAIQ v4.0 · DSP-04SIG LiteISO 27001 Annex A · A.5.12
This question comes from the enterprise world, where thousands of documents circulate and labelling them decides who may open which. A fifteen-person SaaS has a much simpler reality: there is customer data, there is company information, and there is what is on the website. Which is, in fact, a classification scheme, and saying so plainly is a better answer than borrowing somebody else's four tiers.
What a reviewer wants to know. Not the labels. They want to know that you can distinguish the most sensitive thing you hold from everything else, and that the distinction changes who can reach it. If access to production customer data is limited to three named people while the company wiki is open to everyone, you have applied a classification even if you have never written the word.
Write the scheme you actually operate. Three or four classes, each with one line saying who may access it and where it may be stored. That page takes an hour and it is the document this question, and the several that follow it about labelling, handling and disposal, will be answered from for years.
Do not invent tiers you will not use. A scheme with "restricted", "highly confidential" and "secret" as separate classes, when nothing in the company is ever marked with any of them, is worse than having none. The follow-up question is how data is labelled in practice, and the answer will be that it is not.
Where it interacts with other answers. Retention, access reviews and encryption all reference classification implicitly. A reviewer reading a coherent set is much more comfortable than one reading four answers that each imply a different model of what you hold.
This is the question most likely to come back as "not in your documents", because almost no small company has written the page. That grade is accurate and it points at a genuinely useful hour of work: not a policy for the sake of a questionnaire, but the sentence that says who may reach customer data, which you will want written down the first time somebody asks you to prove it.
How this one goes wrong
Specific to this question, not general advice.
- Inventing a four-tier scheme to answer the question. If nothing in the company uses it, the next questionnaire will ask how it is applied and there will be no answer.
- Confusing classification with encryption. The question is about labelling and handling rules, not about the cipher.
- Listing classes without handling rules. A scheme that says what the labels are and not what each one requires is a taxonomy, not a control.
Asked in the same breath
Do you use customer data to train AI models?
Data governance
How do you handle international transfers of personal data?
Data governance
How is one customer's data kept separate from another's?
Data governance
What is your data retention period, and how is customer data deleted after termination?
Data governance