Sensitive data is confidential information that must be kept safe and out of reach from all outsiders unless they have permission to access it.
Access to sensitive data should be limited through sufficient data security and information security practices designed to prevent data leaks and data breaches.
The rise of regulatory scrutiny over sensitive data protection has culminated in a desperate need for improved data management and Third-Party Risk Management framework designs. Forsaking these now essential requirements could cost your business up to $4 million.
Sensitive information includes all data, whether original or copied, which contains:
As defined by the North Carolina Identity Theft Protection Act of 2005, a series of broad laws to prevent or discourage identity theft and to guard and protect individual privacy.
As defined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). PHI under the US law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a third-party associate) that can be linked to a specific individual.
As defined by the Family Educational Rights and Privacy Act of 1974 (FERPA). FERPA governs access to educational information and records by potential employers, publicly funded educational institutions, and foreign governments.
As defined by the Gramm-Leach-Bliley Act (GLB Act, GLBA or the Financial Modernization Act of 1999), requiring financial institutions to explain how they share and protect their customers' private information.
As defined by the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is an information security standard that tells organization's how to handle branded credit cards from the major card schemes.
As defined by the State Personnel Act.
In accordance with the North Carolina Public Records Act. Includes trade secrets and similar related data.
As defined by The EU General Data Protection Regulation (GDPR).
In general, sensitive data is any data that reveals:
Personal data (or personal information) is information that can identify an individual.
GDPR defines personal data as anything that directly identifies an individual such as a person's name, surname, phone number, social security number, driver's license number or any other personally identifiable information (PII).
Versus pseudonymous data or non-directly identifying information that does not allow direct identification but allows singling out of individual behaviour (such as serving a targeted at to a user at the right moment).
GDPR was established to set a clear distinction between directly identifying information and pseudonymous data.
GDPR encourages the use of pseudonymous information over directly identifying information as it reduces the risk of data breaches having adverse effects on individuals.
To determine how sensitive specific is and how it should be classified, think about the confidentiality, integrity and availability (CIA triad) of that information and how it would impact your organization or its customers if it was exposed.
This is a common way to measure data sensitivity and is a framework provided in the Federal Information Processing Standards (FIPS) by the National Institute of Standards and Technology (NIST).
Confidentiality is roughly equivalent to privacy.
Countermeasures that prevent unauthorized access to sensitive information, while ensuring the right people can still access it, are concerned with confidentiality.
These countermeasures range from simple awareness training to understanding the security risks associated with handling the information and how to guard against them, to sophisticated cybersecurity software.
Examples of confidentiality countermeasures:
Integrity is about maintaining the consistency, accuracy and trustworthiness of data over its lifecycle.
Sensitive data, or sensitive information, should not be changed in transit and should not be able to be altered by unauthorized people (for example when a data breach happens).
Examples of integrity countermeasures:
Availability is concerned with ensuring all information systems and sensitive data is available when needed.
Examples of availability countermeasures:
Data privacy is becoming more and more important. In over 80 countries, personally identifiable information (PII) is protected by information privacy laws that outline limits to collecting and using PII by public and private organizations.
These laws require organizations to give clear notice to individuals about what data is being collected, the reason for collecting and the planned uses of the data. In consent-based legal frameworks, like GDPR, explicit consent from the individual is required.
GDPR extends the scope of EU data protection laws to all foreign companies who process the data of EU residents. Requiring that all companies:
The United States has similar laws dictating data breach disclosure, with all 50 US states having data breach laws in some form requiring:
Additionally, many other countries have enacted their own legislature regarding data privacy protection, and more are still in the process of doing so.
The first step in protecting sensitive data is data classification.
Depending on data sensitivity, there are different levels of protection required. The key thing to understand is that not all data is equal and it is best to focus your data protection efforts on protecting sensitive data as defined above.
Examples of non-sensitive information:
Effective information security starts with assessing what information you have and identifying who has access. Understanding how sensitive data moves into, through and out of your organization is essential to assessing potential vulnerabilities and cybersecurity risks.
This means taking inventory of everywhere your organization uses sensitive data and where you hand of sensitive data to third-party and fourth-party vendors.
This will allow you to understand how information flows through your organization and give you a complete picture of who sends personal information in your organization, who receives sensitive data, what information is collected, who keeps the information collected and who has access to the information.
At UpGuard, we can protect your business from data breaches, identify all of your data leaks, and help you continuously monitor the security posture of all your vendors. UpGuard also supports compliance across a myriad of security frameworks, including NIST, HIPAA, HECVAT, ISO 27001, and more!