Glossary

    Data Classification

    Architecture & Design

    Data Classification is the process of organizing data into categories based on its sensitivity and the impact if it were compromised. It determines which security controls to apply.

    Classification Levels

    • Public: information intended for public access (marketing materials, docs). Minimal controls.
    • Internal: not sensitive but not public (internal tools, non-sensitive business data). Basic access control.
    • Confidential: sensitive business data (financial reports, customer data, contracts). Encryption, access logging, need-to-know.
    • Restricted: highest sensitivity (PII, PHI, payment data, credentials, IP). Encryption, strict access control, audit trails, DLP.

    AWS Tools for Data Classification

    • Amazon Macie: automatically discovers and classifies sensitive data in S3
    • Resource Tags: tag resources with classification level for policy enforcement
    • S3 Object Tags: classify individual objects within buckets
    • Lake Formation: column-level and row-level access control for data lakes

    Security Controls by Level

    • Public: no encryption required, basic monitoring
    • Internal: encryption at rest (SSE-S3), VPC-only access
    • Confidential: encryption (KMS CMK), access logging, VPC endpoints
    • Restricted: KMS CMK with key policy, Object Lock, Macie monitoring, DLP, audit trails

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.