U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

SP 1800-39 (Draft)

Implementing Data Classification Practices (Preliminary Draft)

Date Published: April 25, 2023
Comments Due: June 12, 2023
Email Comments to: data-nccoe@nist.gov

Author(s)

William Newhouse (NIST), Murugiah Souppaya (NIST), John Kent (MITRE), Kenneth Sandlin (MITRE), Karen Scarfone (Scarfone Cybersecurity)

Announcement

The National Cybersecurity Center of Excellence (NCCoE) has published for comment Preliminary Draft NIST SP 1800-39A, Implementing Data Classification Practices. 

About the Project

Organizations are managing an increasing volume of data while maintaining compliance with policies for protecting that data. Those policies are driven by business, regulatory, data security, and privacy requirements. This publication can help organizations reduce the risk of data breaches, loss, and mishandling through data-centric security management, by demonstrating how to discover and classify data based on its characteristics regardless of where the data resides or how it is shared.

The NCCoE and its collaborators are using commercially available technology to build interoperable data classification solutions for use cases. As the project progresses, this preliminary draft will be updated with supporting guidance, and additional use cases and volumes will also be released to solicit public comment.

Submit Comments

The public comment period for this draft is open now through June 12, 2023.

Join the Community of Interest

If you have expertise and/or interest in data-centric security practices, consider joining the NCCoE Data Classification Community of Interest (COI) to receive the latest project news and updates! Email the team at data-nccoe@nist.gov declaring your interest.

Control Families

Risk Assessment; PII Processing and Transparency

Documentation

Publication:
NIST SP 1800-39A iprd

Supplemental Material:
Project homepage (web)

Document History:
04/25/23: SP 1800-39 (Draft)

Topics

Security and Privacy
categorization; privacy; zero trust

Technologies
email

Applications
enterprise

Sectors
financial services; healthcare; manufacturing