Data Classification is the practice of labeling information by sensitivity so its handling, storage, and transmission match the damage exposure would cause. Government schemes commonly run Unclassified, Confidential, Secret, and Top Secret. Commercial ones often use Public, Internal, Confidential, and Restricted. Once assigned, the label drives every downstream control.
Making it work takes a policy that spells out the categories, the criteria for each, and the handling rules that follow. The data owner assigns the classification, the custodian implements the protection, and everyone who touches the data follows the rules for that tier. A frequent failure is over-classifying everything, which feels safe but buries genuinely critical data under so much friction that people start routing around the controls. Under-classifying is the mirror problem, leaving sensitive records with weak protection because nobody bothered to label them properly.
How is data classification tested on the CISSP?
This is core Domain 2: Asset Security material. Know the government and commercial schemes, the owner, custodian, and user roles, and how the assigned label dictates the controls. Scenario questions often hand you a data type and ask for the right classification or handling response.