simpl.
Cybersecurity GRC 12 items

Data Classification & Handling Compliance Checklist

Verifies that data is classified, labeled, and handled according to its sensitivity across its lifecycle.

ISO 27001:2022NIST 800-53SOC 2

Free PDF · enter your email to download.

Classification Scheme

  • Is a documented data classification scheme (e.g., Public, Internal, Confidential, Restricted) established? *
  • Are classification criteria based on confidentiality, integrity, and availability impact? *
  • Are data owners assigned responsibility for classifying their data? *

Labeling & Inventory

  • Is information labeled in accordance with the classification scheme? *
  • Is an inventory of sensitive data stores (data map) maintained? *
  • Is sensitive data discovery performed to find unmanaged or shadow data? *

Handling & Protection

  • Are handling rules defined per classification level (storage, transmission, sharing)? *
  • Are data loss prevention (DLP) controls applied to restricted data? *
  • Is encryption applied to confidential and restricted data per policy? *

Retention & Disposal

  • Are retention periods defined for each data classification? *
  • Is data securely disposed of or anonymized at the end of its retention period? *
  • Is media sanitization verified prior to disposal or reuse? *

Download the full Data Classification & Handling Compliance Checklist checklist

Get it as a clean, printable PDF — free.