Cybersecurity GRC 12 items
Data Classification & Handling Compliance Checklist
Verifies that data is classified, labeled, and handled according to its sensitivity across its lifecycle.
ISO 27001:2022NIST 800-53SOC 2
Free PDF · enter your email to download.
Classification Scheme
- Is a documented data classification scheme (e.g., Public, Internal, Confidential, Restricted) established? *
- Are classification criteria based on confidentiality, integrity, and availability impact? *
- Are data owners assigned responsibility for classifying their data? *
Labeling & Inventory
- Is information labeled in accordance with the classification scheme? *
- Is an inventory of sensitive data stores (data map) maintained? *
- Is sensitive data discovery performed to find unmanaged or shadow data? *
Handling & Protection
- Are handling rules defined per classification level (storage, transmission, sharing)? *
- Are data loss prevention (DLP) controls applied to restricted data? *
- Is encryption applied to confidential and restricted data per policy? *
Retention & Disposal
- Are retention periods defined for each data classification? *
- Is data securely disposed of or anonymized at the end of its retention period? *
- Is media sanitization verified prior to disposal or reuse? *
Download the full Data Classification & Handling Compliance Checklist checklist
Get it as a clean, printable PDF — free.
