Absent Data Classification
No scheme identifying which data is sensitive, where it lives, and which controls apply.
- Remediation SLA
- 30 days
- Tier
- 2 · Regulatory
- Domain
- Data
- Escalation
- Security manager review at 14 days
What this finding is
There is no maintained classification scheme, or a scheme exists on paper without being applied to actual data stores. The organisation cannot state with confidence where regulated data resides, which means control requirements cannot be reliably targeted.
Why it is Tier 2
Classification is a prerequisite control that every major framework requires, and its absence undermines every other data control — you cannot encrypt, restrict, or set retention on data you have not located. Assessors treat it as foundational. It is Tier 2 because the absence of classification is not itself an exposure, but it reliably conceals exposures that would otherwise be Tier 1.
Most common misclassification
How to detect it
- 1Ask where regulated data resides and compare the answer against automated discovery results; the delta is the finding.
- 2Run content discovery across storage, databases, and collaboration platforms — regulated data in file shares and ticketing systems is the usual surprise.
- 3Check whether classification labels, where they exist, drive any actual control decision, since labels that affect nothing provide no assurance.
- 4Review whether new systems are classified at onboarding or only during periodic sweeps.
How to remediate it
Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.
- 1Define a small number of levels — three or four — with concrete handling requirements for each; elaborate schemes are not applied consistently.
- 2Run automated discovery to establish the current position rather than relying on system-owner recollection.
- 3Bind classification to enforcement so labels drive encryption, access, retention, and DLP policy.
- 4Make classification a gate in the system-onboarding process so the inventory does not immediately drift.
- 5Assign data owners accountable for maintaining classification of their systems.
How to verify the fix
A maintained inventory maps every system holding regulated data to its classification and applicable controls, automated discovery finds no significant unclassified regulated data, and labels demonstrably drive at least one enforced control.
Mappings
Attacker techniques
- T1213Data from Information Repositories
Compliance mappings
- ISO/IEC 27001:2022A.5.12 — classification of information
- GDPRArt. 30 — records of processing activities
- SOC 2CC3.2 — risk identification