5 ms·
I'm not aware of any private sector companies that have more than 2-3 formal "classification" markings, and they're usually more like "internal use only" and "c
by ajdlinux 7y ago
I'm not aware of any private sector companies that have more than 2-3 formal "classification" markings, and they're usually more like "internal use only" and "confidential" rather than "secret". For particularly sensitive documents there would of course be additional restrictions, but I'd be surprised if there were companies using the marking "top secret" for that purpose...
- rietta 7y agoI have seen companies with 5. Along the lines of: 1. Public: Public information 2. Internal Use: Confidential business information 3. Confidential: Information that customers consider confidential 4. Sensitive: Personal and Private Information (PII), information that THE LAW considers confidential 5. Highly Sensitive: Encryption keys, server secrets, staff/admin passwords This list is from a blog I wrote at https://rietta.com/blog/commercial-information-classifications/ https://rietta.com/blog/commercial-information-classificatio.... It was adapted from something I originally saw while a student at Georgia Tech. I've consulted with companies that separately developed a substantially similar 5 point list.
- jefftk 7y agoYes. Categories I've encountered at the big tech company I work at include: * Public * Company confidential (most things) * Need to know (only finance people can see some kinds of financials, only people working on a service can see it's logs) * Legal stuff * Personnel stuff * Highly valuable IP (spam detection algorithms etc)