Virtuelle Group Information Classification & Handling

Information Classification & Handling

1. Summary
The information treatment policy defines the information classification and sets out rules how information must be treated. Virtuelle Group is committed to maintaining a robust physical security monitoring system to protect its assets, facilities, and data from unauthorised access, damage, or theft.
The policy is applicable to all internal and external personnel and applies to customers, partners and suppliers.

1. Responsibilities

  • Cybersecurity Team: Responsible for implementing and maintaining technical controls related to storage media.
  • Employees: Responsible for following storage media security policies and procedures, including classifying data stored on allocated storage media devices.

2. Storage Media Classification

All storage media used within Virtuelle Group shall be classified based on the sensitivity of the information stored. Classification levels include, but are not limited to, public, internal use only, confidential, and highly confidential.

3. Principles

Information is a valuable resource. Protecting the confidentiality, integrity and availability of information is critical to the company’s operations.

  • Confidentiality of information refers to limiting access to information to authorised persons for approved purposes.
  • Integrity of information refers to the assurance that information is authentic, correct and valid, and can be trusted.
  • Availability of information refers to allowing authorised persons to access information for authorised purposes at the time they need to do so

Our organisation distinguishes the following levels of information classification:

Classification Description Examples Treatment
Public Information of this kind can be freely distributed to anyone
  • Information on our public web site
  • Brochures and leaflets
No special measures need to be taken to protect this information
Internal Information of this kind is meant to be kept internally, but no harm would be done if it would fall into wrong hands. This information can be shared with all Stakeholders when deemed necessary
  • Policies and Procedures
  • Mobile Phones (Assets)
  • Statement of Applicability
No special measures need to be taken to protect this information
Confidential The loss of confidential information can pose a threat to the organization
  • Personally Identifiable Information
  • Financial information
  • Audit reports
  • Risk assessment
  • Assurance statement
  • Access control policy
  • Cryptography policy
  • Endpoint device policy
Highly Confidential The loss of sensitive information can pose a threat to the persons involved. Theft or loss should be reported with the authorities Special categories of personal information, such as

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Personal health data
  • Biometric data
  • Sex life or sexual orientation
  • Access control policy
  • Backup policy
  • Cryptography policy
  • Endpoint device policy
  • Logging policy
Personal Non-business data Personal use only No special measures need to be taken to protect this information

4. Integrity

Integrity ensures that information is correct, authentic, and reliable.

We distinguish the following classifications of integrity:

Classification Description Treatment
Low Loss of integrity would have a low (or no) impact on the organization or on the well-being of people No special measures
Medium Loss of integrity would have a moderate impact Controlled by

  • Access control policy
  • Logging policy
High Loss of integrity would have a high impact

5. Availability

Availability ensures that data is accessible when needed.

We distinguish the following classifications of availability:

Classification Description Treatment
Low Loss of availability would have a low (or no) impact on the organization or on the well-being of people No special measures
Medium Loss of availability would have a moderate impact Controlled by

  • Backup policy
  • Business continuity policy
High Loss of availability would have a high impact

6. Information Handling Guidelines

Handling means the way in which information is managed, how the information is accessed, stored, transferred or transmitted, shared, archived and disposed of. Sensitive information is important as it could contain personal or health information and if compromised, could cause limited damage to Virtuelle Group or individuals. As a result, a higher level of controls to protect and manage this information is required.

7. Collecting

Collect information only for a lawful purpose that is reasonably necessary, and directly related to a function or activity of the Virtuelle Group. Collection methods, including online surveys, must have secure storage. Label digital information that is collected. This includes information captured via automated processes, for example via batch processes or API. This information should be labelled in metadata if the system allows or via system documentation ideally at the time the system is developed.

8. Labelling

Label highly sensitive information at the time of collection or creation. Labelling is not retrospective. If information is not in use, there is no need to re-label with new labels. Information in use should be re-labelled. If receiving information that is already labelled, do not re-label. If there are questions about the validity of the label consult the data originator. Labelling of entire systems and large datasets needs to be carefully considered as this could restrict access to information unnecessarily. Labelling at field, case or record level may be more appropriate if the system has the capability. Access to field, case or records with higher sensitivity within a system or large dataset can be managed via user access permissions, only giving access to users that need-to-know.

9. Monitoring

Monitor information over time to determine if the sensitivity of the information has changed. Change the label and security classification if required. Keep access audit logs for the appropriate retention period to assist in future audit and access control monitoring. Protect these logs from accidental or deliberate modification.

10. Storing

Store hard-copy records and information in a designated location, in lockable storage or secure access areas. Store digital records, information and data in the Virtuelle Group’s recordkeeping systems or business systems. Maintain inactive sensitive data to reduce risk of loss or theft. The risk of exposure of sensitive data increases when applications are retired or migrated, or SharePoint sites and file shares are abandoned at the conclusion of a project. For specific guidance about migration or retiring applications, check with Managing Director.

11. Accessing

Apply the need-to-know principle to all information classified as sensitive or highly sensitive. Access to information classified as sensitive and highly sensitive should be restricted. The information custodian has overall accountability for access provided (to hard copy, digital records, information and data). Ensure access to information classified as sensitive or highly sensitive is only provided for a clear and legitimate business reason. Manage user access on an ongoing basis as roles and personnel change. The need for ongoing access or a time limited period of access should be considered. Review access to information systems containing information classified as sensitive or highly sensitive by directly linked third party applications. Information made available to these third party applications must be limited to need-to-know. User access of the third party applications need to be controlled as does the level of information that the users of this application can view. Access rights cannot be transferred. Usernames and passwords should be kept confidential and not shared.

12. Securing

Security officer must assess all data transiting and at rest and make an assessment whether it should be encrypted. Protect assets which contain sensitive or highly sensitive information such as laptops or mobile devices. Secure mobile devices after use in a lockable room within Virtuelle Group facilities and if possible, outside of Virtuelle Group facilities, for example if working from home. Do not use your device unless it is safe to do so. Be aware of your surroundings. When information is being used that can be read, viewed, heard or comprehended, it may be at a higher risk of compromise. Different physical environments pose different risks for information compromise.

13. Using

Lock your computer screen or log out of secure systems when you leave your desk and make sure hard copies are secure (clear desk and clear screen policies should be implemented). Train all staff using sensitive or highly sensitive information or using a secure system, so they are aware of the nature of the sensitive or highly sensitive information and the rules which apply to use the information. Rules include whether they can view, print, share, or email information.

Manual transfer of information classified as highly sensitive may be passed by hand within a discrete office environment provided it is transferred directly between members of staff who need-to-know and there is no opportunity for any unauthorised person to view the information. When carrying physical information classified as sensitive outside a Virtuelle Group facility, this information is to be carried in an opaque envelope or folder. Do not access information classified as sensitive using public networks. Do not copy information classified as sensitive onto local drives or removable mobile storage devices such as USBs.

14. Using – Reports, Dashboards and Products

Do not display products such as reports or dashboards containing sensitive or highly sensitive information unless the audience need-to-know, and permission has been sought from the data custodian.

15. Sharing

If sharing data externally, reducing the sensitivity of the information by de-identification techniques is recommended, for example removing personal information or information revealing law enforcement procedure. If sharing information externally, it is preferable that the source information is redacted to conceal the sensitive or highly sensitive information where possible. This ensures that the source information remains inviolate and that the information can be safely shared. Care must be taken that the redaction does not alter the source information. Emailing highly sensitive information should be done via secure file transfer protocol, or via a secure system as recommended by the Virtuelle Group. Highly sensitive information should not be stored in emails or as attachments to email in your inbox. Email systems are at higher risk of compromise than approved Virtuelle Group business systems and are at risk of accidental forwarding. Sensitive and highly sensitive information should only be shared for authorised purposes.

16. Archiving, Retention and Disposal

Sensitive and highly sensitive information must be disposed of securely.

17. Disposal of Storage Media

  • End-of-life storage media must be securely erased or physically destroyed to prevent unauthorized data recovery.
  • Procedures for the disposal of storage media must be documented and followed.

18. Physical Security Measures

  • Storage media shall be stored in secure and controlled environments to prevent unauthorized access.
  • Access to storage areas must be restricted to authorized personnel only.
  • End-of-life physical network devices must follow the Hardware disposal process, be securely erased and physically destroyed to prevent unauthorized data recovery or use.
  • Procedures for the disposal of physical network devices must be documented and followed.

19. Encryption

  • All sensitive and confidential data stored on storage media must be encrypted using approved encryption algorithms.
  • Encryption keys shall be stored separately from the encrypted data.

20. Data Backup and Recovery

  • Regular backups of critical data stored on storage media must be conducted.
  • Backup copies shall be stored in a secure location, and recovery procedures should be tested periodically.