Information sensitivity
From Wikipedia, the free encyclopedia
Sensitive information is information or knowledge that might result in loss of an advantage or level of security if revealed (disclosed) to others who might have low or unknown trustability and/or indeterminable or hostile intentions.
Loss, misuse, modification or unauthorized access to sensitive information can adversely affect the privacy of an individual, trade secrets of a business or even the security, internal and foreign affairs of a nation depending on the level of sensitivity and nature of the information.
Contents |
[edit] Types of sensitive information
The term classified information generally refers to information that is subject to special security classification regulations imposed by many national governments. The term Unclassified as used in the table below refers to information that is not subject to security classification regulations.
[edit] N
|
[edit] Public informationThis refers to information that is already a matter of public record or knowledge. For public information, further disclosure can do no harm. [edit] Personal informationThis is information belonging to a private individual, but the individual commonly may share with others for personal or business reasons. This generally includes contact information such as addresses, telephone numbers, e-mail addresses, and so on. It may be considered a breach of privacy to disclose such information, but for most people its disclosure is not considered a serious matter. However, there are situations in which the release of personal information could have a negative effect on its owner. For example, a person trying to avoid a stalker will be inclined to further restrict access to such personal information. [edit] Private informationInformation is private if it is associated with an individual and its disclosure might not be in the individual's best interests. This would include a broad range of information that could be exploited to cause a person damage. A person's SSN, credit card numbers, and other financial information should be considered private, since their disclosure might lead to crimes such as identity theft or fraud. Some types of private information, including records of a person's health care, education, and employment may be protected by privacy laws in some cases. Disclosing private information can make the perpetrator liable for civil remedies and may in some cases be subject to criminal penalties. [edit] Routine business informationThis includes business information that is not subjected to special protection and may be routinely shared with anyone inside or outside of the business. [edit] Confidential business informationConfidential business information refers to information whose disclosure may harm the business. Such information may include trade secrets as described in the "Economic Espionage Act of 1996 (18 USC 1831-39)". In practice, it may include sales and marketing plans, new product plans, and notes associated with patentable inventions. In publicly held companies, confidential information may include "insider" financial data whose disclosure is regulated by the United States Securities and Exchange Commission. |
|
---|---|---|
[edit] C
|
[edit] RESTRICTED
[edit] CONFIDENTIAL
[edit] SECRET
[edit] TOP SECRET (TS)
[edit] "ULTRA SECRET" or SCI
|
Information can be reclassified to a different level or declassified (made available to the public) depending on changes of situation or new intelligence.
[edit] Sensitivity Indicator in the USA
In the intelligence community the sensitivity indicator (aka. sensitivity label) specifies the level of secrecy of a project, document or piece of information by its relevancy to national security. Only those with appropriate security clearance can access information of certain sensitivity and might face additional special access restrictions.
The indicator can also be the name of a classified project such as "Project Blue Book" or "ULTRA", further restricting access to or handling of information.
[edit] See also
- Mandatory Access Control
- Espionage
- RFC1327
- Federal Standard 1037C and the National Information Systems Security Glossary
- Seal of the Confessional