36 MAC Pt. 1, R. 2.3

Classification of Information Assets

Year: 2026Length: 1,026 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 2.3

Classification of Information Assets A. Each agency must establish a framework for classifying information1 based on its sensitivity and criticality to the agency. 1. The framework applies to all data created, collected, accessed, owned, processed, maintained, stored, or transmitted by the agency and covers all employees, contractors, and third-party users who have access to this data. B. Each agency shall serve as a classification authority for its information and information assets irrespective of location, resource, or form. This includes information and/or information assets managed or hosted by third parties. 1. Data classifications are a prerequisite to establishing agency policies and guidance regarding the collection, generation, access, processing, storage, maintenance, transmission, archiving, and disposal of state data. i. In addition to the data classification requirement, ITS recommends all data have a designated data owner responsible for the identification and classification of the information they have been designated as well as establishing rules for data governance and that appropriate requirements are incorporated into agreements relating to the agency’s classified data. C. Each agency must classify data based on potential impact to the agency’s ability to accomplish its assigned mission, fulfill its legal responsibility, maintain its day-to-day functions, and protect individuals that would be caused by a loss of confidentiality, integrity, or availability of the data. 1. Confidentiality i. Preserving authorized restrictions on information access and disclosure, including means for protecting person privacy and proprietary information. A loss of confidentiality is the unauthorized disclosure of information. 2. Integrity i. Guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity. A loss of integrity is the unauthorized modification or destruction of information. 3. Availability i. Ensuring timely and reliable access to and use of information. A loss of availability is a disruption of access to or use of information or an information system. D. Each agency must classify data into one of three categories: Low, Moderate, and High. These categories are based on the potential impact on the agency should the data be compromised in terms of confidentiality, integrity, or availability. 1. Low 1 The use of the words “information” and “data” are interchangeable. i. The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on agency operations, agency assets or individuals. 2. Moderate i. The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on agency operations, agency assets or individuals. 3. High i. The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on agency operations, agency assets or individuals. E. Each agency must maintain an inventory of all data created, collected, accessed, stored, processed, or transmitted by agency assets, including those located on-site or at a remote service provider, classified as Moderate or High. 1. ITS recommends agencies also maintain data mapping of on-premise and off- premise systems, servers, applications, etc. that have data classified as Moderate or High. F. Each agency must determine if their information and information systems are subject to state or federal legal requirements and categorize them as required by law (i.e. HIPAA, PCI, IRS, CJIS, etc.). G. Each agency must establish a process to regularly review and adjust the appropriateness of assigned classifications throughout the lifecycle of the data. H. Each agency must ensure that data classified as Moderate or High is secured in accordance with applicable agency requirements, federal or state regulations/guidelines, and the enterprise security policy. I. Each agency must ensure that data shared, as permitted by applicable legal requirements, with any other public or private entity is classified and protected in accordance with agency and applicable legal requirements and in accordance with a document agreement detailing, at minimum, data treatment and protection requirements. J. All reproductions of information in its entirety must carry the same information classification as the original. Partial reproductions of information need to be evaluated to determine if new classifications are warranted. K. If an agency is unable to determine the classification of specific data sets, the data should be assigned a classification that is equivalent to the highest classified data in the set. L. ITS recommends all personally identifiable information (PII) be classified, at minimum, as “Moderate”. M. Agencies must adhere to all applicable privacy laws, regulations, policies, and procedures regarding the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal of PII. N. Additionally, agencies must establish administrative, technical, and physical safeguards to protect PII from unauthorized access, use, modification, loss, destruction, dissemination, or disclosure. O. ITS recommends agencies consider implementing the below recommendations as it relates to PII. 1. Agencies should only create, collect, use, process, store, maintain, disseminate, and/or disclose PII if they have legal authority to do so. i. Additionally, agencies should, to the extent practicable, seek individual consent for the creation, collection, use, processing, storage, maintenance, dissemination, or disclosure of PII. 2. Agencies should only create, collect, use, process, store, maintain, disseminate, and/or disclose the minimum amount of PII that is relevant and necessary to accomplish its assigned mission, legally authorized purpose, maintain its day-to-day functions, and fulfill its legal responsibility. 3. In addition to establishing safeguards to protect PII as required in Rule 2.3(M), agencies that create, collect, use, access, process, maintain, share, disseminate, disclose, and/or store PII should also develop policies, procedures, and processes aligned with applicable legal requirements and privacy principles and best practices that address the preceding as well as purpose, retention, and disposal of PII. 4. Agencies should be transparent and provide notice to individuals regarding the creation, collection, use purpose, processing, storage, maintenance, dissemination, disposal, and disclosure of PII. i. Agencies should only use PII for the purpose(s) specified in the notice. 5. Agencies should ensure PII is accurate, relevant, timely, and complete. 6. Agencies should only maintain PII for as long as legally required and/or necessary to accomplish its purpose and/or mission. 7. Training should be provided to all parties with access to and/or who use/process PII. 8. Agencies should consider the Fair Information Practice Principles (FIPPs) and/or NIST Privacy Framework when evaluating products, systems, services, solutions, processes, programs, risks, and activities involving PII and/or affecting individual privacy.
36 MAC Pt. 1, R. 2.3: Classification of Information Assets | Justis AI