36 MAC Pt. 1, R. 2.3
Classification of Information Assets
Cite as 36 Miss. Admin. Code Pt. 1, R. 2.3
Classification of Information Assets
A. Each agency must establish a framework for classifying information1 based on its
sensitivity and criticality to the agency.
1. The framework applies to all data created, collected, accessed, owned,
processed, maintained, stored, or transmitted by the agency and covers all
employees, contractors, and third-party users who have access to this data.
B. Each agency shall serve as a classification authority for its information and
information assets irrespective of location, resource, or form. This includes
information and/or information assets managed or hosted by third parties.
1. Data classifications are a prerequisite to establishing agency policies and
guidance regarding the collection, generation, access, processing, storage,
maintenance, transmission, archiving, and disposal of state data.
i.
In addition to the data classification requirement, ITS recommends all
data have a designated data owner responsible for the identification
and classification of the information they have been designated as well
as establishing rules for data governance and that appropriate
requirements are incorporated into agreements relating to the agency’s
classified data.
C. Each agency must classify data based on potential impact to the agency’s ability to
accomplish its assigned mission, fulfill its legal responsibility, maintain its day-to-day
functions, and protect individuals that would be caused by a loss of confidentiality,
integrity, or availability of the data.
1. Confidentiality
i. Preserving authorized restrictions on information access and
disclosure, including means for protecting person privacy and
proprietary information. A loss of confidentiality is the unauthorized
disclosure of information.
2. Integrity
i. Guarding against improper information modification or destruction
and includes ensuring information nonrepudiation and authenticity. A
loss of integrity is the unauthorized modification or destruction of
information.
3. Availability
i. Ensuring timely and reliable access to and use of information. A loss
of availability is a disruption of access to or use of information or an
information system.
D. Each agency must classify data into one of three categories: Low, Moderate, and
High. These categories are based on the potential impact on the agency should the
data be compromised in terms of confidentiality, integrity, or availability.
1. Low
1 The use of the words “information” and “data” are interchangeable.
i. The loss of confidentiality, integrity, or availability could be expected
to have a limited adverse effect on agency operations, agency assets or
individuals.
2. Moderate
i. The loss of confidentiality, integrity, or availability could be expected
to have a serious adverse effect on agency operations, agency assets or
individuals.
3. High
i. The loss of confidentiality, integrity, or availability could be expected
to have a severe or catastrophic adverse effect on agency operations,
agency assets or individuals.
E. Each agency must maintain an inventory of all data created, collected, accessed,
stored, processed, or transmitted by agency assets, including those located on-site or
at a remote service provider, classified as Moderate or High.
1. ITS recommends agencies also maintain data mapping of on-premise and off-
premise systems, servers, applications, etc. that have data classified as
Moderate or High.
F. Each agency must determine if their information and information systems are subject
to state or federal legal requirements and categorize them as required by law (i.e.
HIPAA, PCI, IRS, CJIS, etc.).
G. Each agency must establish a process to regularly review and adjust the
appropriateness of assigned classifications throughout the lifecycle of the data.
H. Each agency must ensure that data classified as Moderate or High is secured in
accordance with applicable agency requirements, federal or state
regulations/guidelines, and the enterprise security policy.
I. Each agency must ensure that data shared, as permitted by applicable legal
requirements, with any other public or private entity is classified and protected in
accordance with agency and applicable legal requirements and in accordance with a
document agreement detailing, at minimum, data treatment and protection
requirements.
J. All reproductions of information in its entirety must carry the same information
classification as the original. Partial reproductions of information need to be
evaluated to determine if new classifications are warranted.
K. If an agency is unable to determine the classification of specific data sets, the data
should be assigned a classification that is equivalent to the highest classified data in
the set.
L. ITS recommends all personally identifiable information (PII) be classified, at
minimum, as “Moderate”.
M. Agencies must adhere to all applicable privacy laws, regulations, policies, and
procedures regarding the creation, collection, use, processing, storage, maintenance,
dissemination, disclosure, and disposal of PII.
N. Additionally, agencies must establish administrative, technical, and physical
safeguards to protect PII from unauthorized access, use, modification, loss,
destruction, dissemination, or disclosure.
O. ITS recommends agencies consider implementing the below recommendations as it
relates to PII.
1. Agencies should only create, collect, use, process, store, maintain,
disseminate, and/or disclose PII if they have legal authority to do so.
i.
Additionally, agencies should, to the extent practicable, seek
individual consent for the creation, collection, use, processing, storage,
maintenance, dissemination, or disclosure of PII.
2. Agencies should only create, collect, use, process, store, maintain,
disseminate, and/or disclose the minimum amount of PII that is relevant and
necessary to accomplish its assigned mission, legally authorized purpose,
maintain its day-to-day functions, and fulfill its legal responsibility.
3. In addition to establishing safeguards to protect PII as required in Rule
2.3(M), agencies that create, collect, use, access, process, maintain, share,
disseminate, disclose, and/or store PII should also develop policies,
procedures, and processes aligned with applicable legal requirements and
privacy principles and best practices that address the preceding as well as
purpose, retention, and disposal of PII.
4. Agencies should be transparent and provide notice to individuals regarding the
creation, collection, use purpose, processing, storage, maintenance,
dissemination, disposal, and disclosure of PII.
i.
Agencies should only use PII for the purpose(s) specified in the notice.
5. Agencies should ensure PII is accurate, relevant, timely, and complete.
6. Agencies should only maintain PII for as long as legally required and/or
necessary to accomplish its purpose and/or mission.
7. Training should be provided to all parties with access to and/or who
use/process PII.
8. Agencies should consider the Fair Information Practice Principles (FIPPs)
and/or NIST Privacy Framework when evaluating products, systems, services,
solutions, processes, programs, risks, and activities involving PII and/or
affecting individual privacy.