Data Classification:
Data classification helps determine where regulated data is located across the enterprise, ensures that appropriate security controls are in place, and that the data is traceable and searchable, as required by compliance regulations.
All Tech Mahindra data in the form of documents, electronic and hard copy, or audio/video shall be classified using one of the following three data classifications.
-
Company Confidential : Data that is confidential to Tech Mahindra, created internally or received from customers / partners.
- Restricted : The data is restricted to pre-defined associates, groups, functions, business units.
- Public : Any data which can be shared to everyone including inside and outside Tech Mahindra. For example: Tech Mahindra Website, Press release.
Data Leakage Prevention:
- DLP is the practice of detecting and preventing Confidential / Critical / Sensitive information from being “leaked” out of an organization’s boundaries.
- Data may be physically or logically removed from the organization either intentionally or unintentionally.
General Data Protection Challenges
Data Leakage channels:
- Internet / Web mail (Yahoo mail, Gmail, Hotmail)
- Company Email
- Cloud Storage
- External Portable Storage Devices
- P2P file sharing (e.g. Filezilla, TeamViewer)
- Printing
- Print Screen
- Clip Board
DLP – Detection Criteria
- Criteria for Detection of Confidential or personal information in the Document.
- Alerts are triggered based on the Keywords, Patterns, Regex, Classification criteria.
- Mandatory classified or tagged documents will be monitored based on the document classification
- Non classified documents will be restricted based on a classification key word search.