Data Classification
Knowing which fields are regulated, because every control depends on it.
5 to work through
-
beginner Multiple choice
A support tool shows `**** **** **** 4242`. A product manager asks to display the full card number for identity verification. The database stores the full number encrypted with a managed key. Which change actually reduces PCI DSS scope?
2 min answer -
intermediate
A consumer finance platform wants to apply controls proportionate to data sensitivity. How should classification work so it actually drives behaviour?
2 min answer -
intermediate Multiple choice
A data platform labels tables as public internal confidential or restricted in its catalogue. Six months on an auditor finds restricted columns in a dashboard that 400 people can open. Which control would have actually prevented it?
3 min answer -
intermediate
A developer needs to reproduce a bug that only occurs with a specific customer's data. What do you allow?
2 min answer -
intermediate
A platform handles customer addresses, payment details, order history, retailer pricing and shopper location. Why does data classification matter architecturally, and what goes wrong without it?
2 min answer
3 terms in this topic
Data Discovery
Automatically scanning stores to find where sensitive data actually resides, as distinct from where the documentation says it should.
patternFail-Closed Classification Default
Resolving an absent sensitivity label to the most restrictive class, so that forgetting to classify data produces a denied query rather than a silent…
patternTag-Bound Access Policy
An access rule attached to a classification label rather than to a table, so that tagging data is what applies the control and derived copies inherit…
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Security Incident Response
Detection, scoping, containment and notification clocks.