Hello all! Hoping to take a crack at defining a data classification policy for my org, and am having issues identifying a (current) framework that can guide me.
I found NIST’s:
* “[Guide to protecting confidentiality of PII](https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-122.pdf) (800-122)” and
* “[Guide for mapping types of information and information systems](https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf) (800-60)”,
But these are both at least a decade old, and I doubt they’ll have language about modernized technologies like EDR, Cloud, etc.
Any suggestions for a data classification framework that has been valuable for any of you? Thanks in advance!