TechKnowSurge
NIST NICE K0865 NIST NICE K0934 NIST CSF ID.AM-07 ISC2 CISSP 2.1
VideoSecurityFree

Data Inventory and Data Labeling

Data classification only works when it's consistently applied through labeling and inventory practices that identify and track sensitive information across an organization's systems. This content covers how to conduct a data inventory, perform data mapping, and use labels and metadata to enforce a classification scheme.

Complete this video to capture a CTF flag worth 1 point.

About this video

A data classification policy has no practical value until the data itself is identified, mapped, and labeled according to that policy. The process begins with a data inventory, which involves systematically scanning an organization's data sources to locate sensitive information, particularly personally identifiable information and other data that falls into restricted or confidential categories. This step requires thoroughness across all systems where organizational data may be stored or transmitted. When dealing with relational databases, data inventory often requires data mapping to trace how information is related and distributed across multiple tables. A single customer record, for example, may have relationships that extend across many tables, and understanding those connections is essential to determining the full scope of what is being stored and how it should be classified. Visual tools such as relationship diagrams help teams follow these connections and ensure nothing is overlooked during the classification process. Once data has been located and its classification determined, it must be labeled in a way that makes that classification persistent and accessible. For documents and files, labeling options include file attributes, embedded metadata, or description fields within a database. Metadata, which is data that describes other data, can be attached to or stored separately from the source files to record classification details. For broader tracking needs, organizations may also maintain external records such as spreadsheets or secondary databases to document the classification status of data stored across their networks.

What you'll learn

What's covered

Applying Data Classification Labels

Aligned to

NIST NICE
K0865 Knowledge of data classification standards and best practices
K0934 Knowledge of data classification policies and procedures
NIST CSF
ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained.
ISC2 CISSP
2.1 Identify and classify information and assets

Key terms

Data Inventory
A structured catalog of the data an organization collects and stores, used to support compliance, access management, and deletion requests.
Data Mapping
The process of tracing relationships between data across systems or database tables to identify where specific data is stored.
Data Classification
The process of organizing and labeling data based on its sensitivity or confidentiality level to inform access and handling policies.
Metadata
Data that describes other data — such as a file's name, size, creation date, and author — allowing operating systems and applications to organize, index, and manage content without reading the content itself.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.

Topics

Data Classification Data Inventory Data Mapping Metadata File Attributes Information Security

Transcript

Just having data classifications isn't enough. We actually have to apply it. But how do we apply it?

Data Inventory

Once we've created some sort of scale for business data classification — so in this case we have public, internal, confidential and restricted — now we need to figure out how does this apply to the different data that we have within our organization.

The first step in this is doing some sort of data inventory: scouring your data sources to figure out where there is data out there and how to classify that data. One of the first times I did this, we took a look at the relational database and we were specifically looking for customer data and personal identifiable information, and we started scouring the database and all the sources where this showed up on this database.

Data Mapping

This might require some data mapping. This is a relational database, and there's relation between a lot of this data that we have on here. The yellow lines are showing those relationships that we have within these different tables. So what we might have to do is find a piece of information, like maybe a customer record, and then trace that through these different areas to find out where that customer's data is and what data we're storing on that. So we're doing this data mapping for us to be able to do this data inventory and figure out where that PII information is located.

Data Labeling

Then we're going to have to start tracking that, so somehow we're going to need to do some sort of data labeling, where we're going to label the data with its classification.

If it's a document, some ways that we could do that is through attributes — a lot of files on your computer have attributes to them, and so perhaps we track it with one of those attributes. Or maybe it has some sort of labeling mechanism. Maybe there's some way that we can keep some metadata. What metadata is, is data about data. So this right here is a document, and if we were to track things separately in another document, or perhaps it's attached to the document somehow, this is data about this data, and that's what we consider metadata.

So these are some ways that we could label or track these different documents and the classification of these documents. In the database, I've also used the description field to track certain information, so we could use that. Or we could possibly use like a separate spreadsheet, or another database, or other ways that we track the data classification of the data that we're storing within our different networks.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →