Purpose of Data Type Selection
Data Type selections are used by the system to gauge impact, not exposure. While Business Case selection determines how a vendor interacts with your environment (exposure), Data Type selection determines what is at stake if that exposure is realized. Data Types represent the digital assets that may be shared with a vendor as part of the relationship. Selecting Data Types allows the system to evaluate the potential severity of consequences associated with loss, misuse, or compromise of those assets.How to Use Data Type Selections
- Select all Data Types that may reasonably be shared with the vendor
- Do not limit selections to what is contractually intended; consider realistic operational access
- Data Types are evaluated after Business Case selection and do not affect controls in scope
- They are used solely to assess impact
Sensitivity levels and defaults
Each Data Type has a sensitivity level — None, Minimal, Moderate, Elevated, or Critical — that determines its contribution to inherent risk. The Organization and Customer Data Type groupings below describe the default assignments. Your organization can configure the sensitivity assigned to each Data Type in Settings → Your Framework → Data classification, so the levels shown in your environment may differ. See Data Types and Sensitivity Levels for how sensitivity contributes to risk scoring.Organization Data Types
These Data Types relate to assets owned by your organization.Critical
Monetary Assets Cash and cash equivalents, including digital or virtual assets, where access could result in direct financial loss. Authentication Credentials or Internal Encryption Keys Credentials or cryptographic material that could be used to access or control your internal environment or protect your most sensitive data. Financial Reporting Information used to track, analyze, or report on business income, financial position, or assets.Moderate
Insider Information Non-public information about the plans or condition of a publicly traded company that could provide a financial advantage. Vulnerabilities Undisclosed information about weaknesses that could be exploited by a threat actor. Source Code Code owned by your organization, including source, configuration, or executable descriptions of systems. Employee Sensitive PII (Personal Identifiable Information) Employee information that is sensitive in nature and typically subject to breach notification requirements. Proprietary and Confidential Information Information your organization seeks to keep confidential, such as business plans, trade secrets, or contracts.Minimal
Less Sensitive Confidential Information Information routinely shared with partners or customers but not publicly available in bulk. Unrestricted Information Information where unauthorized disclosure would result in little or no consequence.Customer Data Types
These Data Types relate to data about individuals or organizations you serve, not your internal staff.Critical
Sensitive PII Personal data which, if compromised, could result in substantial harm or inconvenience to an individual. PHI (Protected Health Information) Health-related information linked to a specific individual. PCI (Payment Card Industry) Data Cardholder data, including Primary Account Numbers (PANs).Moderate
PII and Additional Attributable Information PII combined with other information that could enable social engineering or fraud. Customer or Partner Proprietary Information Confidential information entrusted to you by a customer or partner. PII (Personal Identifiable Information) Information that permits the identity of an individual to be inferred, directly or indirectly.Minimal
Anonymous Customer Data Data stripped of personal identifiers but still useful for analysis or trend identification.Key Guidance
- Data Type selection is about impact severity, not likelihood
- Select conservatively when uncertainty exists
- Data Types do not change which controls apply
- They inform prioritization, scoring, and escalation within the system
Frequently Asked Questions (FAQs)
What qualifies as Monetary Assets?
Question Does Monetary Assets mean access to bank account information (for example, an account number), or access to the account itself? Answer Monetary Assets refers to access to the account itself, sufficient to move, withdraw, or otherwise control funds. Viewing account numbers, balances, or reports alone does not qualify unless the access could be used to directly transact or transfer value (including digital or virtual assets).What counts as Authentication Credentials or Internal Encryption Keys?
Question Does this include:- API keys used between our systems and a vendor?
- A vendor managing encryption keys for data stored in their environment?
- Usernames and passwords we use to access a SaaS platform (for example, Salesforce logins)?
- API keys used solely to interact with a vendor’s service
- Encryption keys managed by the vendor for their own environment
- Usernames and passwords used by your staff to log in to a vendor’s SaaS platform