Data Types represent the categories of information that may be shared with a vendor as part of a relationship. Selecting the right data types is one of the two inputs (along with business cases) that define relationship context — and they directly drive the impact component of risk scoring.
What Data Types Do
Data types answer the question: if this vendor were compromised, what’s at stake?
While business cases determine how a vendor interacts with your environment (exposure/likelihood), data types determine the potential severity if that exposure is realized (impact). Together, they produce the relationship’s inherent risk score.
Data types determine impact only — they do not bring additional controls into scope. Business cases determine which controls are assessed.
Data Sensitivity Levels
Each data type is assigned a sensitivity level that contributes to the impact score. VISO TRUST uses five levels, from lowest to highest impact:
- None
- Minimal
- Moderate
- Elevated
- Critical
The more sensitive the data a vendor handles, the higher the impact — and the higher the resulting inherent risk. The specific data types your organization tracks, and the sensitivity level assigned to each, are configured in your framework’s Data classification (see Your Framework).
Common data types include Monetary Assets, Authentication Credentials or Internal Encryption Keys, PCI (Payment Card Industry) Data, PHI (Protected Health Information), Sensitive PII, PII, Source Code, Vulnerabilities, Insider Information, Proprietary and Confidential Information, and Unrestricted Information. Higher-impact types — such as payment card data, authentication credentials, and monetary assets — carry the highest sensitivity, while unrestricted information carries the lowest.
How to Select Data Types
When configuring relationship context, select all data types that may reasonably be shared with the vendor — not just what’s contractually intended. Consider realistic operational access, not just the stated purpose of the relationship.
To set data types:
- Open the relationship and select the gear icon
- Go to Context → Data Classification
- Select all applicable data types
The maximum sensitivity level across all selected data types drives the impact score. A relationship where a vendor handles both a low-sensitivity type and a high-sensitivity type is scored at the higher sensitivity level.
Impact on Risk Scoring
Data sensitivity is expressed as a numeric value between 0 and 1 internally. Higher sensitivity data types produce a higher impact score, which in turn raises the inherent risk rating.
Inherent risk labels (No Context, Low, Medium, High, Extreme) reflect both the impact from data types and the likelihood from business cases. Changing data type selections updates the inherent risk score immediately.
See Risk Scoring Overview for a full explanation of how impact and likelihood combine into a risk score.