Enterprise Data Classification & Handling (SS-26-002)
Topics:
SS-26-002 Enterprise Data Classification and Handling
Issue Date: 10/01/2026
PURPOSE
The purpose of this standard is to establish consistent requirements for the classification, labeling, handling, and disposal of State data. These requirements help ensure appropriate safeguards are applied across agencies, reduce the risk of unauthorized disclosure, modification, or loss of information, and support compliance with applicable legal, regulatory, and contractual obligations. The standard also aligns data protection requirements with NIST controls and FIPS 199 system categorization to support the selection and implementation of appropriate security controls.
SCOPE and AUTHORITY
O.C.G.A 50-25-4(a)(8) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers
O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers
PS-08-005 Enterprise Information Security Policy
TERMS AND DEFINITIONS
Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11.
Data Classification – The process of categorizing information based on its sensitivity, value, and impact to the organization in the event of unauthorized disclosure, modification, or loss, to determine appropriate protection requirements.
State Employee Record – Information created, collected, or maintained by the State that relates to an individual’s employment or official duties.
State Employee HR Record – A State employee record created, collected, or maintained for human resources or personnel administration, including information related to hiring, compensation, benefits, performance, leave, disciplinary actions, or other employment matters.
System Security Categorization- The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals.
FIPS 199 Impact Level - The assessed potential impact resulting from a loss of confidentiality, integrity, or availability of information or an information system, expressed as Low, Moderate, or High. Impact levels are determined in accordance with FIPS 199 based on whether the potential adverse effect on organizational operations, organizational assets, or individuals would be limited, serious, or severe or catastrophic, respectively. FIPS 199 impact levels are used for system security categorization and are distinct from enterprise data classification levels.
Data Owner – The individual or organization responsible for the accuracy, integrity, and protection of specified information, including responsibility for establishing the controls for its generation, classification, collection, processing, dissemination, and disposal.
Artificial Intelligence Tools and Services - Software, systems, applications, platforms, or services that operate in whole or in part using artificial intelligence to generate outputs such as predictions, recommendations, decisions, content, or other information based on provided data or inputs. This includes internally operated, third-party, cloud-based, and externally hosted AI capabilities.
STANDARD
I. Data Classification
Agencies shall classify all State data in accordance with PS-26-002 using the following classification levels:
- Public
- Internal
- Confidential
- Restricted
| Classification | Description | Examples | Typical Impact Association (Informational Only) |
| Public | Approved for public release | Public websites, press releases, job postings, published policies, standards, guidelines (excludes those related to physical or technical security) | Low |
| Internal | Non-public operational data used within the agency | Internal agency policy, standards and guidelines, internal email, document drafts not yet published, administrative records, internal newsletters, training materials not created for public use | Low–Moderate |
| Confidential | Sensitive data | HR, financial data, state employee records, security features and configurations, plans related to physical or technical security, policies and guidelines related to physical or technical security, source code, security configurations, and detailed architecture | Moderate |
| Restricted | Highly sensitive or regulatory data | Federal Tax Information (FTI), State tax information where applicable, SSN, PHI/HIPAA, Social Security Administration information, CJIS, PCI information, State employee HR records | Moderate–High |
When multiple classifications exist, the highest data classification shall apply.
Agencies shall apply data classification levels consistently based on:
- Data sensitivity
- Regulatory requirements
- Potential impact of unauthorized disclosure, modification, or loss
Agencies shall evaluate aggregate data to determine whether the combined dataset warrants a higher classification level.
Derived data, reports, exports, and analytical output including outputs generated by Artificial Intelligence (AI) systems, shall inherit the highest classification of source data unless formally reviewed and reclassified.
Data classification may be used as a supporting input to system security categorization.
Data classification levels shall not be used as a direct substitute for FIPS 199 impact levels (Low, Moderate, High). FIPS 199 impact levels shall be determined based on impact analysis in accordance with FIPS 199 for system categorization and shall not be based on data classification.
Agencies shall apply classification labels to State systems, applications, and resources using approved metadata tagging or labeling mechanisms where supported.
Data classification requirements are cumulative:
- Higher classification levels shall include all requirements of lower classification levels unless explicitly stated.
- Restricted data shall meet all requirements defined for Confidential and Internal data.
- Confidential data shall meet all requirements defined for Internal data.
Agencies shall document the relationship between data classification and applicable system security categorization within the applicable System Security Plan (SSP).
II. Data Handling
Agencies shall protect State data during access, use, transmission, storage, sharing, and disposal in accordance with its data classification level.
Agencies shall apply the following minimum handling requirements based on classification level.
The requirements below establish minimum expectations for each classification level. Higher classification levels include the requirements of lower levels unless otherwise stated.
Activity | Public | Internal | Confidential | Restricted |
|---|---|---|---|---|
| Using Data (Collection and Use) | Use is permitted for authorized purposes.
Confidentiality-specific protections are not required.
Integrity and availability protections shall be applied where required. | Shall be used only for authorized business purposes. | Shall be used only for authorized business purposes and limited to necessary data. | Shall be strictly limited to authorized business purposes and minimum necessary data. |
| Public Disclosure / Posting | Public disclosure is permitted. | Shall not be publicly disclosed unless authorized. | Shall not be publicly disclosed. | Shall not be publicly disclosed. |
| Account Usage | Use of authorized account types is permitted for approved activities. | User Accounts should be used for routine access. | User Accounts shall be used for routine access. | User Accounts shall be used for routine access.
Use of Service Accounts or Privileged Accounts shall be restricted and subject to additional controls. |
| Electronic Display (computer screens, TV screens) | No restrictions on display. | Should limit visibility to authorized individuals. | Shall be visible only to authorized individuals. | Shall be restricted to authorized and authenticated users; masking should be applied where possible. |
| Email and Electronic Messaging (Soft Copy) | Standard system protections shall be applied. | Shall be limited to authorized recipients with a legitimate business need to know.
Should include classification labeling where supported.
Encryption should be applied when transmitted externally. | Shall be limited to authorized recipients.
Shall be protected using approved cryptographic mechanisms in accordance with PS-08-024 and SS-08-040.
Transmission of unencrypted Confidential data is prohibited.
Shall include classification labeling. | Shall be limited to authorized recipients.
Shall be protected using approved cryptographic mechanisms in accordance with PS-08-024 and SS-08-040.
Transmission of unencrypted Restricted data is strictly prohibited.
Shall require Data Owner approval prior to transmission.
Shall include classification labeling. |
| AI Processing (AI Tools / Services) | Permitted. | Shall be limited to approved AI tools and authorized use. | Shall only be used with approved AI tools.
Confidential data shall not be entered into unapproved AI systems. | Shall not be entered into AI tools unless explicitly approved and controlled in accordance with enterprise policies. |
| Printing, Mailing, Fax (Hard Copy) | No confidentiality-specific protection required. | Shall be distributed only to authorized individuals with a legitimate business need.
Shall include classification labeling. | Shall be distributed only to authorized individuals.
Shall include classification labeling.
Physical access shall be controlled. | Shall be distributed only to authorized individuals.
Shall include classification labeling.
Physical access shall be strictly controlled. |
| Granting Access | Access is permitted for authorized users. | Shall be limited to authorized individuals with a legitimate business need. | Shall be limited to authorized individuals with a legitimate business need to know.
Shall enforce least privilege in accordance with PS-08-009 and SS-08-010. | Shall be limited to authorized individuals with a legitimate business need to know.
Shall enforce least privilege in accordance with PS-08-009 and SS-08-010.
Shall require Data Owner approval. |
| Data Copying / Movement | No restrictions beyond authorized use. | Should be limited to business need.
Encryption should be applied when data is moved outside controlled environments. | Shall be limited to authorized purposes and controlled environments.
Encryption shall be applied when data is moved or transferred. | Shall be strictly controlled and require approval prior to copying or movement.
Restricted data shall not be entered into unapproved AI systems. |
| Data In-Transit | Protection should be applied where integrity or authenticity is required. | Shall use secure communication methods and restrict access to authorized users.
Encryption shall be applied where data is transmitted externally or where risk warrants additional protection. | Shall be protected using approved cryptographic mechanisms in accordance with PS-08-024 and SS-08-040.
Transmission of unencrypted Confidential data is prohibited.
Shall enforce authenticated communication. | Shall be protected using approved cryptographic mechanisms in accordance with PS-08-024 and SS-08-040.
Transmission of unencrypted Restricted data is strictly prohibited.
Shall enforce strong authentication in accordance with PS-08-009 and SS-08-010.
Shall use approved communication channels. |
| Data At-Rest | Standard system protections shall be applied.
Integrity protections should be applied where appropriate. | Shall be protected using appropriate access controls.
Encryption should be applied where risk warrants additional protection.
Monitoring should be applied. | Shall be protected using approved cryptographic mechanisms in accordance with SS-08-040.
Shall enforce access control per SS-08-010.
Shall apply appropriate monitoring controls. | Shall be protected using approved cryptographic mechanisms in accordance with SS-08-040.
Shall enforce strong access controls per SS-08-010.
Shall apply enhanced monitoring in accordance with SS-08-004 and ensure availability controls (e.g., backups). |
| System Storage (Servers / Cloud) | Standard system protections shall be applied | Shall be stored in approved systems. | Shall be stored in approved and secured systems.
Encryption shall be applied where required. | Shall be stored only in approved and controlled systems.
Encryption shall be required. |
| Removable Media | No restrictions beyond standard use. | Shall be protected (e.g., password protection or equivalent). | Shall be protected using approved cryptographic mechanisms.
Use shall require approval.
Non-State media shall not be used. | Restricted data shall not be stored on removable media unless explicitly authorized by the Data Owner and protected in accordance with applicable standards.
Media protection shall follow SS-08-043. |
| Non-State Devices | No restrictions beyond authorized use. | Shall not be stored on non-State or unmanaged devices unless explicitly authorized and protected in accordance with SS-12-002. | Shall not be stored on or accessed from non-State devices. | Shall not be stored on or accessed from non-State devices. |
| Sanitization and Disposal | Standard disposal practices apply. | Shall follow NIST SP 800-88 and SS-08-034. | Shall follow NIST SP 800-88 and SS-08-034. | Shall follow NIST SP 800-88 and SS-08-034.
Shall require documented destruction (certificate of destruction). |
| Open Records Requests | Publicly releasable. | Shall be reviewed by Legal prior to release. | Shall be reviewed and may require redaction. | Shall be reviewed and redacted as required by law. |
| Third-Party Sharing | Third party must be authorized and have a legitimate business need. | Shall require formal agreement approved by Agency Legal and CIO in accordance with SS-08-013 and SS-08-044. | Shall require formal agreement.
Third parties shall meet equivalent or stronger security requirements.
Use of AI tools shall be treated as sharing data with an external system unless approved for internal use. | Shall require formal agreement and approval.
Third parties shall meet equivalent or stronger security requirements in accordance with SS-08-013 and SS-08-044.
Restricted data shall not be entered into AI systems unless explicitly approved and controlled in accordance with enterprise policies. |
Encryption
Encryption requirements shall be implemented in accordance with PS-08-024 (Use of Cryptography) and SS-08-040 (Cryptographic Controls) based on data classification and risk.
Artificial Intelligence and Data Handling
Use of Artificial Intelligence (AI) tools or services shall be considered external data sharing unless the AI system is explicitly approved and controlled in accordance with enterprise AI security policies and security standards.
Confidential and Restricted data shall not be entered into AI systems that are not approved for handling such data.
Data Sharing
Agencies shall document and authorize information exchanges involving State data and establish applicable data classification, handling, security, and privacy requirements in accordance with enterprise requirements. Formal agreements shall be established where required based on the nature of the information exchange, participating organizations, applicable legal or regulatory requirements, or use of external service providers.
Agencies sharing State data with external service providers or other third parties shall establish documented agreements or other authorized arrangements that define applicable data classification, handling, security, privacy, and protection requirements and the responsibilities of each party. Such agreements or arrangements shall be established in accordance with applicable enterprise third-party security and external service requirements.
Media Sanitization, Retention and Disposal
Media sanitization shall be performed in accordance with applicable enterprise media sanitization and disposal requirements, including SS-08-003 (Data Security – Electronic Records) and SS-08-034 (Surplus Electronic Media Disposal), and NIST SP 800-88 (current revision), Guidelines for Media Sanitization.
Agencies shall dispose of State data in accordance with applicable federal and state laws and enterprise data sanitization and disposal requirements. State data that constitutes a State record shall be retained and disposed of in accordance with applicable State and agency records retention schedules.
Monitoring and Review
Agencies shall review assigned data classifications at least annually and upon significant change that may affect the classification or applicable handling requirements.
Agencies shall implement monitoring and logging, as applicable, to validate compliance with the requirements of this standard.
III. Access Control
Agencies shall restrict access to state data to authorized individuals who have a legitimate business need to perform their assigned job responsibilities.
Agencies shall require demonstrated business need and Data Owner approval prior to granting access to Internal and Confidential State data.
Agencies shall require demonstrated business need, completion of required training, where applicable, and Data Owner approval prior to granting access to Restricted State data.
Unauthorized access, disclosure, or distribution of State data is strictly prohibited.
Agencies shall implement access control in accordance with PS-08-009 Access Control, PS-21-002 Multi-Factor Authentication Policy and SS-08-010 Authorization and Access Management.
Access by Account Types
Agencies shall manage access to State data in accordance with the following account types:
- User Accounts – Shall be used for standard user access. User Accounts shall not have privileged system-level permissions and shall be limited to access necessary for assigned job functions.
- Service Accounts – Shall be used only for system-to-system or application access. Service Accounts shall not be used for interactive user access and shall be restricted to only the functions required.
- Privileged Accounts – Shall be used only for administrative or system-level functions. Privileged Accounts shall be limited, controlled, and monitored, and shall not be used for routine access to State data.
Confidential and Restricted State data shall be accessed using User Accounts whenever possible. Use of Service Accounts or Privileged Accounts to access such data shall be restricted and subject to additional controls.
RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES
Access Control Policy (PS-08-009)
Use of Cryptography (PS-08-024)
Enterprise Artificial Intelligence Responsible Use Policy (PS-23-001)
Authorization and Access Control Management (SS-08-010)
Cryptographic Controls (SS-08-040)
Secure Remote Access (SS-08-038)
Incident Response and Reporting (SS-08-004)
Data and Asset Categorization (PS-08-012)
Data Categorization – Impact Level (SS-08-014)
Classification of Personal Information (SS-08-002)
Surplus Electronic Media Disposal (SS-08-034)
Data Security – Electronic Records (SS-08-003)
Media Protection and Handling (SS-08-043)
Third Party Security Requirements (SS-08-013)
Outsourced IT Services and Third-party Interconnections (SS-08-044)
Data Location and Access (SS-15-002)
Non-State Technology Devices (SS-12-002)
REFERENCES
NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)
FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
NIST SP 800-53B, Control Baselines for Information Systems and Organizations
NIST SP 800-60 Vol. 1 & 2, Guide for Mapping Types of Information and Information Systems to Security Categories
NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization
NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)