Enterprise Data Classification & Handling (PS-26-002)
Topics:
PS-26-002 Enterprise Data Classification and Handling
Issue Date: 10/01/2026
PURPOSE
This policy establishes a unified, enterprise-wide framework for classifying and handling State data based on sensitivity, ensuring consistent protection of confidentiality, integrity, and availability, and alignment with FIPS 199 system security categorization.
SCOPE and AUTHORITY
O.C.G.A 50-25-4(a)(8) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers
O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers
PS-08-005 Enterprise Information Security Policy
PM-04-001 Information Technology Policies, Standards and Guidelines
TERMS AND DEFINITIONS
Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11.
POLICY
Agencies shall classify all State data and protect it according to its classification level throughout its lifecycle, including during access, use, transmission, sharing, storage, and disposal. Data handling shall comply with applicable security, legal, regulatory, and third-party sharing requirements, including requirements governing the use of data with AI tools and services.
RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES
Data Classification & Handling Standard (SS-XX-XXX)
Data and Asset Categorization (PS-08-012)
Data Categorization – Impact Level (SS-08-014)
Classification of Personal Information (SS-08-002)
Surplus Electronic Media Disposal (SS-08-034)
Enterprise Information Security Policy (PS-08-005)
Data Security – Electronic Records (SS-08-003)
Media Protection and Handling (SS-08-043)
REFERENCES
NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)
FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
NIST SP 800-53B, Control Baselines for Information Systems and Organizations
NIST SP 800-60 Vol. 1 & 2, Guide for Mapping Types of Information and Information Systems to Security Categories
NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization
NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)