PS-26-002 Enterprise Data Classification and Handling 

Issue Date: 10/01/2026

PURPOSE

This policy establishes a unified, enterprise-wide framework for classifying and handling State data based on sensitivity, ensuring consistent protection of confidentiality, integrity, and availability, and alignment with FIPS 199 system security categorization. 

SCOPE and AUTHORITY

O.C.G.A 50-25-4(a)(8) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers

O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers

PS-08-005 Enterprise Information Security Policy 

PM-04-001 Information Technology Policies, Standards and Guidelines 

TERMS AND DEFINITIONS

Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11. 

POLICY

Agencies shall classify all State data and protect it according to its classification level throughout its lifecycle, including during access, use, transmission, sharing, storage, and disposal. Data handling shall comply with applicable security, legal, regulatory, and third-party sharing requirements, including requirements governing the use of data with AI tools and services.

RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES

Data Classification & Handling Standard (SS-XX-XXX)

Data and Asset Categorization (PS-08-012)

Data Categorization – Impact Level (SS-08-014)

Classification of Personal Information (SS-08-002)

Surplus Electronic Media Disposal (SS-08-034)

Enterprise Information Security Policy (PS-08-005)

Data Security – Electronic Records (SS-08-003)

Media Protection and Handling (SS-08-043)

REFERENCES

NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)

FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

NIST SP 800-53B, Control Baselines for Information Systems and Organizations

NIST SP 800-60 Vol. 1 & 2, Guide for Mapping Types of Information and Information Systems to Security Categories

NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization

NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)