https://www.computerweekly.com/feature/Risk-management-Data-organization-and-impact-analysis
Start the process of implementing insider threat controls in your organization by classifying critical information by confidentiality, integrity and availability with associated impact ratings. NIST SP 800-60 provides sample information categories and impact definitions.
| Data Type | Confidentiality | Integrity | Availability |
| Trade Secrets | High | High | Medium |
| Human Resources | High | Medium | Low |
| Financial | High | High | Medium |
Now that your data has been defined and classified by CIA rating, identify system boundaries. Boundaries should include systems, data flow, networks, people and hard copy printouts.
29 Aug 2006