Platform data classification
🌐 This document is available in both English and Ukrainian. Use the language toggle in the top right corner to switch between versions. |
1. Confidentiality, integrity, and information availability levels
Security attributes | High | Medium | Low |
---|---|---|---|
Confidentiality is the property that ensures the information is not provided or disclosed to third parties, organizations, or processes. It includes the following metrics:
|
Unauthorized disclosure of information will have a significant or catastrophically negative impact on the operations of the organization, its assets, or people. |
Unauthorized disclosure of information will have a significant negative impact on the operations of the organization, its assets, or people. |
Unauthorized disclosure of information will have a limited negative impact on the operations of the organization, its assets, or people. |
Integrity refers to maintaining and ensuring the accuracy and completeness of data throughout its lifecycle. Integrity is about ensuring that data has not been tampered with or destroyed and, therefore, can be trusted. It includes the following metrics:
|
Unauthorized modification or destruction of information will have a significant or catastrophically negative impact on the operations of the organization, its assets, or people. |
Unauthorized modification or destruction of information will have a significant negative impact on the operations of the organization, its assets, or people. |
Unauthorized modification or destruction of information will have a limited negative impact on the operations of the organization, its assets, or people. |
Availability refers to the provision of timely and guaranteed access to information and its use. It includes the following metrics:
|
Violation of access to or use of information or an information system will have a significant or catastrophically negative impact on the operations of the organization, its assets, or people. |
Violation of access to or use of information or an information system will have a significant negative impact on the operations of the organization, its assets, or people. |
Violation of access to or use of information or an information system will have a limited negative impact on the operations of the organization, its assets, or people. |
2. General data classification
Classification level | Description | Confidentiality | Integrity | Availability |
---|---|---|---|---|
Open information |
Information that can be freely distributed in public. |
Absent |
Medium |
High |
Official information that constitutes a state or other legally mandated secret |
Information for which the loss, forgery, blocking, processing distortion, or violation of the established routing process can lead to undesirable consequences for the project’s operation and reputation. |
High |
High |
Medium |
Confidential information |
Information for which the loss, forgery, blocking, processing distortion, or violation of the established routing process can lead to significant negative consequences, such as causing harm to a person, society, and the state. This includes personal data, which is information or a set of data about a natural person that identifies or can be used to identify them. |
High |
High |
High |
3. Data categories
Data category | Description | Data |
---|---|---|
User authentication data |
Any user data used in the authentication process. |
|
Administrator authentication data |
Any administrator data used in the authentication process. |
|
Service authentication data |
Any technical account data used in the authentication process. |
|
Registry data |
A set of data from the registry that was created as a result of specific operations and circulates in the system. All data that belongs to the user and is processed by the Platform. |
|
Business process metadata |
Any information about a business process. |
|
Registry technical data |
Data on the implementation, configuration, and operation of the Platform. |
|
Historical data |
Data on the changes to the Platform components and processes. |
|
Platform public documentation |
Documentation about the Platform that is published publicly. |
|
System performance data |
Monitoring, tracing, and logging data. |
|
Cryptographic data |
Data related to cryptographic operations. |
|
Digital signatures |
Data used in the process of signing or verifying the data signature on the Platform. |
|
Test data |
Data used exclusively for system testing and containing no real information. |
|
Sensitive settings |
Settings that affect the performance of the Platform and may contain sensitive information. |
|
4. Platform data
4.1. Registry operational zone
Subsystem | Data | System components | Classification level |
---|---|---|---|
User portals subsystem |
|
Confidential information |
|
External traffic management subsystem |
|
Service information |
|
Business process management subsystem |
|
Confidential information |
|
Registry data management subsystem |
|
Confidential information |
|
Registry analytical reporting subsystem |
|
Confidential information |
|
External integrations subsystem |
|
Confidential information |
|
External API simulation subsystem |
|
Service information |
|
Registry excerpt generation subsystem |
|
Confidential information |
|
User notification subsystem |
|
Confidential information |
|
Geodata management subsystem |
|
Confidential information |
|
Registry audit events logging subsystem |
|
Service information |
|
User settings management subsystem |
|
Confidential information |
|
Digital signatures subsystem |
|
Confidential information |
|
Secrets and encryption management subsystem |
|
Service information |
|
Asynchronous messaging subsystem |
|
Confidential information |
|
Relational database management subsystem |
|
Confidential information |
|
Non-relational database management subsystem |
|
Confidential information |
4.2. Registry administrative zone
Subsystem | Data | System components | Classification level |
---|---|---|---|
External traffic management subsystem |
|
Service information |
|
Registry regulations modeling subsystem |
|
Confidential information |
|
Registry regulations deployment subsystem |
|
Service information |
|
Registry’s operational zone service subsystem |
|
Service information |
4.3. Platform operational zone
Subsystem | Data | System components | Classification level |
---|---|---|---|
External traffic management subsystem |
|
Service information |
|
Users and roles management subsystem |
|
Confidential information |
|
Cross-service communication management subsystem |
|
Service information |
|
Secrets and encryption management subsystem |
|
Confidential information |
|
Event logging subsystem |
|
Service information |
|
Event monitoring and notification subsystem |
|
Service information |
|
Request tracing subsystem |
|
Service information |
|
Distributed data storage subsystem |
|
Confidential information, service information |
|
Email messaging subsystem |
|
Confidential information |
|
Backup and restore subsystem |
|
Confidential information |
4.4. Platform administrative zone
Subsystem | Data | System components | Classification level |
---|---|---|---|
Platform and registries management subsystem |
|
Confidential information |
|
Platform and registries deployment and configuration subsystem |
|
Confidential information |
|
Platform documentation |
|
ddm-architecture |
Open information |