Skip to main content

AView from the CISO: Insights from the Data Classification Process

Publication ,  Journal Article
Bradford, M; Taylor, EZ; Seymore, M
Published in: Journal of Information Systems
March 1, 2022

Data security is a critical concern for organizations. In a rush to protect data, some IT managers overlook the important first step of data classification and instead focus on implementing the strictest controls on all data to reduce risk. To investigate organizational processes surrounding data classification, we conduct interviews with 27 CISOs in 23 organizations. We develop a model that identifies the common themes of data classification and their interrelationships. The most common driver for data classification is compliance with data privacy regulations and security standards. Collaboration and employee education are essential to the process. Increases in employee awareness of data security risk and improvements in data hygiene are outcomes. Challenges to data classification include the increase in IT landscape complexity, maintenance of an accurate data inventory, immaturity of automated tools, limited resources, and user compliance. Our model provides insights for practitioners and identifies areas of interest for researchers.

Duke Scholars

Published In

Journal of Information Systems

DOI

EISSN

1558-7959

ISSN

0888-7985

Publication Date

March 1, 2022

Volume

36

Issue

1

Start / End Page

201 / 218

Related Subject Headings

  • 4609 Information systems
  • 3501 Accounting, auditing and accountability
  • 1503 Business and Management
  • 1501 Accounting, Auditing and Accountability
  • 0806 Information Systems
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Bradford, M., Taylor, E. Z., & Seymore, M. (2022). AView from the CISO: Insights from the Data Classification Process. Journal of Information Systems, 36(1), 201–218. https://doi.org/10.2308/ISYS-2020-054
Bradford, M., E. Z. Taylor, and M. Seymore. “AView from the CISO: Insights from the Data Classification Process.” Journal of Information Systems 36, no. 1 (March 1, 2022): 201–18. https://doi.org/10.2308/ISYS-2020-054.
Bradford M, Taylor EZ, Seymore M. AView from the CISO: Insights from the Data Classification Process. Journal of Information Systems. 2022 Mar 1;36(1):201–18.
Bradford, M., et al. “AView from the CISO: Insights from the Data Classification Process.” Journal of Information Systems, vol. 36, no. 1, Mar. 2022, pp. 201–18. Scopus, doi:10.2308/ISYS-2020-054.
Bradford M, Taylor EZ, Seymore M. AView from the CISO: Insights from the Data Classification Process. Journal of Information Systems. 2022 Mar 1;36(1):201–218.

Published In

Journal of Information Systems

DOI

EISSN

1558-7959

ISSN

0888-7985

Publication Date

March 1, 2022

Volume

36

Issue

1

Start / End Page

201 / 218

Related Subject Headings

  • 4609 Information systems
  • 3501 Accounting, auditing and accountability
  • 1503 Business and Management
  • 1501 Accounting, Auditing and Accountability
  • 0806 Information Systems