Know your data.
Classify it. Protect it.
Every document you create, store, or share at Ittihad carries a classification level. This guide helps you decide when and how to classify data — and how to handle it safely across its lifecycle.
Which classification should I use?
Answer a few quick questions about your document or data, and we'll suggest the right classification level based on the policy.
This helper is guidance only. The Data Owner is responsible for the final classification. When in doubt, treat the data as Restricted and confirm with the Data Owner or the Information Security team.
Know your company & department classification
Select your company and department to see the common document types you handle and the classification level each one needs.
Why classification matters
The Data Classification & Handling Policy establishes the requirements for appropriate classification, labeling and handling of Ittihad data based on its sensitivity, value and impact throughout its lifecycle.
It applies to you
All employees, contractors and authorized third parties who have access to Ittihad information and information assets are covered by this policy.
All forms of data
The policy covers all forms of data — digital and physical. Every document shall be labelled and visually marked; no exceptions to visual marking are approved for any business document.
You are responsible
Users are responsible for safeguarding Ittihad information against unauthorized disclosure, modification and destruction. The Data Owner classifies incoming and outgoing information assets.
The five classification levels
Ittihad classifies information by its sensitivity and the potential impact on the organization if compromised. Click a level of the pyramid to see what it means.
↑ Higher in the pyramid = more protection required
How each level must be handled
What you can and cannot do with data — from creation to destruction — depends on its classification.
| Lifecycle / Activity | Public | Internal | Confidential | Restricted | Secret |
|---|---|---|---|---|---|
| Creation | |||||
| Labeling / Classification | ✓ | ✓ | ✓ | ✓ | ✓ |
| Storage | |||||
| Authorized servers | ✓ | ✓ | ✓ | ✓ | ✓ |
| Removable media (USB, external disk, CD-ROM) | ✓ | ✓ | ✓ | ✗ | ✗ |
| Endpoint applications (OneDrive, Teams, Outlook, etc.) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Endpoint LAN (network share drive) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Devices enrolled in Ittihad MDM | ✓ | ✓ | ✓ | ✓ | ✓ |
| Usage & Sharing | |||||
| Printing & copying | ✓ | ✓ | ✓ | ✓1* | ✗ |
| Email — internal | ✓ | ✓ | ✓ | ✓2* | ✓2* |
| Email — external | ✓ | ✓ | ✓ | ✓3* | ✗ |
| Unauthorized apps (WhatsApp, Telegram, etc.) | ✓ | ✗ | ✗ | ✗ | ✗ |
| Publication on the Internet | ✓ | ✗ | ✗ | ✗ | ✗ |
| Retention | |||||
| Secure deletion | After 10 years | ||||
| Destruction | |||||
| Physical data (printed copies) — standard shredding | ✓ | ✓ | ✓ | ✓4* | N/A |
| Digital data — secure destruction (degaussing / overwriting, etc.) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Access Level | Public | Internal | Confidential | Restricted | Secret |
|---|---|---|---|---|---|
| Data Owner | ✓ | ✓ | ✓ | ✓ | ✓ |
| General Public | ✓ | ✗ | ✗ | ✗ | ✗ |
| General User | ✓ | ✓ | ✗ | ✗ | ✗ |
| Assigned User | ✓ | ✓ | ✓* | ✓** | ✓** |
| Authorized Third Parties | ✓ | ✗ | ✓* | ✓** | ✗ |
| User Role | Public | Internal | Confidential | Restricted | Secret |
|---|---|---|---|---|---|
| Data Owner (person applying the label) | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Internal User | ✓ Yes | ✗ No | ✓ Yes | ✗ No | ✗ No |
| Permission Level | Usage Rights |
|---|---|
| Viewer | View, Open, Read, View Rights, Reply, Reply All, Allow Macros |
| Restricted Editor | Viewer permission + Save, Edit Content, Edit, Forward |
| Editor | Restricted Editor permission + Save As, Export, Print |
| Owner | Full permission |
Golden rules to remember
The everyday habits that keep Ittihad information safe.
Label every document
All documents shall be labelled and visually marked with the appropriate classification. No exceptions are approved for any business document.
Treat unmarked data as Restricted
If a document is not visually marked, mark and treat it as Restricted until it's appropriately categorized.
Verify email recipients
Check that recipient addresses are correct and that content and attachments are intended for them — especially for Confidential or Restricted information.
Use WhatsApp, Telegram or Gmail
Unauthorized communication channels shall not be used to transmit Ittihad information — except for information classified as Public.
Use personal devices outside MDM
Personally owned devices not enrolled in Ittihad MDM must not store or access Confidential, Restricted or Secret information.
Share Secret data outside
Secret data shall never be shared outside the organization, and internal sharing beyond intended recipients requires Top Management authorization.
Encrypt Restricted & Secret data
Restricted and Secret data shall be encrypted at rest. Restricted data must also be encrypted when transferred (per the Ittihad Data Encryption policy).
Collect your printouts immediately
Confidential / Restricted printouts must be promptly removed and stored securely. If a printer jams, stay until all copies are removed or illegible.
Give third parties access without an NDA
Any third party requiring access to information classified as anything other than Public must sign a Non-Disclosure Agreement first.
Detailed handling requirements
Expand each topic for the full policy requirements.
- Access to data is based on the principle of least privilege, business need, and the need-to-know basis.
- Information assets shall be identified, inventoried, valued and classified by the Data Owner, and updated and maintained on an ongoing basis.
- Data Owners conduct periodic reviews (at least once yearly) of the information assets inventory to ensure classifications remain appropriate. The Infosec Department supports this review.
- Data Owners are responsible for granting access to other users and must not provide more than what is required.
- When data is transmitted to a recipient outside the Ittihad network, that third party must agree to maintain a data protection level equivalent to this policy.
- All data transferred between systems — including over the Internet or by email — must be protected according to its classification. Restricted data must be encrypted when transferred, following the Ittihad Data Encryption policy.
- Exercise care that recipient email addresses are correct and that message content and attachments are intended for those recipients, using established protection mechanisms for Confidential or Restricted information.
- When sending hard-copy reports containing Confidential information, limit distribution strictly to the intended individuals and companies.
- Reproduction of Confidential data by authorized third parties must be kept to the absolute minimum required.
- Personally owned devices not enrolled under Ittihad MDM must not store or access Confidential, Restricted or Secret information.
- Secret data shall not be shared outside the organization; sharing within the organization beyond the intended recipients requires authorization from Top Management.
- Restricted and Secret data shall be encrypted at rest.
- If you need to store data on a non-standard system or unauthorized application, or outside company systems, work with the Ittihad Infosec team for an acceptable encryption solution per the Ittihad Data Encryption policy.
- Restricted data stored on removable media or approved portable storage devices must be encrypted.
- Secret data shall not be stored on removable/portable storage devices at all.
- Hard copies of Restricted information must be physically secured (e.g., a locked file cabinet or desk) when not in use.
- Printers and copiers used to process Confidential or Restricted information must be placed in secure locations not easily accessible to unauthorized persons.
- Confidential or Restricted printouts must be promptly removed from the printer/copier and placed in an appropriate, secure location.
- If a printer or copier jams while printing Confidential or Restricted information, do not leave the machine until all copies are removed or are no longer legible.
- This policy also applies to information assets received from third parties. The Ittihad recipient acts as the Data Owner and ensures policy compliance throughout the information's lifecycle.
- Third parties must, at minimum, implement the data protection controls in this policy before being given access to Ittihad information.
- Any third party requiring access to information classified as anything other than Public must sign an NDA prior to being given access.
- The Ittihad information security team conducts regular reviews to ensure policies are enforced and aligned with ISO 27001:2022. Audits may be internal or external.
- Identified non-compliance results in corrective actions that must be addressed within a specified timeframe; findings feed into continuous improvement and management reviews.
- Incident response: follow the data classification incident response procedure for reporting data classification violations.
- Non-compliance or violations may lead to corrective actions under Group HR Policies.
Roles & responsibilities
Everyone has a part to play in protecting Ittihad information.
Top Management
Approve and endorse the policy, ensure resources are available for implementation, and review and support adherence.
Data Classification Committee (DCC)
Oversees development, implementation and enforcement of the policy — ensuring data is classified, protected and managed per business, regulatory and security requirements.
Information Security Department
Develops and maintains the policy, conducts risk assessments, sets protection levels per classification, implements automated enforcement, monitors compliance and coordinates training.
IT Department
Implements technical controls to enforce classification levels, safeguards information per established procedures, controls removable-storage access and monitors data flow for leakages.
Data Owner
Labels data based on its classification (physical and electronic), safeguards it per procedures, and grants the right access level based on least privilege and need-to-know.
Department Heads
Ensure their teams read, acknowledge and comply with the policy, report related security incidents to Information Security, and promote a culture of security.
All Employees
Comply with the policy, apply the appropriate label on information, and safeguard Ittihad information in accordance with established procedures.
Third Parties
Contractors, vendors and others with access to Ittihad information shall adhere to this policy and all its applicable procedures.