Information Security Awareness

Know your data.
Classify it. Protect it.

Every document you create, store, or share at Ittihad carries a classification level. This guide helps you decide when and how to classify data — and how to handle it safely across its lifecycle.

Doc No. III/DC/DCHP/01 Version 1 Effective 01 Feb 2026 Owner: Information Security Manager
!

Golden rule: if a document or data is not visually marked with a classification, it shall be marked and treated as Restricted until it is appropriately categorized — it must remain within the company.

Interactive Helper

Which classification should I use?

Answer a few quick questions about your document or data, and we'll suggest the right classification level based on the policy.

This helper is guidance only. The Data Owner is responsible for the final classification. When in doubt, treat the data as Restricted and confirm with the Data Owner or the Information Security team.

Know your company & department classification

Select your company and department to see the common document types you handle and the classification level each one needs.

Open the department guide
Purpose & Scope

Why classification matters

The Data Classification & Handling Policy establishes the requirements for appropriate classification, labeling and handling of Ittihad data based on its sensitivity, value and impact throughout its lifecycle.

👥

It applies to you

All employees, contractors and authorized third parties who have access to Ittihad information and information assets are covered by this policy.

📄

All forms of data

The policy covers all forms of data — digital and physical. Every document shall be labelled and visually marked; no exceptions to visual marking are approved for any business document.

🔒

You are responsible

Users are responsible for safeguarding Ittihad information against unauthorized disclosure, modification and destruction. The Data Owner classifies incoming and outgoing information assets.

Classification Levels

The five classification levels

Ittihad classifies information by its sensitivity and the potential impact on the organization if compromised. Click a level of the pyramid to see what it means.

↑ Higher in the pyramid = more protection required

Handling Rules

How each level must be handled

What you can and cannot do with data — from creation to destruction — depends on its classification.

Lifecycle / Activity Public Internal Confidential Restricted Secret
Creation
Labeling / Classification
Storage
Authorized servers
Removable media (USB, external disk, CD-ROM)
Endpoint applications (OneDrive, Teams, Outlook, etc.)
Endpoint LAN (network share drive)
Devices enrolled in Ittihad MDM
Usage & Sharing
Printing & copying 1*
Email — internal 2*2*
Email — external 3*
Unauthorized apps (WhatsApp, Telegram, etc.)
Publication on the Internet
Retention
Secure deletion After 10 years
Destruction
Physical data (printed copies) — standard shredding 4*N/A
Digital data — secure destruction (degaussing / overwriting, etc.)
Legend Authorized    Not authorized 1* — Printing & copying allowed with business justification and the approval of the Data Owner. 2* — Internal sharing via email to individuals/groups other than the intended ones requires business justification and approval of the Data Owner or Top Management. 3* — Allowed to share only with authorized third parties with a signed NDA, and requires approval from the Data Owner. 4* — Disposal using paper shredders.
Access Level Public Internal Confidential Restricted Secret
Data Owner
General Public
General User
Assigned User *****
Authorized Third Parties ***
Legend Access allowed    Access not allowed * — Read access allowed only when there is a business need-to-know and Data Owner approval. The information shall be securely handled and controlled against disclosure to unauthorized parties. ** — Read access allowed only when all of the following are met: business need-to-know, Data Owner approval, and a signed NDA.
User Role Public Internal Confidential Restricted Secret
Data Owner (person applying the label) Yes Yes Yes Yes Yes
Internal User Yes No Yes No No
Legend Allowed to reclassify    Not allowed
Permission Level Usage Rights
Viewer View, Open, Read, View Rights, Reply, Reply All, Allow Macros
Restricted Editor Viewer permission + Save, Edit Content, Edit, Forward
Editor Restricted Editor permission + Save As, Export, Print
Owner Full permission
Do's & Don'ts

Golden rules to remember

The everyday habits that keep Ittihad information safe.

Do

Label every document

All documents shall be labelled and visually marked with the appropriate classification. No exceptions are approved for any business document.

Do

Treat unmarked data as Restricted

If a document is not visually marked, mark and treat it as Restricted until it's appropriately categorized.

Do

Verify email recipients

Check that recipient addresses are correct and that content and attachments are intended for them — especially for Confidential or Restricted information.

Don't

Use WhatsApp, Telegram or Gmail

Unauthorized communication channels shall not be used to transmit Ittihad information — except for information classified as Public.

Don't

Use personal devices outside MDM

Personally owned devices not enrolled in Ittihad MDM must not store or access Confidential, Restricted or Secret information.

Don't

Share Secret data outside

Secret data shall never be shared outside the organization, and internal sharing beyond intended recipients requires Top Management authorization.

Do

Encrypt Restricted & Secret data

Restricted and Secret data shall be encrypted at rest. Restricted data must also be encrypted when transferred (per the Ittihad Data Encryption policy).

Do

Collect your printouts immediately

Confidential / Restricted printouts must be promptly removed and stored securely. If a printer jams, stay until all copies are removed or illegible.

Don't

Give third parties access without an NDA

Any third party requiring access to information classified as anything other than Public must sign a Non-Disclosure Agreement first.

Policy Deep-Dive

Detailed handling requirements

Expand each topic for the full policy requirements.

  • Access to data is based on the principle of least privilege, business need, and the need-to-know basis.
  • Information assets shall be identified, inventoried, valued and classified by the Data Owner, and updated and maintained on an ongoing basis.
  • Data Owners conduct periodic reviews (at least once yearly) of the information assets inventory to ensure classifications remain appropriate. The Infosec Department supports this review.
  • Data Owners are responsible for granting access to other users and must not provide more than what is required.
  • When data is transmitted to a recipient outside the Ittihad network, that third party must agree to maintain a data protection level equivalent to this policy.
  • All data transferred between systems — including over the Internet or by email — must be protected according to its classification. Restricted data must be encrypted when transferred, following the Ittihad Data Encryption policy.
  • Exercise care that recipient email addresses are correct and that message content and attachments are intended for those recipients, using established protection mechanisms for Confidential or Restricted information.
  • When sending hard-copy reports containing Confidential information, limit distribution strictly to the intended individuals and companies.
  • Reproduction of Confidential data by authorized third parties must be kept to the absolute minimum required.
  • Personally owned devices not enrolled under Ittihad MDM must not store or access Confidential, Restricted or Secret information.
  • Secret data shall not be shared outside the organization; sharing within the organization beyond the intended recipients requires authorization from Top Management.
  • Restricted and Secret data shall be encrypted at rest.
  • If you need to store data on a non-standard system or unauthorized application, or outside company systems, work with the Ittihad Infosec team for an acceptable encryption solution per the Ittihad Data Encryption policy.
  • Restricted data stored on removable media or approved portable storage devices must be encrypted.
  • Secret data shall not be stored on removable/portable storage devices at all.
  • Hard copies of Restricted information must be physically secured (e.g., a locked file cabinet or desk) when not in use.
  • Printers and copiers used to process Confidential or Restricted information must be placed in secure locations not easily accessible to unauthorized persons.
  • Confidential or Restricted printouts must be promptly removed from the printer/copier and placed in an appropriate, secure location.
  • If a printer or copier jams while printing Confidential or Restricted information, do not leave the machine until all copies are removed or are no longer legible.
  • This policy also applies to information assets received from third parties. The Ittihad recipient acts as the Data Owner and ensures policy compliance throughout the information's lifecycle.
  • Third parties must, at minimum, implement the data protection controls in this policy before being given access to Ittihad information.
  • Any third party requiring access to information classified as anything other than Public must sign an NDA prior to being given access.
  • The Ittihad information security team conducts regular reviews to ensure policies are enforced and aligned with ISO 27001:2022. Audits may be internal or external.
  • Identified non-compliance results in corrective actions that must be addressed within a specified timeframe; findings feed into continuous improvement and management reviews.
  • Incident response: follow the data classification incident response procedure for reporting data classification violations.
  • Non-compliance or violations may lead to corrective actions under Group HR Policies.
Accountability

Roles & responsibilities

Everyone has a part to play in protecting Ittihad information.

🏛

Top Management

Approve and endorse the policy, ensure resources are available for implementation, and review and support adherence.

📋

Data Classification Committee (DCC)

Oversees development, implementation and enforcement of the policy — ensuring data is classified, protected and managed per business, regulatory and security requirements.

🛡

Information Security Department

Develops and maintains the policy, conducts risk assessments, sets protection levels per classification, implements automated enforcement, monitors compliance and coordinates training.

🖥

IT Department

Implements technical controls to enforce classification levels, safeguards information per established procedures, controls removable-storage access and monitors data flow for leakages.

🔑

Data Owner

Labels data based on its classification (physical and electronic), safeguards it per procedures, and grants the right access level based on least privilege and need-to-know.

👤

Department Heads

Ensure their teams read, acknowledge and comply with the policy, report related security incidents to Information Security, and promote a culture of security.

💼

All Employees

Comply with the policy, apply the appropriate label on information, and safeguard Ittihad information in accordance with established procedures.

🤝

Third Parties

Contractors, vendors and others with access to Ittihad information shall adhere to this policy and all its applicable procedures.