Blog

Data Access Security Sensitive & Regulated Data Classification

Author

  • hanan_levy

    SailPoint

Data Access Security now supports the classification and cataloging of regulated and sensitive data

Regulated Data Classification enables SailPoint’s ISC customers to quickly, easily, and consistently discover, govern, and secure sensitive unstructured data governed by Data Protection and Privacy regulations. Enabling customers to establish the necessary controls to protect sensitive data, and the appropriate governance processes to be able to address regulation requirements, respond to audits, and reduce the risk of financial penalties, from compliance fines, ransom fees in case of a breach, and reputation damage.

Customers can now leverage Data Access Security's out-of-the-box data classification policies and predefined classifications rules within their environment to automatically classify and catalog regulated sensitive data, including personal identifiable information (PII), payment card information (PCI), medical records regulated under HIPAA, and information covered under data protection laws like GDPR. Organizations can also catalog content based on internal identifiers and dynamic policies to secure intellectual property, parented information, and classified restricted content.

Who is affected?

All Identity Security Cloud customers who purchased Data Access Security can take advantage of the Data Classification capabilities to be able to classify and catalog personal, sensitive and regulated data.

Action Required

In order to take advantage of Data Access Security Data Classification within their environments, customers will need to deploy Data Access Security Data Classification Collection Virtual Appliances clusters to deploy collector instances that perform the classification collection task. Administrators will need to create and deploy dedicated Data Access Security Data Classification Collection Virtual Appliance (VA) Clusters and worker VA instances to perform classification data collection.

Please refer to the Data Access Security documentation for information about deploying Data Classification Collectors.

Important Dates

Data Access Security’s Sensitive Data Classification is now available to all new Data Access Security customers, and required Data Classification Collection Virtual Appliances (VAs) installed to perform classifications.

Existing customers will need to deploy Data Classification Collection Virtual Appliances to switch over to VA-bases classification - when Sensitive Data Classification is enabled.

For existing customers, Sensitive Data Classification will be enabled on April 15th. At that point - classification will require VA-bases classification and will not be to properly execute without VA-based collectors.

Customers are advised to take the necessary steps in advance to prepare for the migration.

  • Before April 15th

  • On April 15th

    • Once Sensitive Data Classification is enabled follow the steps detailed in the Data Access Security documentation to create a Data Classification Collection VA cluster, and associate the required Virtual Appliances.

    • Follow the steps detailed in "Adding Applications" section in the Data Access Security documentation to associate governed applications with the Data Classification Collection VA cluster.

    • In Data Access Security, under Compliance > Data Classification > Policies, ensure that you enable the policy you would like to apply during the classification.
    • Once the governed applications are associated with Data Classification Collection VA cluster(s), and you've enabled the appropriate policies, you will be able to resume executing Data Classification tasks.