This policy sorts information into levels. It states how to handle each level and how to encrypt it.
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
| Level | What it covers | Handling rule |
|---|---|---|
| Restricted | Personal data, buyer contact data, access tokens, API keys, credentials, financial records | Encrypt at rest and in transit. Access by named person only. Never send by plain email. Never place in source code. |
| Confidential | Merchant business data, order data, pricing, source code, contracts | Encrypt in transit. Store in a private repository or a private bucket. Share only with a business need. |
| Internal | Internal notes, drafts, configuration that holds no secret | Keep inside company systems. Do not publish. |
| Public | Published policies, marketing pages, public documentation | No restriction. |
Store Restricted data in a location that only holds Restricted data. Name the location clearly. Do not mix levels in one folder.
The Managing Member reviews this policy one time each year.