Implementing Data Classification and Grading: A Practical Guide

The article explains why data classification and grading are essential for data security governance, outlines the legal backdrop, describes a six‑step methodology, and presents detailed case studies from a municipal HR bureau, a big‑data bureau and a bank that illustrate how the process is planned, executed and operationalized with a self‑built discovery platform.

Smart Sea Tide
Smart Sea Tide
Smart Sea Tide
Implementing Data Classification and Grading: A Practical Guide

Data classification and grading form the foundation of data security governance. Recent laws such as the Data Security Law, Personal Information Protection Law, and draft regulations on network data management require organizations to establish classification and grading systems. Industry standards and regional guidelines (e.g., Shanghai, Wuhan, Zhejiang) also provide reference frameworks.

Despite the regulatory push, many organizations struggle with the practice: there are few standards, existing standards are hard to apply, and once implemented, the results are difficult to use.

Methodology

Based on legal requirements, standards research, consulting expertise, and mature tools, a six‑step process is proposed:

Pre‑visit research : Conduct field visits and interviews to uncover business data pain points and produce research conclusions.

Organizational setup : Form a data‑asset leadership group (strategic decisions) and a working group (execution, coordination, evaluation).

Data asset inventory : Scan data sources, automatically capture database details (IP, port, type), recognize data formats and meanings, and generate a unified data‑resource list covering department, system, data type, security level, description, volume, storage location, retention, processing, external provision, and lifecycle security measures.

Data classification : Apply public data classification dimensions (management, business application, security, data object) and, after considering laws and business goals, classify data primarily by data‑object dimension.

Data grading : Determine security levels (1‑4) based on the “high‑as‑strict” principle; adjust levels according to data sensitivity, aggregation, volume, timeliness, and de‑identification. The final grading for the HR case resulted in three levels: non‑sensitive, low‑sensitive, and moderately sensitive.

Application and operation : Use a self‑developed “dark data discovery and classification platform” that combines automated scanning, model matching, statistics, and machine learning to improve discovery accuracy, shorten project cycles, and support continuous iteration of classification rules.

Case Study – Municipal HR Bureau

Under a provincial directive to inventory data assets, the bureau followed the six‑step approach, establishing a leadership group and a working group. The resulting classification scheme includes seven top‑level categories (personal information, business information, organization information, object information, system data, basic types, statistics) and 45 second‑level sub‑categories. Data grading was adjusted to three levels (non‑sensitive, low‑sensitive, moderately sensitive) to align with sharing and security requirements.

Case Study – City Big‑Data Bureau

Using the Public Data Classification Guide , the Population Integrated Database Specification , and the Personal Information Security Specification , the bureau built a reference standard and embedded it into the classification tool. The process produced 11 second‑level and 50 third‑level categories, identified 5 sensitivity levels, and catalogued over 30 schemas, ~1,000 tables, and ~25,000 fields. More than 40% of tables contained sensitive fields, enabling targeted security controls.

Case Study – Bank

Following the People’s Bank of China’s 2020 “Financial Data Security Grading Guide,” the bank used the same platform to classify 51 tables and 2,409 fields. The platform already includes the financial‑industry grading standard (JR/T 0197‑2020). The tool automatically scanned, identified business types, discovered sensitive fields, and generated a visual classification report that feeds into security products and data‑resource management platforms.

Benefits and Conclusions

The platform’s high automation reduces manual effort, continuously refines classification rules, and provides visual asset inventories and grading reports. Uniform grading facilitates secure data sharing across departments and industries, supports data‑driven initiatives, and lays the groundwork for lifecycle data protection.

Overall, a structured, six‑step methodology combined with automated discovery tools enables organizations to translate regulatory requirements into actionable data classification and grading practices.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

case studyinformation securityData Governancedata classificationgovernmentbank
Smart Sea Tide
Written by

Smart Sea Tide

Sharing cutting‑edge big data and AI technologies, with occasional lifestyle insights.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.