Data classification and handling: who owns it on each service model
What the data is, how it is labelled, where it may be stored and who may move it. No service model moves this to the provider.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
| Platform as a service | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
| Software as a service | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
| Serverless functions and event services | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
| Hosted AI models and AI platforms | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
The clauses each framework attaches
8 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-DSP-04 Data Classification ยท CCM-DSP-19 Data Location |
| ISO/IEC 27017:2015 | ISO/IEC 27017 8.2.2 Labelling of information |
| ISO/IEC 27018:2019 | ISO/IEC 27018 A.12.1 Geographical location of PII |
| SOC 2 Trust Services Criteria | SOC 2 C1.1 Confidential information is identified and protected during receipt, processing, storage |
| ISO/IEC 27001:2022 Annex A | ISO/IEC 27001 5.12 Classification of information |
| CMMC 2.0 | CMMC AC.L2-3.1.3 Control CUI Flow |
| C5 cloud criteria catalogue | C5-PSS-12 Locations of Data Processing and Storage |
CCM-DSP-04 Data ClassificationAssign each dataset a classification reflecting its type and sensitivity.
- The classification scheme with defined levels and criteria
- Classification values recorded against datasets
- Evidence classification drives handling, such as differing controls by level
- Review records for reclassification
- Scheme published but most data left unclassified
- Classification assigned without any control difference between levels
- Datasets classified at creation and never reassessed when their content changed
CCM-DSP-19 Data LocationRecord the physical locations where data is held, processed and backed up, and be able to produce that record.
- The data location record covering processing, storage and backup sites
- The method that keeps it current as infrastructure changes
- Evidence it is available to customers or regulators who may ask
- Coverage of sub-processor locations
- Locations recorded for primary storage with backup and replica locations omitted
- Record based on contracted regions rather than actual deployment
- Sub-processor locations unknown
ISO/IEC 27017 8.2.2 Labelling of informationThe customer should label information according to its classification before and while it is in a cloud service, using labelling the service can carry, and the provider should describe what labelling capability the service offers and whether labels survive processing. Both should agree how labels are handled where the provider's staff can see customer information.
- Labelling scheme applied to cloud-hosted information
- Provider documentation of labelling features
- Test that labels persist through the service
- Labels stripped when information is uploaded to a service that cannot carry them
- No labelling rule for information created inside the cloud service
ISO/IEC 27018 A.12.1 Geographical location of PIIThe public cloud PII processor should specify and document the countries in which PII can possibly be stored, so that the cloud service customer can assess whether the locations meet its legal and contractual obligations.
- Published or contractual list of countries where PII may be stored
- Change notification when locations change
- Locations stated for primary storage but not backups, support access or sub-contractors
- Location list not updated when regions are added
SOC 2 C1.1 Confidential information is identified and protected during receipt, processing, storageIdentifies and maintains confidential information to meet the entity's objectives related to confidentiality
- The definition of confidential information for the entity, including information designated confidential by customers or by contract
- Evidence confidential information is identified across the system, covering where it is received, processed, stored and transmitted
- The protections applied, such as access restriction, encryption and handling rules, tied to the identification
- Evidence of the retention period applied to confidential information and of its basis
- Evidence customers are informed of and agree the confidentiality commitments the entity makes
- Confidentiality commitments made in contracts that were never translated into an internal definition anyone operates against
- Confidential information identified in the primary system while copies in analytics, support tooling and non production environments are unidentified
- Retention undefined, so confidential information is held indefinitely with no basis
- Protection applied uniformly with no relation to the identification, so the identification step adds nothing
ISO/IEC 27001 5.12 Classification of informationClassify information by confidentiality, integrity, availability and interested-party requirements.
- Classification policy
- Classification scheme
- Labeling guidelines
- Asset inventory with classification
- Training records
- Classification levels not aligned with business impact
- Inconsistent labeling across departments
- Missing periodic review of classifications
- Unclear ownership for classification decisions
CMMC AC.L2-3.1.3 Control CUI Flow Level 2Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.
- Documented CUI flow authorizations and approved flow paths
- Firewall, proxy, DLP or gateway rules enforcing those flows
- Data flow diagrams identifying CUI sources, stores and destinations
- Records of blocked or exception-approved transfers
- CUI flows documented but not technically enforced
- Egress to cloud and email paths unmonitored for CUI
- No defined authorization for flows to external partners
C5-PSS-12 Locations of Data Processing and StorageLet the cloud customer choose, from the options available under its contract, the location or country in which its data is processed, stored and backed up, and ensure the cloud architecture itself enforces that choice.
- Contract or ordering options listing the selectable processing and storage regions
- Architecture documentation showing regional placement is technically enforced
- Configuration evidence that backup copies remain within the chosen region
- Record confirming a tenant's actual data placement matches its selection
- Primary storage pinned regionally while backups or replicas leave the region
- Placement honoured by process alone with nothing preventing a cross region deployment
- Support tooling and telemetry data processed outside the selected location
- Customers given a choice with no means of verifying where data actually resides