Data Inventory & Classification Policy

How 7 Minute Security inventories, classifies, and handles data based on its sensitivity.
Version Effective Approved Last reviewed Owner
1.4 October 2, 2026 October 2, 2026 October 2, 2026 Brian Johnson, President

1. Purpose

You can't protect what you don't know you have. This policy establishes how 7MinSec identifies, inventories, and classifies the data it holds, and defines the handling requirements for each classification level.

2. Scope

This policy applies to all data created, received, processed, stored, or transmitted by 7MinSec, regardless of format (digital or physical) or location (cloud, local, or endpoint).

3. Data Classification Levels

Classification Definition Examples
Level 1: Public Information approved for public release with no restrictions Marketing materials, Trust Center policies, published blog posts
Level 2: Internal Non-sensitive business information for internal use only Internal procedures, vendor lists, meeting notes
Level 3: Confidential Sensitive business or client information; unauthorized disclosure would cause harm Client reports, assessment findings, subcontractor agreements, business financials
Level 4: Restricted Highly sensitive data; disclosure could cause significant harm or legal liability Client credentials (during testing), raw vulnerability data, PII, authentication secrets

When in doubt, classify data at the higher level. Reclassification requires approval from Brian Johnson (President).

4. Data Inventory

Data Type Classification Primary Location Retention Period
Client contact information Level 2: Internal Productivity suite (email/contacts) Duration of relationship + 3 years
Active engagement working files Level 3: Confidential Cloud file storage (access-restricted) 60 days post-engagement, then purged
Penetration test raw output & notes Level 4: Restricted Cloud file storage, report authoring platform, or vulnerability scanning host (all access-restricted) 60 days post-engagement, then purged
Client credentials (during testing) Level 4: Restricted Password manager (dedicated vault) Deleted immediately at engagement close
Final report deliverables Level 3: Confidential Cold storage archive 3 years, then securely deleted
Subcontractor partnership agreements Level 3: Confidential Productivity suite / secure storage Duration of relationship + 3 years
7MinSec internal credentials Level 4: Restricted Password manager Active, rotated per access policy
Marketing and public content Level 1: Public 7MinSec website / productivity suite Indefinite

5. Handling Requirements by Classification

Requirements are cumulative. Each level carries every requirement of the levels below it, plus its own.

5.1 Level 1: Public

  • No special handling required
  • May be freely shared externally

5.2 Level 2: Internal

  • Share only with 7MinSec personnel and subcontractors on a need-to-know basis
  • Store in 7MinSec-managed systems (productivity suite, cloud file storage)

5.3 Level 3: Confidential

  • Access restricted to personnel directly involved in the relevant engagement
  • Must be transmitted as expiring, password-protected, encrypted links, never as email attachments
  • Must be stored in access-controlled locations (cloud file storage with restricted sharing, the report authoring platform, or cold storage)
  • Must be encrypted at rest
  • Labeled "CONFIDENTIAL" on documents where practical

5.4 Level 4: Restricted

  • Access limited to the minimum number of personnel required
  • Client credentials stored exclusively in a dedicated password manager vault and deleted at engagement close
  • Raw vulnerability data stored on the report authoring platform (address-restricted), on the self-hosted vulnerability scanning host (network-isolated), or in cloud file storage with strict access controls
  • Never transmitted via email under any circumstances
  • Never stored on unmanaged or personal devices beyond the duration of active work
  • Must be encrypted at rest
  • Where transmission is unavoidable, use the same expiring, password-protected encrypted links required at Level 3
  • Labeled "RESTRICTED" on all documents

6. Approved Storage Platforms

Platform Purpose Approved Classification
Cloud productivity suite Internal email, calendar, business documents Levels 1 to 3
Cloud file storage Active engagement working files Levels 1 to 3 (Level 4 only in restricted-access folders)
Report authoring platform (self-hosted, address-restricted) Penetration test report authoring and raw findings Levels 3 and 4
Vulnerability scanning host (self-hosted, network-isolated) Authenticated and external vulnerability scanning, and the raw scan output it produces Level 4
Enterprise password manager All credential storage Level 4
Cold storage archive Long-term report retention Level 3
Encrypted, expiring link delivery Secure delivery of reports and credentials to clients Levels 3 and 4 (transmission only)

Storing 7MinSec or client data on unapproved platforms (personal cloud storage, USB drives, personal email, etc.) is prohibited without explicit approval from Brian Johnson (President). Subcontractor data handling obligations are established in the 7MinSec Partnership Agreement and reaffirmed annually via the Subcontractor Security Acknowledgment form.

7. Data Disposal

When data reaches the end of its retention period, it must be disposed of securely:

  • Digital files: secure deletion using approved tools (file shredding / verified overwrite)
  • Cloud storage: permanent deletion confirmed (emptying trash/recycle bin)
  • Credentials: revoked and deleted from the password manager, not just archived

Disposal is logged for Level 3 and Level 4 data.

8. Policy Review

This policy and the data inventory table are reviewed annually, or whenever a new data category, platform, or significant business change occurs. The current version is published in the 7MinSec Trust Center.

Change Log

This log records all changes made to this policy over time.

Version Date Author Description of Change
1.0 September 1, 2026 Brian Johnson Initial release.
1.1 September 23, 2026 Brian Johnson No substantive change. Version aligned with the rest of the policy suite following the September 2026 review.
1.1.1 September 24, 2026 Brian Johnson Editorial pass ahead of publication: em dashes removed throughout, including from the classification level labels, which now read Level 1: Public and so on. No requirement, classification, or retention period changed.
1.2 September 28, 2026 Brian Johnson Reviewed by an independent assessor against the CIS Controls with no changes required. Version aligned with the rest of the policy suite.
1.3 October 2, 2026 Brian Johnson Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. Added the self-hosted vulnerability scanning host as an approved Level 4 location in Sections 4, 5.4 and 6, carrying the same 60 day post-engagement purge as other raw output. Raw scan output of client environments was already held there, which Sections 5.4 and 6 did not permit. Corrected the approved platforms table so the expiring encrypted link service shows Levels 3 and 4 for transmission, matching Section 5.4, which already permitted Level 4 transmission where unavoidable.
1.4 October 2, 2026 Brian Johnson No change to this policy. Version aligned with the rest of the suite.

Last reviewed: October 2, 2026