There are no products listed under this category.
|
The Unified Scoping Guide (USG) is a free resource that is intended to help organizations define the scope of the sensitive data where it is stored, transmitted and/or processed. This guide will refer to both sensitive and regulated data as “sensitive data” to simplify the concept this document is focused on. This scoping guide categorizes system components according to several factors:
|
![]() |
The Unified Scoping Guide (USG) is intended to help organizations define the scope of the sensitive data where it is stored, transmitted and/or processed. This guide will refer to both sensitive and regulated data as “sensitive data” to simplify the concept this document is focused on. This approach is applicable to the following sensitive data types:
When viewing scoping, there are nine (9) zones for sensitive data compliance purpose.
Identifying and addressing the people, processes and technologies around sensitive data is a necessary part of any cybersecurity and data protection (privacy) program. This guide focuses on categorizing the system components that comprise a company's computing environment and helps with the following:
This model categorizes system components according to several factors:
This guide does not define which statutory, regulatory and/or contractual controls are required for each category (see Integrated Controls Management (ICM) model for defining control applicability). Since every organization is different, it is up to each organization and its assessor to determine the nature, extent and effectiveness of each control to adequately mitigate the risks to sensitive data.
There are no products listed under this category.