This message was posted by a user wishing to remain anonymous
Stephen,
We use a brief version of this in Inherent risk questionnaire to rank Information sharing. NPI includes bank confidential not just customer PII (NPI foreign data storage, NPI domestic data storage, NPI via remote support, No NPI data sharing)
We also then detail at the vendor level
Data Classification (Restricted, Internal Use Confidential, Public, None)
Data Context (Narrative description of the data shared. This should describe the subset of data being exposed e.g. Mortgage customers)
Data Density (Small, Medium, Large) this measure is related to the context description e.g. by being based on the context we can see Large in terms of the mortgage customers. vs the same record exposure might be small in terms of all customers.
Data Classification, Context, and Density shape the perspective for assessment scope and qc review. qc would flag for challenge Large data density if the Risk Impacts are Low (those appear inconsistent) ...