ConceptioArchiveNIST
NISTpublic full text

NIST SP 1800-39 ipd: Data Classification Practices

William Newhouse (NIST); Murugiah Souppaya (NIST); John Kent (MITRE); Kenneth Sandlin (MITRE); Ryan Williams (MITRE); Karen Kent (Trusted Cyber Annex); Mark Evans (ActiveNav); Jimmy Katz (ActiveNav); John Dombroski (IBM); Harmeet Singh (IBM); Neville Jones (Janusnet); Helen Farrell (Janusnet); Pablo Blasco (Thales TCT); Jane Gilbert (Thales TCT); D'Nan Godfrey (Thales TCT); Matt Jochim (Thales TCT); Rich Johnson (Thales TCT); Ludmila Rinaudo (Thales TCT); Gina Scinta (Thales TCT); Patrick Greer (Trellix); Wilson Patton (Trellix); Jason White (Trellix) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
cybersecuritypracticeimplementationguidenccoenist
cybersecurity practice, NCCoE, implementation guide, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 1800-39 (Initial Public Draft) Data Classification Practices Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: February 12, 2026 Comments Due: March 30, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Author(s) William Newhouse (NIST) , Murugiah Souppaya (NIST) , John Kent (MITRE) , Kenneth Sandlin (MITRE) , Ryan Williams (MITRE) , Karen Kent (Trusted Cyber Annex) , Mark Evans (ActiveNav) , Jimmy Katz (ActiveNav) , John Dombroski (IBM) , Harmeet Singh (IBM) , Neville Jones (Janusnet) , Helen Farrell (Janusnet) , Pablo Blasco (Thales TCT) , Jane Gilbert (Thales TCT) , D'Nan Godfrey (Thales TCT) , Matt Jochim (Thales TCT) , Rich Johnson (Thales TCT) , Ludmila Rinaudo (Thales TCT) , Gina Scinta (Thales TCT) , Patrick Greer (Trellix) , Wilson Patton (Trellix) , Jason White (Trellix) Announcement This guide, Data Classification Practices , demonstrates how organizations can discover, identify, and label unstructured data using data classification practices. Performing Data Classification Practices allows an organization to know its data and apply technologies that minimize the risk of valuable or sensitive data being lost or mismanaged. Data Classification Practices prepare an organization for the use of emerging security measures—including Zero Trust Architecture, quantum-safe cryptography, and AI model training that requires labeled data. This 1800-series NIST publication documents how the NCCoE and its collaborators created a synthetic dataset and used commercially available data classification tools to discover, identify, and label unstructured data. Background Organizations trying to protect sensitive data from unauthorized access or disclosure need to understand all their data—structured and unstructured—across all the places that data might live. Sensitive data, such as PII, may reside in a variety of systems, digital conversations, data lakes, and file repositories. Identifying and classifying sensitive data is crucial for minimizing data loss and preparing organizations for advanced security measures, including Zero Trust Architecture, quantum-safe cryptography, and AI model training. The goal of this project is to demonstrate data classification practices for identifying and understanding sensitive unstructured data. This NIST Cybersecurity Practice Guide provides users with the information they need to apply data classification practices to discover, identify, and label sensitive unstructured data using commercially available data classification technology. By doing so, organizations can better understand their data and minimize the risk of losing or mismanaging valuable or sensitive data. The public comment period ends on March 30, 2026. Abstract This guide demonstrates how organizations can discover, identify and label unstructured data using data classification practices. Performing Data Classification Practices allows an organization to know its data and apply technologies that minimize the risk of valuable or sensitive data being lost or mismanaged. Data Classification Practices prepare an organization for the use of emerging security measures—including Zero Trust Architecture, quantum-safe cryptography, and AI model training that requires labeled data. This 1800-series NIST publication documents how the NCCoE and its collaborators created a synthetic dataset and used commercially available data classification tools to discover, identify and label unstructured data. This guide demonstrates how organizations can discover, identify and label unstructured data using data classification practices. Performing Data Classification Practices allows an organization to know its data and apply technologies that minimize the risk of valuable or sensitive data being lost or... See full abstract This guide demonstrates how organizations can discover, identify and label unstructured data using data classification practices. Performing Data Classification Practices allows an organization to know its data and apply technologies that minimize the risk of valuable or sensitive data being lost or mismanaged. Data Classification Practices prepare an organization for the use of emerging security measures—including Zero Trust Architecture, quantum-safe cryptography, and AI model training that requires labeled data. This 1800-series NIST publication documents how the NCCoE and its collaborators created a synthetic dataset and used commercially available data classification tools to discover, identify and label unstructured data. Hide full abstract Keywords synthetic unstructured data ; data pillar of zero trust ; data types, data labels ; data classification practices Control Families None selected Documentation Publication: Download URL Supplemental Material: Submit comments Project homepage Document History: 02/12/26: SP 1800-39 (Draft) Topics Security and Privacy asset management , general security & privacy , media protection , post-quantum cryptography , zero trust Technologies artificial intelligence HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2847 · SHA-256 a8ffddc229b9b5bd
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.