Data and Information Inventory and Attributes - Understand the relationship between the Data and Information Inventory and the Data Sensitivity Types Inventory
Data and Information Inventory and Attributes
Chapter 35. Understand the relationship between the Data and Information Inventory and the Data Sensitivity Types Inventory
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Sensitivity Type | A Sensitivity Type is a governed classification value such as public, internal, confidential, restricted, or regulated. Referencing a separate inventory keeps classifications standardized. |
| Control Inheritance | Control inheritance means that classification obligations follow the data type wherever it appears. Applications, integrations, and stores handling the type inherit the relevant protection expectations. |
| Regulatory Protection | Regulatory protection connects sensitivity classification to privacy, security, retention, and compliance requirements. It helps avoid inconsistent controls for the same data type across systems. |
Quick Q&A
Question: How does the Data Sensitivity Types Inventory strengthen data governance?
Read More Below
The Sensitivity Classification attribute on every Data and Information type record references the Data Sensitivity Types Inventory (not yet published — refer to the IF4IT Enterprise Inventory Management Best Practices document). The Data Sensitivity Types Inventory defines the governed sensitivity classifications — PII, PHI, PCI, PFI, and others — with their domains, governing frameworks, regulatory obligations, and scope. This inventory applies those classifications at the data type level.
When the Data Sensitivity Types Inventory is published, Sensitivity Classification values will carry formal Semantic ID references. Until then, the standard value set (PII, PHI, PCI, PFI, Confidential, Regulated, None) is used as plain text. The Data Sensitivity Types Inventory baseline has been designed and is documented in REFERENCE_DATA_INVENTORY_NOTES.md for reference.
When established, this relationship enables enterprise-level sensitivity governance queries: for any sensitivity classification, the complete set of Data and Information types carrying that classification is queryable — and from those types, the complete set of integrations, applications, capabilities, and data stores handling sensitive content is traversable through the Enterprise Model graph.
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Understand the relationship between the Data and Information Inventory and the Data Sensitivity Types Inventory | Data and Information Inventory and Attributes. https://if4it.org/best-practices/data-and-information-inventory-and-attributes/understand-the-relationship-between-the-data-and-information-inventory-and-the-data-sensitivity-types-inventory/ (accessed 2026-07-22).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers