Integrations Inventory and Attributes - Security attributes for the Integrations Inventory
Integrations Inventory and Attributes
Chapter 18. Security attributes for the Integrations Inventory
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Data Sensitivities | Data Sensitivities captures whether the integration transmits PII, PHI, PCI, PFI, Confidential, Regulated, or non-sensitive data. |
| Per-Flow Governance | Sensitivity at the integration level avoids overgeneralizing from application-level classifications and supports more precise privacy, security, and compliance controls. |
Quick Q&A
Question: Why should sensitivity be tracked per integration instead of only per application?
Read More Below
Security attributes capture the sensitivity of data moving through this Integration and the access controls governing the integration channel.
| Attribute Name | Maturity | Description and Notes |
|---|---|---|
Data Sensitivities [Multi-Value] | Crawl | Description — The sensitivity classifications of the data or information transmitted through this integration. A single integration may carry multiple sensitivity types simultaneously. Benefit(s) — Enables per-integration sensitivity governance rather than entity-level approximation. Two applications may have five integrations between them but only one that transmits PII — this attribute makes that distinction explicit and actionable for privacy impact assessments, regulatory audits, and encryption enforcement. Source — Manual. Examples — PII; PHI; PCI; PFI; Confidential; Regulated; None Notes — Valid values: PII (Personally Identifiable Information), PHI (Protected Health Information), PCI (Payment Card Industry data), PFI (Protected Financial Information), Confidential (internal sensitive but not regulated), Regulated (subject to regulatory handling requirements not covered by the above), None (no sensitive data transmitted). Separate multiple values with semicolons. None is an explicit governance statement — do not leave this field blank. |
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Security attributes for the Integrations Inventory | Integrations Inventory and Attributes. https://if4it.org/best-practices/integrations-inventory-and-attributes/security-attributes-for-the-integrations-inventory/ (accessed 2026-07-20).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers