Understand the relationship between the Integrations Inventory and the Data Sensitivity Types Inventory - Integrations Inventory and Attributes
Understand the relationship between the Integrations Inventory and the Data Sensitivity Types Inventory
(Chapter 36 of Integrations Inventory and Attributes)
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Data Sensitivities | The sensitivity classifications of the payload transmitted by a specific integration. |
| Per-Integration Classification | Sensitivity is assigned to the flow itself, not merely inferred from the source or target system. |
| Sensitivity Governance | Classification supports encryption, monitoring, privacy impact analysis, regulatory control, and audit scope decisions. |
Quick Q&A
Question: Why classify sensitivity at the integration level?
Read More Below
The Data Sensitivities attribute on each integration record carries the sensitivity classifications of data transmitted through the integration. The Data Sensitivity Types Inventory (not yet published — refer to the IF4IT Enterprise Inventory Management Best Practices document) will govern the formal taxonomy of sensitivity classifications to which these values are mapped.
The relationship is consumption: the Integrations Inventory consumes Data Sensitivity Type definitions to formally classify its integration payloads by sensitivity. Until the Data Sensitivity Types Inventory is published, Data Sensitivities values are documented using the standard value set (PII, PHI, PCI, PFI, Confidential, Regulated, None). When published, Data Sensitivities will carry formal Data Sensitivity Type Semantic ID references through the Related Data Sensitivity Types relationship attribute.
When established, this relationship enables enterprise-level sensitivity governance at the integration level: for any given sensitivity classification, the complete set of integrations that transmit data of that type is immediately queryable. This enables targeted governance of high-sensitivity flows — ensuring encryption, access control, monitoring, and regulatory compliance are applied to every integration that warrants them, and only to those that do.
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Understand the relationship between the Integrations Inventory and the Data Sensitivity Types Inventory | Integrations Inventory and Attributes. https://if4it.org/best-practices/integrations-inventory-and-attributes/understand-the-relationship-between-the-integrations-inventory-and-the-data-sensitivity-types-inventory/ (accessed 2026-09-08).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers