All pages
Powered by GitBook
1 of 4

Loading...

Loading...

Loading...

Loading...

Manage Classification Frameworks

Private preview

This feature is only available to select accounts. To activate classification frameworks without the private preview feature, use the .

Requirements:

  • SDD enabled and turned on

  • Frameworks enabled

    • To use the classification frameworks UI, enable the

  • Registered

  • Immuta permission GOVERNANCE

To activate a classification framework,

  1. Navigate to Discover and select the Classification tab.

  2. Click the more actions icon in the Actions column for the framework you want to activate.

  3. Select Activate.

Repeat this process for all frameworks relevant to your data. See the for information on Immuta's built-in frameworks.

  1. Navigate to Discover and select the Classification tab.

  2. Click the more actions icon in the Actions column for the framework you want to activate.

  3. Select Deactivate.

To activate a framework using the Immuta API, see the .

Activate a classification framework

Deactivate a classification framework

Activate and manage classification frameworks using the API

Additional compliance frameworks and the data inventory dashboard
Snowflake, Databricks, Redshift, or Starburst (Trino) data sources
Frameworks reference guide
Frameworks API reference page
/frameworks endpoint in the API

How-to Guides

Adjust Identification and Classification Framework Tags

Requirements:

  • SDD enabled

  • Frameworks enabled

    • To use the classification frameworks UI, enable the

  • Registered

  • Immuta permission GOVERNANCE

Immuta Discover provides identification frameworks out-of-the-box to recognize and tag data, and Discover also provides classification frameworks out-of-the-box to categorize and classify data. These frameworks are all generic to industry practices and should be customized to each organization's specific needs.

Tune SDD frameworks and identifiers first to adjust where Discovered tags are applied. Because classification frameworks apply classification tags from the Discovered tags, tuning SDD should come first and will have trickle-down effects on classification. Customizing SDD requires some initial work but will automate data tagging for all data sources in the future.

Follow the steps below to tune SDD from the Default Framework:

  1. .

  2. .

  3. : This will remove the tags from any previous identification frameworks and re-run identification with your new framework. From here, either continue to edit identifiers to reconfigure the applied tags, or if you are happy with the results, proceed to the next step.

After SDD has applied entity tags, classification frameworks will automatically reapply their tags to account for any changes to Discovered tags. It may be necessary to adjust the classification tags based on your organization's data, security, and compliance needs.

Requirements:

  • Immuta permission AUDIT

  • Snowflake integration (If you are using Databricks, use the how-to below.)

Use the Detect dashboards to review queries at different sensitivity levels and review the tags that have been applied to your data source columns to understand the tags that Immuta applied there:

  1. Have an Immuta user subscribed to a data source make multiple queries to a data source in Snowflake. The user should query both non-sensitive and sensitive data.

  2. Navigate to the Audit page and click ↻Load Audit Events to pull in queries made in Snowflake.

  3. Navigate to the Events (Beta) page. Note that Snowflake has a 15-minute data latency for all audit events.

Requirement: Immuta permission GOVERNANCE or data owner

Target some data sources to manually review tags:

  1. Navigate to the data dictionary for the data source by opening the Data Sources page and selecting a data source. Click the Data Dictionary tab to open the data dictionary.

  2. The data dictionary lists the data source columns, with details about the name, data type, and a list of the tags on each column. Assess whether the tags are accurate to your data.

Tags may be unexpected but still accurate to your data. Additionally, they may have been applied because they were found to be the best match from the identifiers in the framework.

If you want to improve SDD and personalize it to your data,

  1. Assess why the tag was applied to your data.

  2. Is the identifier incorrectly matching your data and irrelevant to your organization? .

  3. Is the identifier incorrectly matching this specific column, but correct in other places? It must have been the most correct match found by identification. Create a better match by completing the following steps:

If you want to remove the unexpected tags, use one of the following how-to guides:

  1. .

  2. Ensure the Discovered tags are applied properly by adjusting SDD.

  3. . Note that classification tags build off of other tags, so removing a single classification or Discovered tag can have trickle-down effects on the data source.

If you were expecting some sensitive data to be tagged and it is not, enable additional tags using one of the following how-to guides:

  1. .

  2. Ensure the Discovered tags are applied properly by adjusting SDD.

  3. . Note that classification tags build off of other tags, so adding a single classification or Discovered tag can have trickle-down effects on the data source.

Requirement: Immuta permissions GOVERNANCE and AUDIT

Tags can be edited on an individual basis for each data source. If broad changes to the classification framework are necessary to re-tag your data, use the .

  1. Navigate to the Data Sources page and select the data sources that you assessed and noted issues.

  2. Click the Data Dictionary tab.

  3. Delete unnecessary tags by clicking on the tag you want to remove from the column, and select Disable from the tag side sheet.

  • .

  • Select the Event Id of one of the queries. Click the Columns tab.
  • The Column tab lists the columns in the query organized from highest to lowest sensitivity and the tags applied to each column. Check that the columns you know to be sensitive are here.

    For example, if the query has a column with last names, you should see a minimum of the following tags: DSF. Personal, DSF.Record.Subject.Type.Individual, DSF.Record.Identifiability.Identifiable, and DSF.Control.Personal.

  • Note any sensitive columns not labeled as sensitive.

  • Complete steps 2-5 for as many queries as you want.

  • .
  • so this column is correctly matched by identification.

  • .
    .
    To add tags,
    1. Click Add Tags in the Actions column.

    2. Begin typing the name of the tag you want to add in the Search by Name field and select the tag from the dropdown list.

    3. Click Add.

    Assess your queries with Detect

    Assess your data source tags

    If you find that too many tags are applied

    If you find that tags are missing

    Tune your data dictionaries

    Additional compliance frameworks and the data inventory dashboard
    Snowflake, Databricks, Redshift, or Starburst (Trino) data sources
    Create a new identification framework
    Configure the resulting tags in the identifiers
    Create an identifier specific to your organization
    Add a few data sources to your new framework
    assess your data source tags
    Delete the identifier that applied the tag from the identification framework
    Deactivate frameworks irrelevant to your organization
    Remove any excess tags
    Activate additional frameworks relevant to your organization
    Add additional tags
    frameworks API
    Configure SDD to run your new framework on all data sources
    Create an identifier specific to the column with a new Discovered tag
    Add the identifier to the identification framework
    Adjust the classification framework rules using the frameworks API
    Adjust the classification framework rules using the frameworks API

    How to Use a Built-In Classification Framework with Your Own Tags

    The built-in classification frameworks in Immuta provide a quick way to leverage your own catalog or data platform tags to establish classifications tags. These classification tags can then be used in the Immuta Data Platform for query activity visualizations, monitors, reports, and policies. After you have configured a data catalog integration and registered data sources in Immuta, you can start automating data classification of a column based on its context by considering the combination of its associated tags, its neighboring columns' tags, or its table tag. Classification frameworks also provide query event context. To use classification frameworks with your current tags from an external catalog, use one of the following options:

    1. Follow the tutorial below: This starter framework is built to map a classification scale of restricted, confidential, internal, and public to Immuta's three level scale. It requires an external catalog, but all other steps are described below.

    2. : This minimal framework allows you to map your own classification tags to Immuta classification tags. Then, your users' queries will have a sensitivity score on the Detect dashboard and in audit logs based on the classification tags on the data columns they queried. Use this option if you have already classified your organization’s data in an external catalog and want that metadata reflected in Immuta as Sensitive and Highly Sensitive.

    3. : This option allows you to map your own tags describing your data to Immuta's predefined classification tags in the context of a specific compliance framework. Immuta provides built-in frameworks for GDPR, CCPA, and HIPAA. Map your tags to the most comparable Data Security Framework (DSF) tag, and Immuta will apply the classification tag based on the framework. Use this option if you have descriptive tags on your data and want that metadata mapped to a specific compliance framework.

    Follow this guide to map your external catalog tags to the example framework, or consult the for more information about the framework schema.

    Using the example framework below, customize the framework for your organization's classification tags.

    For more information about these parameters see the .

    1. tags: These tags are automatically created in Immuta with the sensitivity you assign. All tags used in the classificationTag parameter should be defined here.

    2. tags.sensitivities: This is metadata for the sensitivity of the new tag. Use confidentiality for dimension. Options for sensitivity are 1

    Follow the example below to map your external tags to the rules in the example framework.

    The Immuta built-in framework, Risk Assessment Framework has a rule where columns tagged DSF.Interpretation.Credentials.Secret by sensitive data discovery will be tagged RAF.Confidentiality.High:

    To translate this to your tags, replace the name and source value of the columnTags, neighborColumnTags, or tableTags with your own. This new example is for a Collibra tag that an organization uses for confidential data. This rule now states: Apply the classification tag RAF.Confidentiality.High to a column if it has the collibra tag Confidential. Repeat this for your organization's remaining classification levels.

    If you do not know the name or source for your tags, you can list your tags using the Immuta API:

    This request will list all the tags in your Immuta environment, similar to this example response:

    Requirement: Immuta permission GOVERNANCE

    Once you have made all the customizations to the example framework, make the following request using the Immuta API, with your full customized framework as the payload.

    Your new framework will now be visible in the Immuta UI by navigating the Classification section under Discover.

    (shown as sensitive in Detect dashboards) and
    2
    (shown as highly sensitive in Detect dashboards). For nonsensitive, leave this parameter empty.
  • rules: These are the rules for applying the tags defined above.

  • rules.classificationTag: This classification tag must be defined in tags. Add the name you want and the source is curated. This is the tag that will be applied if the rule requirement is met.

  • rules.columnTags: This object represents tags on a column. If the tag defined here is found on a column, then the rule's classificationTag will be applied to the same column.

  • rules.neighborColumnTags: This object represents tags on other columns in the data source. If the tag defined here is found on any column in the data source, then the rule's classificationTag will be applied to all the neighboring columns.

  • rules.tableTags: This object represents tags on the data source. If the tag defined here is found on the data source, then the rule's classificationTag will be applied to all the columns in that data source.

  • active: When true the framework is active and will apply tags when the rules are met.

  • Customize the framework

    Example framework

    Parameters

    How to edit rules

    Find the name and source for your tags

    Activate your new framework

    Use Risk Assessment Framework (RAF)
    Use a compliance framework
    framework API guide
    Frameworks API reference guide
    {
      "shortName": "ECMC Framework",
      "name": "External Catalog Mapping Classification Framework",
      "description": "This framework maps the classification tags the organization has in Collibra to Immuta data sources.",
      "tags": [
        {
          "name": "ECMC.Confidentiality.Highly Sensitive",
          "source": "curated",
          "sensitivities": [
            {
              "dimension": "confidentiality",
              "sensitivity": 2
            }
          ]
        },
        {
          "name": "ECMC.Confidentiality.Sensitive",
          "source": "curated",
          "sensitivities": [
            {
              "dimension": "confidentiality",
              "sensitivity": 1
            }
          ]
        },
        {
          "name": "ECMC.Confidentiality.Nonsensitive",
          "source": "curated",
          "sensitivities": []
        }
      ],
      "rules": [
        {
          "name": "ECMC 00001",
          "classificationTag": {
            "name": "ECMC.Confidentiality.Highly Sensitive",
            "source": "curated"
          },
          "columnTags": [
            {
              "name": "Restricted",
              "source": "collibra"
            }
          ],
          "neighborColumnTags": [],
          "tableTags": []
        },
        {
          "name": "ECMC 00002",
          "classificationTag": {
            "name": "ECMC.Confidentiality.Sensitive",
            "source": "curated"
          },
          "columnTags": [
            {
              "name": "Confidential",
              "source": "collibra"
            }
          ],
          "neighborColumnTags": [],
          "tableTags": []
        },
        {
          "name": "ECMC 00003",
          "classificationTag": {
            "name": "ECMC.Confidentiality.Sensitive",
            "source": "curated"
          },
          "columnTags": [
            {
              "name": "Internal",
              "source": "collibra"
            }
          ],
          "neighborColumnTags": [],
          "tableTags": []
        },
        {
          "name": "ECMC 00004",
          "classificationTag": {
            "name": "ECMC.Confidentiality.Nonsensitive",
            "source": "curated"
          },
          "columnTags": [
            {
              "name": "Public",
              "source": "curated"
            }
          ],
          "neighborColumnTags": [],
          "tableTags": []
        }
      ],
      "active": true
    }
    "rules": [
    {
        "name": "RAF 00004",
        "classificationTag": {
          "name": "RAF.Confidentiality.High",
          "source": "curated"
        },
        "columnTags": [
        {
            "name": "DSF.Interpretation.Credentials.Secret",
            "source": "curated"
        }
        ],
        "neighborColumnTags": [],
        "tableTags": []
    }
    ]
    "rules": [
    {
        "name": "RAF 00004",
        "classificationTag": {
          "name": "RAF.Confidentiality.High",
          "source": "curated"
        },
        "columnTags": [
        {
            "name": "Confidential",
            "source": "collibra"
        }
        ],
        "neighborColumnTags": [],
        "tableTags": []
    }
    ]
    curl \
        --request GET \
        --header "accept: application/json" \
        --header "Authorization: Bearer <your-token." \
        https://your-immuta-url.com/tag
    [
      {
        "id": 114,
        "name": "DataProperties.Cross-Sectional",
        "source": "curated",
        "deleted": false,
        "systemCreated": true
      },
      {
        "id": 2,
        "name": "Discovered.Country.Argentina",
        "source": "curated",
        "deleted": false,
        "systemCreated": true
      },
      {
        "id": 9,
        "name": "Discovered.Country.Australia",
        "source": "collibra",
        "deleted": false,
        "systemCreated": true
      }
    ]
    curl \
        --request POST \
        --header "Content-Type: application/json" \
        --header "Authorization: Bearer <your-token>" \
        --data @example-payload.json \
        https://your.immuta.com/frameworks/