Data Classification
Data Handling
See Something Say Something
PII/PCI
100

This process ensures sensitive data is labeled correctly and shared only with authorized parties, forming the backbone of DTCC’s data protection strategy.

What is Data Classification?

100

Before sending an email with confidential data, you should do this to ensure the message reaches only the intended recipient.

What is verifying the email recipient?

100

This phrase encourages employees to report suspicious behavior that could indicate insider threats.

What is "See Something Say Something"

100

This acronym refers to any data that can be used to uniquely identify an individual, such as names, addresses, or Social Security numbers.

What is PII (Personally Identifiable Information)?

200

The four official DTCC data classification levels, ranked from most to least sensitive.

What are Red, Yellow, Green, and White?

200

Under this rule, employees should only access the minimum amount of data necessary to perform their job.

What is least privilege or RBAC

200

Name one of the countries designated as a nation-state actor where DTCC workers are not permitted to work from?

What is China, Russia, Iran, North Korea.


200

If you accidently send PII to an unintended recipient you should immediately notify these teams. 

Who are the Privacy Office and Insider Risk Team

300

Documents such as YOUR payslips, onboarding guides, and benefits plan information fall under this classification

What is Green Data

300

This policy defines what users should and should not be doing on their corporate devices

What is the technology usage policy

300

This US President is responsible for the creation of Insider Risk program with in government regulated agencies

Who is Barack Obama

300

The name of your first pet, the street you grew up on and your mother's maiden name

What is white data

400

What are operational and technology procedures

What is Yellow Data

400

This recipirical is located on all office floors to discard confidential information that was made available on a hard copy

What is a locked trash can. 

400

 A sudden change in behavior, increased secrecy, or visible stress may be signs of this.

What is a potential insider threat?

400

What is the best way to send documents containing PII to authorized external parties when required for business?

Password protect 

500

This color label represents DTCC’s most sensitive data like MNPI and encryption keys, and must be handled with extreme caution.

What is Red Data

500

This group is responsible for providing access to blocked web portals 

Who is the SARG

500

The 3 types of insiders threats?


What are malicious, negligent, and accidental. 


500

DTCC uses this type of training to help employees recognize and properly handle PII to reduce insider risk.

What is security and awareness training

M
e
n
u