Beyond Labels: Evolving Data Classification
Rob Oden (Senior Data Classification Specialist · Roblox)
BSidesSF 2024 · Day 1
Overview
In this insightful talk at BSidesSF 2024, Rob Oden, Senior Data Classification Specialist on the Roblox Information Security Team, presented a comprehensive framework for evolving data classification beyond traditional, often rigid, labeling schemes. Titled "Beyond Labels: Evolving Data Classification," Oden drew upon his two decades of experience across the United States Air Force, intelligence community, aerospace and defense consulting, and the tech sector, including his current role at Roblox. The core message of the presentation revolved around the critical need for organizations to adopt a holistic, risk-management-driven approach to data classification that is deeply integrated with business operations, rather than being a standalone security or compliance exercise.

Key moments
- 1:50 GRC as the communication layer for infosec to the business and regulators.
- 3:50 Roblox's adoption of a 'Big R' (Risk-managed) GRC program for data classification.
- 8:00 The 'Scope' phase: Identifying the burning platform and leveraging existing crown jewels/classifications.
- 10:00 Addressing unconscious discipline biases and avoiding analysis paralysis in classification design.
- 12:00 The 'Stratify' phase: Balancing broad enterprise lexicon with granular, specific data type needs.
- 16:00 The critical principle: 'If there is no action, there is no category' for effective classification.
- 19:00 The 'Secure' phase: Data classification as an enablement for controls like access management, DLP, and encryption.
- 21:00 Phased approach to automation: From guidance to manual controls, then to automation for data classification.
Beyond Labels: Evolving Data Classification
Speakers: Rob Oden
Conference: BSidesSF 2024
YouTube: https://www.youtube.com/watch?v=aKjU0TOA5T8
Overview
In this insightful talk at BSidesSF 2024, Rob Oden, Senior Data Classification Specialist on the Roblox Information Security Team, presented a comprehensive framework for evolving data classification beyond traditional, often rigid, labeling schemes. Titled "Beyond Labels: Evolving Data Classification," Oden drew upon his two decades of experience across the United States Air Force, intelligence community, aerospace and defense consulting, and the tech sector, including his current role at Roblox. The core message of the presentation revolved around the critical need for organizations to adopt a holistic, risk-management-driven approach to data classification that is deeply integrated with business operations, rather than being a standalone security or compliance exercise.
The talk is particularly relevant given the immense scale and complexity of data managed by platforms like Roblox, which boasts over 72 million daily active users, 2.5 million developers, and nearly 4.5 million unique experiences. For such an organization, the ability to protect sensitive data while simultaneously enabling its appropriate sharing and utilization is paramount to business success. Oden emphasized that effective data classification is not merely about assigning labels but about creating an enablement layer that informs and right-sizes security controls, ultimately supporting the organization's strategic goals. He aimed to provide practical, experience-based guidance for building an impactful data classification program that avoids common pitfalls like analysis paralysis or an over-reliance on compliance-driven mandates.
Background
▶ Watch: GRC as the communication layer for infosec to the business and regulators. (1:50)
Rob Oden began by contextualizing data classification within the broader landscape of Governance, Risk, and Compliance (GRC), an essential communication mechanism for information security programs. He outlined that GRC is not monolithic but comprises three distinct components: Governance (how security should be done), Risk Management (understanding operational drivers and right-sizing security), and Compliance (meeting regulatory and industry mandates like PCI DSS or GDPR). Oden noted that most GRC programs are primarily driven by one of these components, leading to different types of information security programs:
- Big G (Governance-led): Focuses on security best practices, common in the US (e.g., "we have firewalls, we have a SOC").
- Big R (Risk-led): Aims to quantify and qualify security risk in financial terms, right-sizing security efforts. This is the approach leveraged by Roblox.
- Big C (Compliance-led): Dictated by mandatory requirements (e.g., ISO 27001, NIST 800-53), often seen in heavily regulated industries or European agencies.
Oden then mapped these GRC drivers to common approaches to data classification, highlighting their limitations when applied enterprise-wide. A Governance-led data classification typically involves generic steps like identifying, classifying, protecting, educating, and monitoring data. While foundational, this approach can be too broad and lacks the specificity needed for actionable security. Conversely, a Compliance-led data classification is highly specific to particular data types (e.g., 16-digit PANs for PCI DSS, user PII for GDPR) and often confined to departments or teams that handle that data. While crucial for specific mandates, it struggles to scale across an entire enterprise and often results in a reactive "plans of action and milestones" approach rather than proactive risk reduction.
The inherent problem with these traditional models, Oden argued, is their failure to provide a holistic, adaptable framework for an organization's diverse data landscape. They either offer too little actionable detail or are too narrowly focused, preventing a unified and effective data protection strategy. This gap necessitates an evolution towards a more dynamic, risk-management-centric approach, which Roblox has adopted and which forms the basis of Oden's recommended framework.
Key Findings
▶ Watch: The 'Scope' phase: Identifying the burning platform and leveraging existing c... (8:00)
Rob Oden's presentation unveiled several key findings and principles for evolving data classification:
- Risk-Led Approach is Paramount: Roblox leverages a Big R GRC program, meaning its security strategy, and by extension its data classification, is driven by risk management. This involves defining why data classification is being undertaken, identifying stakeholders, and understanding the desired impact to right-size security based on data sensitivity and operational impact.
- The "Scope, Stratify, Secure" Framework: This three-part framework is the cornerstone of Oden's recommended holistic data classification program. It moves beyond simple labeling to a continuous cycle of understanding, categorizing, and protecting data in alignment with business objectives.
- Common Pitfalls to Avoid: Oden highlighted several recurring issues he has encountered throughout his career:
- Lack of a "Burning Platform": Failing to continuously ask and understand the core operational need that data classification is solving.
- Ignoring Existing Efforts: Discarding valuable existing data protection efforts (e.g., departmental PCI DSS programs) instead of leveraging them.
- Unconscious Discipline Biases: Security professionals, legal teams, and compliance officers often have different, sometimes conflicting, priorities based on their roles. Acknowledging these biases is crucial for a balanced approach.
- Analysis Paralysis: Striving for a "perfect" solution can prevent any solution from being implemented. A "good enough" approach that can be iterated upon is more impactful.
- Security as Sole Owner: Data classification, like vulnerability management, should be democratized, with business partners taking responsibility for defining data sensitivity within their domains.
- Building for Initial, Narrow Needs: Designing an entire program around a single department's specific requirement (e.g., privacy at Meta/Facebook post-2016) can restrict its enterprise-wide applicability.
- Labels Without Action: If a data category or label doesn't dictate a specific, different action from other categories, it's superfluous and creates friction.
- Semantic Ambiguity: Words like "confidential" or "sensitive" can have vastly different meanings across government, industry, and even within different internal departments (e.g., security vs. privacy's definition of "sensitive PII"). Clear internal taxonomy is vital.
- Data Classification as an Enablement: A crucial finding is that data classification itself is not a security control but an enablement layer. It provides the context necessary to prioritize funding and resources for actual security controls, allowing organizations to right-size their security posture.
- Phased Automation: Oden advocated for a phased approach to automation: first, establish clear guidance; second, implement manual controls based on that guidance; and finally, automate once expected behaviors and processes are well-defined and consistent.
- Continuous Management: Data classification is not a one-time project but an ongoing management effort. It must continuously adapt to changing business needs, regulatory environments, and evolving risk landscapes, always aligning with the organization's strategic goals (e.g., Roblox's goal of 1 billion users).
Technical Deep Dive
▶ Watch: The 'Stratify' phase: Balancing broad enterprise lexicon with granular, speci... (12:00)
The core of Oden's presentation was a detailed exploration of his recommended three-part framework: Scope, Stratify, and Secure. While presented linearly, he noted that these phases often run in parallel and in a somewhat circular fashion, with continuous iteration.
1. Scope: Defining the "Why"
The initial phase, Scope, focuses on asking the right questions to understand the fundamental drivers behind data classification. This involves:
- Identifying the Burning Platform: What is the operational need the organization is trying to solve by categorizing and classifying sensitive information? This question must be asked continuously throughout the program's lifecycle, as priorities can shift.
- Leveraging Existing Efforts: Instead of starting from scratch, organizations should identify and integrate existing data protection mechanisms. For instance, a payments department might already adhere to PCI DSS for its Cardholder Data Environment (CDE). Components of such established programs can be leveraged and expanded.
- Acknowledging Unconscious Discipline Biases: Different departments (legal, compliance, engineering, security) will have distinct priorities and perspectives on data sensitivity. Acknowledging these biases and striving for a risk-based approach that considers the overall business impact is crucial.
- Embracing "Good Enough": The pursuit of a perfect solution can lead to analysis paralysis. Oden stressed the importance of shipping a "good enough" solution and then continuously iterating and improving it.
- Democratization of Ownership: Security should not be the sole owner of data classification. Business partners must be empowered and made responsible for defining what is sensitive within their operational contexts. This fosters broader adoption and ensures relevance.
2. Stratify: Categorizing and Prioritizing Data
The Stratify phase deals with the actual categorization, segmentation, and prioritization of data.
- Industry Standard Categorization: Most organizations start with a broad, industry-standard approach, typically involving three to five levels such as Public, Internal, Confidential, and Restricted. These categories aim to establish a minimum level of protection and a common lexicon across the enterprise.
- Specific Use Cases and Granularity: While broad categories are useful, organizations also need the capability to drill down for specific data types. For example, handling an individual's email address (PII) might differ significantly from handling their Social Security Number, or gameplay data without direct identifiers. The framework must allow for this granularity when necessary.
- Common Lexicon and Enterprise Focus: A common understanding of what constitutes "sensitive data" across the enterprise is vital. However, the classification system must also accommodate departmental needs and the sharing of data both internally and externally.
- Avoiding Initial Needs Bias: A common pitfall is building the entire classification program around a single, initial departmental need (e.g., a privacy-only focus after a major incident). This can create a "bent" that restricts the program's ability to expand and serve the broader enterprise.
- Action-Oriented Classification: A critical principle Oden highlighted is: "If there is no action, there is no category." Every classification label should dictate a specific, different action or control. He cited an example from Hell3 Harris, where an initial 48 data categories were reduced to six due to usability issues.
- Importance of Semantics: The terminology used for classification is highly important. Words like "confidential," "secret," or "top secret" carry specific meanings in government contexts and should be avoided in corporate environments if there's a risk of confusion with classified data. Similarly, the term "sensitive" can mean different things to security professionals (any data requiring higher protection) versus privacy professionals (specifically sensitive PII). Establishing a clear internal taxonomy and definitions is essential.
3. Secure: Implementing Controls
The final phase, Secure, focuses on implementing actual security measures based on the established classification. Oden stressed that classification labels (metadata tags, human-readable markings, database indexes) provide awareness, but not inherent security. Data classification is an enablement for security controls.
Key security controls that are directly informed and right-sized by data classification include:
- Access Management: Classification provides the context to implement granular access controls. For example, less sensitive "internal" data might have default, broader access, while "restricted" data requires highly restrictive access.
- Data Tagging and Discovery: Technology can be leveraged to automatically tag and discover sensitive data types (e.g., scanning for credit card numbers for PCI compliance), supplementing human efforts.
- Data Loss Prevention (DLP): DLP solutions, which control data movement, rely heavily on understanding data classification. Whether inspecting content or controlling authorized storage, knowing the data's category is crucial for effective prevention.
- Policy Enforcement: Classification provides the basis for enforcing security policies, dictating how different data types should be handled.
- Encryption: Data classification helps right-size the application of encryption. High-cost encryption (full disk, file-based, IRM, application-level) can be strategically applied to the most sensitive data, optimizing resource allocation.
- Audit: Classification aids in auditing, allowing organizations to verify the effectiveness of their security tools and controls against specific data types.
Crucially, Oden emphasized the need for guidance and education. Employees cannot be expected to follow classification rules if they are not clearly told what to do and how to do it in various situations.
The implementation of these controls follows a phased approach, particularly concerning automation:
- Guidance: Document processes and make them easily understandable and accessible.
- Manual Controls: Implement manual steps that align with the documented guidance.
- Automation: Once processes are stable and behaviors are predictable, automate tasks to reduce manual load and abstract complexity, reinforcing with ongoing guidance.
Finally, Oden underscored that data classification is an ongoing management effort. The initial rollout is often the "easy part"; continuous adaptation to changing business priorities, regulatory landscapes, and emerging risks is the real challenge. The program must remain aligned with the organization's overarching business goals, such as Roblox's ambition to connect one billion users.
Demo / Proof of Concept
▶ Watch: The critical principle: 'If there is no action, there is no category' for eff... (16:00)
The presentation by Rob Oden focused on a conceptual framework and strategic approach to data classification rather than a specific technical demonstration or proof of concept. While the speaker mentioned that all images in the slides were generated by AI (e.g., ChatGPT), these were illustrative and served to enhance the presentation's visual appeal rather than showcasing a functional system or tool. The talk did not include any live demonstrations of data classification tools, code, or architectural implementations.
Defensive Implications
▶ Watch: Phased approach to automation: From guidance to manual controls, then to auto... (21:00)
The insights shared by Rob Oden offer several critical defensive implications for organizations looking to strengthen their security posture through effective data classification:
- Strategic Resource Allocation: By adopting a risk-led data classification framework, defenders can strategically prioritize security investments. Instead of applying uniform, often costly, controls across all data, classification enables the right-sizing of resources (funding, personnel, tools) to protect the most sensitive and impactful data, thereby maximizing security ROI.
- Enhanced Access Management: Data classification provides the necessary context for implementing granular and effective access management. Defenders can define access policies based on data sensitivity, defaulting to easier access for less critical "internal" data while enforcing stringent controls for "restricted" or "confidential" information. This reduces the attack surface by limiting unnecessary access.
- Improved Data Loss Prevention (DLP): A well-defined data classification scheme is foundational for effective DLP. Defenders can configure DLP tools to accurately identify, monitor, and prevent unauthorized exfiltration or movement of sensitive data, whether through content inspection or by controlling authorized storage locations.
- Targeted Encryption Strategies: Encryption is a powerful control, but it comes with performance and management overhead. Data classification allows defenders to apply encryption strategically, focusing high-cost solutions (e.g., application-level encryption, file-based encryption) on the most critical data types, rather than indiscriminately encrypting everything.
- Actionable Security Policies and Guidance: Defenders must move beyond generic security policies. Data classification enables the creation of clear, actionable guidance for employees on how to handle different types of data. This empowers the workforce to become a stronger line of defense by understanding their responsibilities and the expected behaviors for data protection.
- Shared Ownership and Accountability: Shifting data ownership and stewardship to business units and senior leadership, rather than solely resting with security, fosters a culture of shared responsibility. This means that operational teams are accountable for defining data sensitivity and adhering to controls, making the defense more robust and integrated into business processes.
- "Shift Left" Security Integration: Integrating data classification early in the Software Development Life Cycle (SDLC) and data collection processes (i.e., "security by design" and "privacy by design") ensures that security controls are considered from inception. This proactive approach is significantly more effective and less costly than retrofitting security measures later.
- Continuous Adaptation and Management: Defenders must recognize that data classification is not a static project but an ongoing management discipline. The threat landscape, business operations, and regulatory requirements are constantly evolving. The classification program must be continuously reviewed, updated, and adapted to remain effective and aligned with organizational risk tolerance.
Key Takeaways
- Business-Aligned Classification: Data classification must reflect an organization's unique business and regulatory needs, rather than forcing the business to conform to a rigid classification scheme.
- Clear, Adaptive Roadmap: A well-defined roadmap, continuously aligned with evolving business priorities, is crucial for securing buy-in from key partners and ensuring the program remains impactful.
- Holistic, Risk-Based Approach: Adopt a comprehensive "Scope, Stratify, Secure" framework that prioritizes security efforts based on the actual risk and impact to business operations, moving beyond mere compliance.
- Actionable Categories: Every data category or label should drive a specific, distinct action or control. If a label doesn't dictate different behavior, it adds unnecessary complexity and friction.
- Mindful Semantics: Carefully define and standardize terminology for data classification internally to avoid confusion and misinterpretation across different departments and disciplines.
- Early Integration (Shift Left): Integrate data classification principles and controls as early as possible in the data lifecycle, from collection to design, to maximize program effectiveness and impact.
About the Speaker(s)
Rob Oden is the Senior Data Classification Specialist on the Roblox Information Security Team. He brings over 20 years of extensive experience in information security and data protection. His career spans diverse sectors, including supporting the United States Air Force and multiple three-letter agencies within the intelligence community. He has also worked as a consultant in the Aerospace and Defense industries, and in various roles within the tech sector, including at Facebook (Meta). Oden's expertise is grounded in practical application, drawing from his broad background to develop and implement effective data classification programs in complex, large-scale environments.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk provides a highly practical and experience-driven framework for implementing and evolving data classification programs, moving beyond generic GRC advice to a risk-based model. The speaker, drawing from extensive background in government and tech, offers actionable strategies for scoping, stratifying, and securing data, while candidly addressing common organizational pitfalls and biases that hinder effective classification.
Heather Calloway (CISO) — MUST SEE
This is a highly valuable session for any CISO or security leader grappling with effective data classification. Rob Oden provides a clear, experience-backed framework that directly addresses the institutional challenges of data governance, risk management, and operationalizing security controls. His emphasis on aligning classification with business objectives and ensuring clear accountability offers a pragmatic path forward for organizations.