NIST 800-53
The National Institute of Standards and Technology (NIST) created the
NIST Special Publication 800-53
to provide security and privacy controls for U.S. federal information systems.
This document suggests you categorize your data in three levels:
Low Impact
Moderate Impact
High Impact
Determine impact level by the amount of damage the disclosure of the data would cause.
PCI-DSS
The Payment Card Industry Data Security Standard (PCI-DSS) is a standard that
organizations that handle payment cards (credit and debit) need to follow.
One of the requirements of this standard is that the organization in question "Protects Cardholder Data".
This requirement means that storage and transmission of data such as:
Be encrypted and handled in specific ways.
The levels and requirements of your data classification will be determined by what kind
of data you have and from where it originated.