Sensitivity labels are applied by the team member when the document is created. Each sensitivity label provides predetermined rules and protections, which allows you to decide who can open, view, and edit the document.
What Sensitivity Labels Do
Sensitivity labels help strengthen Sun’s overall data security by allowing team members to easily identify a document's level of sensitivity, categorize it, and control who has access to it.
This helps:
Support compliance requirements (i.e. - quarterly/annual results for SEC filings)
Protect team member and customer personal identifiable information, or PII
Safeguard Sun’s proprietary information
Enable safe external collaboration with our partners
How Sensitivity Labels Work
Microsoft sensitivity labels are designed to be persistent and stay with the document wherever it goes (copied, emailed, moved) for the length of time that the document exists. The document owner, or the person who created the document, will apply and manage the sensitivity label. The label and its rules and permissions will apply continuously. Document owners can edit the sensitivity label and permissions at any time.
Who can apply sensitivity labels?
All Sun Team Members with access to Microsoft desktop applications.
File Types Included
Currently, sensitivity labels are required for documents that are created using Microsoft Office/Microsoft 365.
This includes:
Documents created with:
Microsoft 365 desktop software (Word, Excel, PowerPoint)
Microsoft Online: Web-based apps or cloud versions accessed via app or web browser
Documents saved on:
Your desktop
OneDrive
SharePoint
I-Drive
Other cloud-based file storage
File types:
Word: .docx, .docm, .dot, .dotx
Excel: .xlsx, .xlsm, .xlsb, .xlt, .xltx, .xltm
PowerPoint: .pptx, .pps, .ppsx, .pot, .potx, .pptm
Note: PDFs (Adobe Acrobat) are not included at this time.
Label Definitions & When To Use Them
Review the different sensitivity labels and their details below:
This is the default sensitivity label.
All documents that are created (or existing documents opened for the first time) will automatically default to: All Team Members (Internal Only). The team member must then change the label based on the document's data and level of sensitivity if necessary.
These documents are intended solely for Sun team members. Internal data should be handled securely to prevent access by unauthorized persons.
Internal Data applies to information that is generally accessible by a wide internal audience and is intended for use only within Sun. While unauthorized disclosure to outsiders should be against policy, the unlawful disclosure of the information is generally not expected to be detrimental to the organization, team members, business partners or vendors.
Examples include:
Policies and procedures
Most individual team procedures and team-specific documents
Internal, non-customer facing forms
Team member announcements
Learning content
Proprietary secrets, such as credit scoring models and other tools used within Sun
See more label information below by clicking the + icons
These documents are intended to be viewed by anyone internal or external to the company and do not contain any sensitive information.
These documents are intended to be viewed by virtually anyone external to the company and do not contain any sensitive information. Documents labeled with Public includes information that has been formally approved and published for public distribution.
Examples include:
Posted press releases
Public social media posts
Posted marketing materials
Posted job announcements
Regulatory filings (after they are provided to the public) i.e. SEC filings, public annual reports
These documents are intended to be shared only with the specific individual who created the document or groups the document creator selects.
These documents are intended to be shared only with the specific individuals or groups the author selects, not for broader internal teams or general access.
Limited Audience label refers to data that is intended for the individual users or groups specified when labeling. Limited Audience should be kept to the specific audience the author or data owner has identified or opted to share with and can be used for internal team members or external partners.
It's best practice to avoid using the Limited Audience label for documents shared internally (throughout the Sun team and/or your direct team) that do not contain sensitive information or PII. Utilize the All Team Members (Internal Only) label instead.
Confidential data applies to information where the disclosure is likely to seriously harm the organization, our business partners, team members, vendors, or customers and must be protected. This data applies to the most sensitive information used within the organization.
Sun team members are instructed to handle confidential data in a manner that protects the information, whether it is electronic or paper documents.
Disclosure is limited to individuals who have been specifically authorized for such access on a “need-to-know” basis only. Access to one category of confidential information (e.g., social security numbers) does not automatically authorize access to another category within this classification (e.g., trade secrets).
There are subcategories that apply within the Confidential label:
Confidential - Named Contacts
These documents are intended for named recipients only. May including sensitive information such as team member HR files, payroll, and health data.Confidential - Audit
Documents are intended to be used for audit related information.Confidential - Legal
Documents legal in nature, usually sent to Sun Counsel.Confidential - Mergers and Acquisitions
These documents are intended for named recipients only. Due diligence material, deal teams, sensitive operational data, general communications relating to pending acquisition/disposition activity.Highly Confidential - Mergers and Acquisitions
These documents contain significant merger and acquisition communications and are intended only for select executive team members.Highly Confidential - Executive and Board Only
These documents are intended solely for the designated executive team and board members, covering items such as strategic plans, sensitive financial data, and high-impact legal matters.
Applying Labels
To apply a label:
1. Click Save or Save As, as usual.
2. Choose where you would like to store your document (I.e.- Locally on your desktop, OneDrive, SharePoint, etc.)
3. Name the file.
4. Determine the level of sensitivity needed for the document's data by selecting the appropriate sensitivity label from the Sensitivity dropdown field.
Note: The All Team Members (Internal Only) label will be automatically selected and applied. Review the different sensitivity labels in the prior section before making a selection.
Note: Depending on the sensitivity label you choose, you may be prompted to add users and determine their permissions, or what they are able to do with the document, before you are able to click Save.
See the section below for more information on permissions.
Labels that need permissions added: | Labels that do not need permissions added: |
|---|---|
Private | All Team Members (Internal Only) |
Limited Audience | Anyone (Unrestricted) |
Confidential | Public |
5. Click Save.
Applying Labels to Incompatible/Unsupported Files
Sometimes, an existing file is opened that is not compatible with Microsoft Sensitivity Labels. This usually occurs when the file was originally created using an older version of a Microsoft Application. An example would be Excel 97-2003.xls.
When this is the case, the document will show the following Compatibility Mode.
1. Click on Compatibility Mode and Click Convert.