Classification of information
Purpose
Make sure information's protection needs are identified and understood according to its importance.
How to meet this control
In short: Classify information based on its confidentiality, integrity and availability needs plus the requirements of interested parties such as regulators, customers and partners.
- Step 01Adopt a simple, organisation-wide classification scheme (for example Public, Internal, Confidential, Restricted) based on confidentiality, integrity and availability
- Step 02Make information owners accountable for classifying their information and provide quick guidance and examples
- Step 03Align classification levels to access control and labelling so a classification automatically implies handling rules
- Step 04Define criteria and a cadence for reviewing and reclassifying information as its sensitivity changes
- Step 05Provide a mapping table for when you share information with partners who use a different scheme
Tip: Keep it simple: 3-4 levels (e.g. Public, Internal, Confidential, Restricted).
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Establish and communicate a topic-specific policy on information classification
- ›Base the classification scheme on confidentiality, integrity, availability and interested-party needs
- ›Make information owners accountable for classifying their information
- ›Use consistent classification levels and conventions across the whole organisation
- ›Define criteria for reviewing and updating classifications over time
- ›Align the scheme with the access control policy and avoid over- or under-classification
- ›Classify other assets in line with the information they store or process
- ›Map classification levels when sharing information with other organisations that use different schemes
Audit evidence to keep
- - Documented information classification scheme with defined levels and criteria
- - Examples of information assets assigned a classification by their owners
- - Guidance mapping classification levels to handling and access rules
- - Evidence of classification review or reclassification over time
Common mistakes
- - Classifying data once and never reviewing it
- - Allowing sensitive data into test or AI tools without approval
- - Keeping data after the business or legal need has expired
Owner, cadence, and proof
Assign one accountable owner for A.5.12. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.