GlossaryCompliance operations

Information classification

Short answer

Information classification is the process of assigning each type of information a level according to how sensitive it is, such as public, internal, confidential or restricted, and defining how each level must be handled, stored, shared and destroyed.

Why classify

Not all information needs the same protection. Classification lets a company focus its strongest controls on what matters most, such as customer data, financial information, source code or contracts, and gives employees a simple rule for how to treat what they handle.

A typical scheme

Most companies use three or four levels. Public: can be shared freely. Internal: for employees, with low impact if leaked. Confidential: limited to those who need it, with real damage if disclosed. Restricted: the most sensitive data, with strict access, encryption and logging. Each level comes with handling rules: who can access it, where it can be stored, whether it can be sent outside the company, and how it is destroyed.

Making it work in practice

Keep the scheme simple, assign an owner to each information asset in the asset inventory, use labels in documents and email where tools allow it, and connect classification to technical controls such as DLP, access rights and backup policies. A scheme nobody uses is worse than none, because it gives a false sense of control.

Where it shows up in compliance

ISO 27001 requires information to be classified and labelled according to the organisation's needs (Annex A 5.12 and 5.13). The ENS requires information to be rated according to its security requirements, and the GDPR treats special categories of personal data as needing extra protection.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub