information-classification-iso-27001

By July 25th, 2026ISO Audit And Certificate7 min read

Information Classification According to ISO 27001

Information is one of an organisation’s most valuable assets. Without a systematic way to classify that information, you cannot protect it appropriately. Information classification ISO 27001 provides the structure needed to label, handle and safeguard data based on its sensitivity and criticality. This article explains what information classification is, how it maps to the ISO 27001 standard, and what you need to implement a effective classification policy.

What Is Information Classification?

Information classification is the process of categorising information assets according to their level of sensitivity, value and criticality to the organisation. Once classified, each category receives a defined set of handling, storage, transmission and disposal requirements.

Under ISO 27001, information classification is a key requirement of Annex A.8.2, which sits within the asset management domain. The standard requires that information is classified in terms of its confidentiality, integrity and availability (the CIA triad), and that the classification scheme is applied consistently across the organisation.

AspectDescriptionRelevance to Classification
ConfidentialityInformation is not disclosed to unauthorised partiesDetermines who can access the data
IntegrityInformation is accurate and completeDetermines modification controls required
AvailabilityInformation is accessible when neededDetermines backup and redundancy needs

Classification Levels

Most organisations adopt between three and five classification levels. The most common scheme following information classification ISO 27001 guidance uses three levels: Confidential, Internal and Public. Some organisations also add a fourth level, such as Restricted or Top Secret, for highly sensitive data.

Classification LevelDefinitionExample
ConfidentialUnauthorised disclosure could cause serious harm to the organisation or its stakeholdersCustomer personal data, trade secrets, board meeting minutes
InternalAccess limited to employees and authorised partners; not for public distributionInternal policies, operational procedures, staff handbooks
PublicInformation approved for external release with no restriction on distributionMarketing materials, published annual reports, press releases

Classification Criteria

When deciding how to classify an information asset, organisations should evaluate the following criteria:

  • Legal and regulatory impact – Does the information fall under data protection law, financial regulation or other statutory requirements?
  • Business impact – What would the financial, operational or reputational damage be if the information were disclosed or lost?
  • Contractual obligations – Are there confidentiality agreements or client contracts that dictate how information must be handled?
  • Strategic value – Does the information represent a competitive advantage or intellectual property?
  • Aggregation risk – Could combining this information with other data create a greater risk?
CriterionLow SensitivityMedium SensitivityHigh Sensitivity
Legal impact of breachNone or minimal fineRegulatory penalty possibleMajor penalty or prosecution
Business harmNegligibleModerate financial or reputational damageSevere or existential impact
Access restrictionsNo restrictionsRole-based access requiredNeed-to-know basis only
Encryption requiredNoIn transitAt rest and in transit
Retention periodMinimalStandard business retentionExtended or permanent retention

Labelling Procedures

Once information is classified, it must be labelled so that users can immediately recognise the handling requirements. Labelling can be applied in several ways:

  • Physical documents – Header, footer or cover-page classification markings. Confidential documents should also be watermarked.
  • Electronic documents – Metadata tags, filenames, document properties and visible headers or footers.
  • Email – Classification banners embedded in the email template or added manually.
  • Databases and applications – Field-level classification tags within data dictionaries or database schemas.
  • Removable media – Physical labels on USB drives, external hard drives and optical discs.

Handling Requirements

Each classification level must have defined handling requirements that specify how information is stored, transmitted, accessed and disposed of. The following table summarises typical handling rules for a three-level scheme:

Handling ActivityPublicInternalConfidential
Access controlNoneAuthenticated user accessRole-based need-to-know
Encryption at restNot requiredRecommendedRequired (AES-256 minimum)
Encryption in transitNot requiredTLS 1.2+ recommendedTLS 1.2+ required
Printing and copyingUnrestrictedAuthorised use onlyLogging required
Transmission by emailUnrestrictedInternal recipients onlyEncrypted or secure portal
Retention periodAs neededPer records scheduleDefined minimum with destruction log
Disposal methodStandard recyclingCross-cut shreddingSecure destruction with certificate

ISO 27001 Annex A.8.2 Requirements

Annex A.8.2 of ISO 27001:2022 specifies two controls related to information classification:

  • A.8.2 Information classification – Information must be classified according to its confidentiality, integrity, availability and legal requirements. The organisation must define and document a classification scheme.
  • A.8.3 Labelling of information – Appropriate labelling procedures must be developed and implemented in accordance with the classification scheme adopted by the organisation.

These controls are part of the asset management domain and are closely linked to A.8.1 (asset inventory) and A.7 (human resource security). An ISMS auditor will expect to see evidence that classification is applied consistently and that employees understand their responsibilities.

Classification Policy

Every organisation implementing information classification ISO 27001 must document a formal classification policy. The policy should include:

  • Scope and objectives of the classification scheme
  • Classification levels with definitions and examples
  • Roles and responsibilities for classifying and handling information
  • Labelling rules and procedures
  • Handling, storage, transmission and disposal requirements per level
  • Review cycle and frequency of reclassification
  • Penalties for non-compliance or misuse

Roles and Responsibilities

Clear ownership is essential for a successful classification scheme. The following roles should be defined:

RoleResponsibility
Information OwnerSenior manager accountable for a specific set of information assets; decides the classification level
Information CustodianIT or security staff responsible for implementing technical controls according to classification
Information UserAll employees who handle information; must follow labelling and handling procedures
Data Protection OfficerOversees compliance with privacy regulations and advises on classification of personal data
Internal AuditorVerifies that classification and labelling controls are operating effectively

Frequently Asked Questions

How many classification levels should my organisation use?

Most organisations find a three-level scheme (Confidential, Internal, Public) sufficient. Highly regulated sectors such as defence or finance may require additional levels. Avoid creating too many levels, as this can confuse users and reduce compliance.

Is information classification mandatory for ISO 27001 certification?

Yes. Annex A.8.2 requires that information is classified. An ISMS auditor will check for a documented classification scheme, evidence of classification in practice, and appropriate labelling of information assets.

Who should classify information in an organisation?

The information owner – typically the senior manager who creates or is accountable for the information – is responsible for assigning the initial classification. The classification policy should define the criteria and process they must follow.

How often should information be reclassified?

Information should be reviewed at least annually or whenever there is a significant change in legal, regulatory or business circumstances. Some organisations include reclassification as part of their regular asset review cycle.

What happens if employees do not follow classification rules?

Non-compliance with classification policy should be treated as a disciplinary matter. The policy should specify consequences, and awareness training should reinforce the importance of correct classification for information security.

Can classification be automated?

Yes. Data-loss prevention (DLP) tools, content-aware classification software and Microsoft Information Protection (MIP) can automatically suggest or apply labels based on content analysis, metadata rules or user behaviour patterns. Automation improves consistency and reduces the burden on users.

Implement Information Classification With Expert Support

Setting up a robust information classification ISO 27001 scheme requires careful planning, clear policies and the right tools. Our consultants can help you design, document and implement a classification framework that meets the standard and protects your data.

Get in touch on WhatsApp for a quick consultation.

Tags: ISO 27001, information classification, data classification, asset management, ISMS, Annex A