Englishالعربية Soon
Under attack?
Data classification · ISO 27001 Annex A 5.12

Protecting everything equally means protecting the important things inadequately.

A structured process for identifying and classifying information assets across every business unit, so controls are applied according to sensitivity and business impact, and so the classification is validated by the people who own the data, not asserted by a consultant.

Delivered as part of the ISO 27001:2022 implementation lifecycle, and equally as a standalone exercise where the objective is to know what you hold before deciding how to defend it.

Sensitivity levels

Four levels, defined by consequence rather than by feel

Each level is written so that a Head of Department can apply it without needing to consult anyone. Levels that require interpretation get applied inconsistently, which defeats the exercise.

Confidential
Highly sensitive information: trade secrets, customer personal data, financial records.
Strict access restrictions. Unauthorised disclosure could cause severe damage.
Restricted
Information intended for internal use only.
May cause harm if disclosed, but not catastrophic.
Protected
Information requiring caution but with lower business impact if exposed.
Limited access controls are sufficient.
Public
Information approved for public release.
No confidentiality concerns.
Process

Five steps, and the order is the method

Catalogue first, classify second. Asking a department to do both at once reliably produces a shorter list.

01
Distribute
A departmental data collection sheet is issued across all business units, structured to catalogue key information assets: name and description, owning department, location and storage, purpose, and format.
02
Collect
Each department completes the sheet for the data it owns or processes. This is the step that produces visibility, and the step where the count is always higher than management expected.
03
Add the classification column
Once the initial version is returned, a classification column is added. Cataloguing first and judging second is deliberate: it stops departments from omitting assets they suspect will be inconvenient to classify.
04
Review and assign
The Head of Department, with the data owners, reviews each entry and assigns a sensitivity level against internal policy and regulatory requirements. Assignment sits with the business, not with us.
05
Finalise and return
The approved sheet becomes the working classification register, used to drive access control decisions, guide control selection during risk treatment, and inform ISMS documentation.
The collection sheet

Six columns, and one of them arrives late on purpose

A template is provided. Departments complete the first five columns; the sixth is added once the catalogue is back.

Document name / description
What the asset is, in terms the department that owns it recognises.
Owning department
Who is accountable for it. Assets without an owner are the ones that go unclassified.
Location / storage
Where it actually lives: system, share, cabinet or cloud service.
Purpose / use
Why it is held, which is also the first test of whether it should still be held at all.
Format
Digital or physical. Both carry obligations, and physical records are routinely forgotten.
Classification
Added after the first return, so departments catalogue before they judge.
What it feeds

The register is an input, not a deliverable

A classification exercise that ends with a finished spreadsheet has not finished. Four things should change as a result of it.

01

Access control decisions

Who may reach what, justified by classification rather than by job title or by whoever asked first.

02

Control selection during risk treatment

Treatment effort concentrated on confidential and restricted assets instead of spread evenly across everything.

03

ISMS documentation

Acceptable use, data handling procedures and related policies written against real asset categories rather than generic ones.

04

Annex A 5.12 evidence

A classification of information control an auditor can test, with business validation attached to each entry.

Outcome

The classification is not only documented but validated by the business, which is what makes it hold up under audit and what makes people follow it afterwards. A register the departments wrote is one they recognise; a register written for them is one they ignore.

Related

What the register makes possible

Data leakage prevention

Enforcement needs labels. A DLP policy without classification blocks everything or nothing.

ISO 27001

Annex A 5.12 is where this sits, and the register is the evidence for it.

Personal data protection

Personal data is a category within the register, with its own legal obligations attached.

Start with one department.

Run the collection sheet through a single business unit first. It sets the standard the rest of the organisation is measured against.