Four levels, defined by consequence rather than by feel
Each level is written so that a Head of Department can apply it without needing to consult anyone. Levels that require interpretation get applied inconsistently, which defeats the exercise.
Five steps, and the order is the method
Catalogue first, classify second. Asking a department to do both at once reliably produces a shorter list.
Six columns, and one of them arrives late on purpose
A template is provided. Departments complete the first five columns; the sixth is added once the catalogue is back.
The register is an input, not a deliverable
A classification exercise that ends with a finished spreadsheet has not finished. Four things should change as a result of it.
Access control decisions
Who may reach what, justified by classification rather than by job title or by whoever asked first.
Control selection during risk treatment
Treatment effort concentrated on confidential and restricted assets instead of spread evenly across everything.
ISMS documentation
Acceptable use, data handling procedures and related policies written against real asset categories rather than generic ones.
Annex A 5.12 evidence
A classification of information control an auditor can test, with business validation attached to each entry.
The classification is not only documented but validated by the business, which is what makes it hold up under audit and what makes people follow it afterwards. A register the departments wrote is one they recognise; a register written for them is one they ignore.
What the register makes possible
Data leakage prevention
Enforcement needs labels. A DLP policy without classification blocks everything or nothing.
ISO 27001
Annex A 5.12 is where this sits, and the register is the evidence for it.
Personal data protection
Personal data is a category within the register, with its own legal obligations attached.
