Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.12: Classification of Information

58 min read

Share
On this page

Quick Reference

Figure · Tiers

The four classification tiers

The four ISO 27001 information classification tiers, least to most sensitive: Public, freely shareable with no restrictions; Internal, standard protection for internal use; Confidential, sensitive with controlled access; and Restricted, highly sensitive with minimal access.
Sensitivity rises up the ladder, and the handling rules tighten with it. Label colours and hex codes are in the scheme table further down.
AttributeDetail
Control NumberA.5.12
Control TitleClassification of Information
ISO 27001:2022 DomainOrganizational Controls (5)
Control TypePreventive
Information Security AttributeConfidentiality, Integrity, Availability
Maturity Model LevelLevel 1–5 (covered in Section 20)
Typical Implementation Time3–6 months for initial classification; ongoing maintenance
Estimated Annual overhead– (tools, staff time, training, DLP)
Primary OwnerCISO / Data Protection Officer
Key StakeholdersData Owners, IT, Legal, Compliance, HR, All Employees
Audit FrequencyQuarterly review + annual complete assessment

What the Standard Requires

ISO 27001:2022 Annex A 5.12 states:

ISO 27001:2022 Annex A 5.12 asks organizations to classify information by how sensitive it is, weighing its confidentiality, integrity, and availability needs alongside stakeholder requirements.

This control requires organizations to:

  1. Establish a classification scheme, Define categories or levels that reflect the organization's information security needs
  2. Classify all information, Apply the scheme consistently across all organizational information
  3. Base classification on security needs, Consider confidentiality, integrity, availability, and stakeholder requirements
  4. Apply appropriate handling rules, Each classification level must have defined handling, storage, transmission, and disposal requirements
  5. Communicate classification, Ensure all users understand the classification scheme and their responsibilities
  6. Review and update, Periodically review classification levels to ensure they remain appropriate

Classification is the foundation of proportionate security. Without classification, organizations apply the same controls to all information, either over-protecting low-value data (wasting resources) or under-protecting sensitive data (creating unacceptable risk).


Why It Matters

Proportionate Security Investment

Not all information requires the same level of protection. Public marketing materials need minimal security controls. Customer financial data needs encryption, access controls, monitoring, and DLP. Board-level strategic plans need the highest level of protection. Classification enables organizations to apply the right level of protection to the right data, optimizing security spend.

An Indian banking group with 15,000 employees implemented a four-tier classification system and discovered that only 12% of their data was "Confidential" or "Restricted", requiring premium-tier controls. The remaining 88% needed standard or minimal controls. By right-sizing protection, they saved s annually in unnecessary security spending while improving protection for truly sensitive data.

Regulatory and Compliance Requirements

Indian and international regulations increasingly mandate data classification:

  • DPDP Act 2023 distinguishes between personal data and sensitive personal data, requiring different protection levels
  • RBI requires banks to classify customer data based on sensitivity
  • SEBI mandates classification of market-sensitive information
  • PCI DSS requires identification of cardholder data (CHD) and sensitive authentication data (SAD)
  • GDPR requires organizations to identify special categories of personal data
  • Health sector regulations (NABH, CDSCO) require classification of patient data

Without classification, organizations cannot demonstrate compliance with these differentiated requirements. A healthcare organization that treats all patient data the same may fail to meet enhanced requirements for sensitive health information, while over-investing in protecting routine appointment schedules.

Data Breach Impact Mitigation

When breaches occur, classification determines the response severity and regulatory obligations:

  • Public data breaches may require minimal response
  • Internal data breaches may require internal investigation and remediation
  • Confidential data breaches may require customer notification, regulatory reporting, and legal review
  • Restricted data breaches may require immediate incident response, law enforcement notification, regulatory penalties, and media management

An Indian e-commerce platform suffered a breach affecting customer records. Because they had classified their data, they knew exactly which records were affected, which customers needed notification, and which regulators required reporting. Their response overhead **** instead of the estimated s if they had to investigate the entire database scope.

Access Control and Least Privilege

Classification enables granular access control. Employees should only access data necessary for their role. A sales representative needs customer contact information but not financial records. A developer needs source code but not HR data. Classification provides the framework for defining these boundaries and implementing least-privilege access.

A Mumbai-based IT services company with 800 employees reduced unauthorized access incidents by 45% after implementing classification-based access controls. Employees could no longer accidentally access data outside their classification scope, and security teams could easily identify inappropriate access patterns.

Cloud and Third-Party Data Protection

Classification is essential for cloud migration and third-party data sharing decisions:

  • Public data can be stored on public cloud with minimal controls
  • Internal data can be stored on standard cloud with basic controls
  • Confidential data requires encrypted cloud storage, CASB monitoring, and contractual controls
  • Restricted data may require private cloud, data residency, and enhanced vendor assessments

Without classification, organizations cannot make rational cloud and outsourcing decisions. They either avoid cloud entirely (losing agility benefits) or place all data in the cloud without differentiation (creating unacceptable risk).

Data Retention and Disposal

Classification drives retention and disposal policies:

  • Public data may have minimal retention requirements
  • Internal data may be retained for 3–7 years per business requirements
  • Confidential data may have specific retention periods (e.g., customer records for 7 years, financial records for 10 years)
  • Restricted data may have the longest retention with the most secure disposal requirements

An Indian manufacturing company saved **** in storage overhead by implementing classification-based retention policies. They discovered that 40% of their stored data was outdated internal documents that could be safely deleted, while 8% was restricted IP that required enhanced archival protection.

Incident Response Prioritization

During security incidents, classification enables intelligent prioritization:

  • Incidents affecting Restricted data trigger immediate executive escalation and legal involvement
  • Incidents affecting Confidential data trigger standard incident response with regulatory notification assessment
  • Incidents affecting Internal data trigger routine investigation and remediation
  • Incidents affecting Public data may require minimal response

This prioritization ensures that the most damaging incidents receive the most attention, rather than treating all incidents equally (which can lead to alert fatigue and delayed response to truly critical events).

Employee Awareness and Culture

Classification creates a tangible security culture:

  • Employees understand that data has different values and protection requirements
  • Classification labels serve as constant visual reminders of security responsibilities
  • Employees can make better decisions about sharing, storing, and handling data
  • Classification training is concrete and practical, not abstract

A Bengaluru-based SaaS company reported that after implementing visual classification labels, employees were 3x more likely to question unusual data requests and report potential security issues. The classification system made security visible and actionable.


Scope and Applicability

In Scope, Information to be Classified

Business Information:

  • Strategic plans and board materials
  • Financial statements, budgets, and forecasts
  • M&A documentation and due diligence materials
  • Customer lists, contracts, and licensing information
  • Product roadmaps and development plans
  • Marketing strategies and campaign data
  • Competitive intelligence and market research
  • Vendor and supplier information
  • Audit reports and compliance documentation

Customer and Client Data:

  • Personal identifiers (name, address, phone, email, Aadhaar)
  • Financial information (account numbers, transaction history, credit scores)
  • Payment card data (primary account number, CVV, expiry)
  • Health and medical records (for healthcare organizations)
  • Insurance policy details and claims data
  • Legal and case information (for legal services)
  • Service usage data and preferences
  • Communication records and support tickets

Employee and HR Data:

  • Personal information and contact details
  • Salary, compensation, and benefits data
  • Performance reviews and disciplinary records
  • Background check and verification data
  • Health and insurance records
  • Training and certification records
  • Attendance and leave records

Technical and Operational Information:

  • Source code and development artifacts
  • System architecture and network diagrams
  • Configuration files and security settings
  • Database schemas and data dictionaries
  • API documentation and integration details
  • Security policies and incident response plans
  • Vulnerability assessments and penetration test results
  • Backup configurations and recovery procedures

Regulatory and Legal Information:

  • Regulatory filings and submissions
  • Legal contracts and agreements
  • Litigation materials and privileged communications
  • Intellectual property and patent documentation
  • Government correspondence and licenses
  • Compliance audit reports and findings

Third-Party Information:

  • Customer data processed on behalf of clients
  • Partner and vendor confidential information
  • Shared data under contractual agreements
  • Data subject to third-party security requirements

Classification Dimensions

While confidentiality is the primary classification dimension, organizations should consider:

Confidentiality: Who should have access to this information?

  • Public: Anyone can access
  • Internal: Employees and authorized personnel
  • Confidential: Specific authorized individuals with business need
  • Restricted: Minimal authorized individuals with strict controls

Integrity: How important is accuracy and completeness?

  • Low: Minor errors acceptable
  • Medium: Errors should be detected and corrected
  • High: Must be accurate; tampering must be prevented
  • Critical: Must be 100% accurate; any modification is catastrophic

Availability: What are the uptime and recovery requirements?

  • Low: Can be unavailable for days
  • Medium: Should be available during business hours
  • High: Must be available 24/7 with minimal downtime
  • Critical: Must be available continuously; any outage is catastrophic

Regulatory Sensitivity: What regulatory requirements apply?

  • Standard: General business data
  • Personal: Personal data subject to DPDP Act
  • Sensitive Personal: Sensitive personal data under DPDP Act
  • Financial: Subject to RBI/SEBI/IRDAI requirements
  • Health: Subject to healthcare data protection requirements
  • Government: Subject to official secrets or classified handling

Organizational Size Considerations

Small Organizations (≤50 employees):

  • Simple 3-tier classification (Public, Internal, Confidential)
  • Manual classification by document creators
  • Basic labeling (file names, folder structures, email footers)
  • Annual review and training
  • Budget: –annually

Medium Organizations (50–500 employees):

  • 4-tier classification (Public, Internal, Confidential, Restricted)
  • Automated classification tools for sensitive data types
  • Visual labeling (headers, footers, watermarks)
  • Integration with DLP and email security
  • Quarterly review and refresher training
  • Budget: –annually

Large Organizations (≥500 employees):

  • Multi-dimensional classification (confidentiality × integrity × availability)
  • Automated classification with machine learning
  • Metadata tagging and integration with security tools
  • Enterprise DLP with classification-driven policies
  • Role-based access tied to classification
  • Monthly monitoring and quarterly review
  • Budget: –+ annually

Key Definitions

TermDefinition
Information ClassificationThe systematic process of categorizing information based on its sensitivity, value, and required protection level
Classification SchemeThe defined set of categories or levels used to classify information within an organization
Classification LevelA specific category within the classification scheme (e.g., Public, Internal, Confidential, Restricted)
Data OwnerThe individual or business unit accountable for the classification, accuracy, and protection of specific information
Data CustodianThe individual or IT function responsible for the technical storage, maintenance, and security of information on behalf of the owner
Data UserAny individual who accesses, processes, or handles information in the course of their duties
ConfidentialityThe property that information is not made available or disclosed to unauthorized individuals, entities, or processes
IntegrityThe property of accuracy and completeness of information and processing methods
AvailabilityThe property of being accessible and usable upon demand by an authorized entity
Classification LabelA visual or metadata indicator applied to information to show its classification level (e.g., header, footer, watermark, tag)
Handling RulesThe specific requirements for how information of a particular classification must be stored, transmitted, processed, and destroyed
DowngradingThe process of changing information to a lower classification level when the sensitivity decreases
UpgradingThe process of changing information to a higher classification level when the sensitivity increases
ReclassificationThe general process of changing an information's classification level, either up or down
Need-to-KnowThe principle that information should only be accessible to those who require it for legitimate business purposes
Data MappingThe process of identifying and documenting where data resides, how it flows, and how it is processed across systems
Sensitive Personal DataPersonal data that may reveal sensitive information about an individual, including financial, health, biometric, or genetic data, as defined under the DPDP Act 2023
Data SubjectThe individual to whom personal data relates
Information AssetData, information, or knowledge that has value to the organization and requires protection
Classification AuthorityThe role or individual with the authority to determine, approve, or change information classification
Data LineageThe tracking of data as it flows through an organization from creation to consumption
Metadata TaggingThe application of classification information as metadata to files, emails, and database records for automated enforcement
Visual MarkingThe physical or digital marking of documents with classification indicators (headers, footers, stamps, watermarks)

Relationship to Other Controls

ControlRelationship
A.5.8, Information and Other AssetsClassification identifies the sensitivity of assets discovered through A.5.8.
A.5.9, Inventory of Information and Other AssetsThe inventory records classification levels for all assets.
A.5.10, Acceptable Use of InformationThe AUP enforces handling rules based on classification.
A.5.11, Return of AssetsClassification determines the handling requirements for returned assets.
A.5.13, Labeling of InformationClassification levels are applied as labels to information.
A.5.14, Information TransferClassification determines how information may be transferred and to whom.
A.5.15, Access ControlClassification drives access control decisions and least-privilege implementation.
A.5.34, Privacy and Protection of PIIClassification identifies personal data requiring enhanced privacy protection.
A.6.3, Information Security Awareness TrainingClassification is a primary training topic; employees must understand classification responsibilities.
A.8.14, Information BackupClassification determines backup frequency, retention, and encryption requirements.
A.8.15, LoggingClassification determines which systems and data access must be logged.
A.8.16, Monitoring ActivitiesClassification determines which assets require enhanced monitoring.
A.8.24, Use of Cryptographic ControlsClassification determines which data requires encryption.
A.8.25, Secure Development Life CycleClassification determines security requirements for different code and data types.
A.8.34, Outsourced DevelopmentClassification determines what data can be shared with third-party developers.
ControlRelationship
A.5.7, Threat IntelligenceClassification helps prioritize threat intelligence application to specific data types.
A.5.18, Information Security in ICT Supply ChainClassification determines what data can be shared with supply chain partners.
A.5.19, Information Security in Supplier RelationshipsClassification determines security requirements for supplier data handling.
A.5.21, Managing Information Security in ICTClassification informs cloud security and outsourcing decisions.
A.5.24, Information Security Incident ManagementClassification determines incident response severity and escalation.
A.5.28, Redundancy of Information Processing FacilitiesClassification determines availability requirements and redundancy needs.
A.6.2, Terms and Conditions of EmploymentEmployment contracts may include classification handling obligations.
A.7.1, Physical Security PerimetersClassification determines physical protection requirements for information storage.
A.8.1, User Endpoint DevicesClassification determines endpoint protection requirements.
A.8.8, Management of Technical VulnerabilitiesClassification prioritizes patching for systems handling sensitive data.
A.8.22, Development, Testing & Production EnvironmentsClassification determines data handling rules across environments.
A.8.23, Web FilteringClassification may influence what web services can process organizational data.
A.8.28, Secure CodingClassification determines security requirements for code handling different data types.

Implementation Roadmap

Figure · Timeline

First four weeks

  1. Week 1Governance and roles defined
  2. Week 2Scheme and handling rules drafted
  3. Week 3Legal review and approval
  4. Week 4Labelling standards published
The opening month of the roadmap. Deliverables for each week are listed in full below.

Phase 1: Foundation (Weeks 1–4)

WeekActivityDeliverable
1Define classification governance, roles, and authorityClassification charter
2Develop classification scheme with handling rulesClassification policy draft
3Legal review and stakeholder approvalApproved classification policy
4Develop labeling standards and templatesLabeling guide and templates

Phase 2: Pilot and Validation (Weeks 5–10)

WeekActivityDeliverable
5–6Select pilot department and classify all informationPilot classification report
7–8Validate classification with data owners and security teamValidation feedback and adjustments
9–10Refine handling rules and develop training materialsFinalized handling rules and training content

Phase 3: Enterprise Rollout (Weeks 11–18)

WeekActivityDeliverable
11–12Deploy classification tools (DLP, auto-classification)Tool deployment and configuration
13–14Train all employees and data ownersTraining completion records
15–16Classify all critical and high-value informationCritical data classification report
17–18Integrate classification with DLP, IAM, and email securityIntegration verification

Phase 4: Continuous Improvement (Ongoing)

FrequencyActivityDeliverable
MonthlyReview classification accuracy and DLP alertsMonthly classification report
QuarterlyAudit classification compliance and update rulesQuarterly audit report
Bi-annuallyRefresher training and awareness campaignsTraining records
AnnuallyComplete classification scheme reviewAnnual review report
Event-triggeredReclassification for M&A, regulatory changes, incidentsUpdated classification records

Detailed Guidance

Figure · Matrix

Where each tier may be stored

On-premCloudEndpointMobile
PublicFile sharesAny approvedAllowedAllowed
InternalAccess-controlledBasic controlsEncryptedPassword
ConfidentialEncrypted shareCASB + DLPEncrypted onlyMDM only
RestrictedMonitoredPrivate cloudNot allowedNot allowed
Storage permissions by classification. The full rules, including cloud control requirements, are in the table below.

Designing the Classification Scheme

The classification scheme must be simple enough for employees to understand and use, yet complete enough to cover all information types. A typical 4-tier scheme:

Level 1, Public

  • Definition: Information intended for public disclosure with no restriction on distribution
  • Examples: Marketing materials, website content, press releases, published annual reports, job postings, public APIs
  • Handling Rules:
    • No access restrictions required
    • Standard integrity controls (prevent unauthorized modification)
    • Standard availability controls (backup, basic redundancy)
    • No encryption required for storage or transmission
    • Can be shared with anyone, including media and public
  • Label: PUBLIC or no label

Level 2, Internal

  • Definition: Information for internal use only, not intended for public disclosure but not highly sensitive
  • Examples: Internal memos, HR policies, training materials, organizational charts, operational procedures, internal newsletters, meeting minutes (non-sensitive)
  • Handling Rules:
    • Access limited to employees and authorized contractors
    • Authentication required for access
    • Standard backup and retention (3–7 years)
    • Encryption not required for internal transmission
    • Not to be shared with external parties without authorization
    • Can be printed for internal use; secure disposal recommended but not mandatory
  • Label: INTERNAL

Level 3, Confidential

  • Definition: Sensitive information whose unauthorized disclosure could cause significant harm to the organization, customers, or partners
  • Examples: Customer data, financial records, contracts, source code, employee personal data, strategic plans, product designs, licensing information, vendor agreements, audit reports
  • Handling Rules:
    • Access strictly limited to individuals with business need-to-know
    • Multi-factor authentication required for access
    • Encryption required for storage and external transmission
    • DLP monitoring and prevention for exfiltration
    • Enhanced logging and access monitoring
    • Secure printing and disposal (shredding)
    • External sharing requires approval and encryption
    • Backup with encryption and restricted access
    • Retention per legal/regulatory requirements (typically 7+ years)
  • Label: CONFIDENTIAL

Level 4, Restricted

  • Definition: Highly sensitive information whose unauthorized disclosure could cause severe harm, including regulatory penalties, competitive damage, or national security implications
  • Examples: M&A plans, board strategy documents, encryption keys, customer payment data (CHD), source code for critical systems, classified government data, trade secrets, customer biometric data, passwords and credentials, incident response details during active investigation
  • Handling Rules:
    • Minimal access, only specifically authorized individuals
    • Strong encryption (AES-256) for storage and transmission
    • Multi-factor authentication with strong factors (hardware tokens, biometrics)
    • Compartmentalized access (no bulk access, per-document authorization)
    • Enhanced monitoring with real-time alerting
    • No external transmission without CISO and legal approval
    • Secure printing with watermarking and tracking
    • Physical storage in secure areas with access logging
    • Mandatory secure disposal with certificate
    • Segregated backup with enhanced access controls
    • Regular access recertification (quarterly)
  • Label: RESTRICTED

Classification Authority and Governance

Classification Authority Levels:

LevelAuthorityScope
Level 1 (Default)Information Creator / UserPublic and Internal information they create
Level 2 (Department)Data Owner / Department HeadConfidential information within their domain
Level 3 (Organization)CISO / Data Protection OfficerRestricted information and cross-departmental classification
Level 4 (Executive)CEO / BoardStrategic, M&A, and board-level information
Level 5 (Legal)General Counsel / LegalLitigation-related, privileged, and legally sensitive information

Classification Governance Process:

  1. Default Classification: New information is classified at creation based on the creator's judgment and default rules
  2. Review and Validation: Data owners review and validate classification for their domain
  3. Escalation: Uncertain cases are escalated to the CISO or classification committee
  4. Dispute Resolution: Disagreements on classification are resolved by the classification committee (CISO, Legal, Data Owner)
  5. Periodic Review: All classifications are reviewed annually or upon significant business changes
  6. Reclassification: Changes to classification level require approval and documentation

Classification by Data Type

Different data types have inherent classification requirements:

Data TypeDefault ClassificationRationale
Customer PIIConfidentialDPDP Act requirements; customer trust; regulatory obligations
Customer Financial DataRestrictedRBI/SEBI requirements; fraud risk; high impact of breach
Payment Card Data (CHD)RestrictedPCI DSS requirements; severe breach impact; criminal liability
Employee PIIConfidentialPrivacy requirements; employee trust; legal obligations
Employee Salary DataConfidentialPrivacy; employee relations; competitive sensitivity
Source CodeConfidentialIntellectual property; competitive advantage; security risk
Cryptographic KeysRestrictedFoundation of security; catastrophic impact if compromised
Strategic PlansRestrictedCompetitive advantage; market impact; board-level sensitivity
Financial Statements (Unpublished)ConfidentialRegulatory requirements; market sensitivity; investor relations
Financial Statements (Published)PublicAlready disclosed; no confidentiality requirement
ContractsConfidentialLegal obligations; commercial sensitivity; third-party relationships
Vulnerability ReportsConfidentialSecurity risk; attacker utility; responsible disclosure obligations
Incident Details (Active)RestrictedInvestigation integrity; attacker awareness; legal privilege
Incident Details (Closed)ConfidentialLessons learned; regulatory reporting; customer notification
Marketing Materials (Draft)InternalWork in progress; not approved for external release
Marketing Materials (Published)PublicApproved for public consumption
Research DataConfidentialIntellectual property; competitive advantage; regulatory requirements
Health RecordsConfidentialPatient privacy; medical ethics; regulatory requirements
Government Classified DataRestrictedNational security; legal obligations; severe penalties
Trade SecretsRestrictedCompetitive survival; legal protection; economic value

Automated Classification Tools and Techniques

Pattern-Based Classification:

  • Regular expression matching for PII (Aadhaar numbers, PAN, passport numbers, phone numbers, email addresses)
  • Keyword matching for sensitive topics ("confidential," "restricted," "password," "proprietary")
  • Dictionary matching for financial terms, medical terms, legal terms
  • Template matching for document types (contracts, invoices, medical records)

Machine Learning Classification:

  • Content-based classification using NLP and text analysis
  • Behavioral classification based on user access patterns
  • Contextual classification considering document location, author, and recipients
  • Image classification for scanned documents and screenshots
  • Sentiment and topic analysis for classification suggestions

Metadata-Based Classification:

  • Author department classification (e.g., Finance documents default to Confidential)
  • File location classification (e.g., files in "Board" folder default to Restricted)
  • Email domain classification (e.g., external recipient emails suggest higher classification)
  • Application context (e.g., CRM data defaults to Confidential)

DLP Integration:

  • DLP policies trigger automatic classification suggestions
  • DLP blocks or warns when data is handled contrary to its classification
  • DLP scans discover unclassified sensitive data and suggest classifications
  • DLP reports help identify misclassified data through violation patterns

Labeling and Visual Marking

Document Labeling Standards:

  • Header: Classification level at the top of every page (e.g., "CONFIDENTIAL, [Organization Name]")
  • Footer: Classification level at the bottom of every page
  • Watermark: Semi-transparent classification marking for highly sensitive documents (especially when printed or shared)
  • Email Subject: Prefix classification to email subject lines (e.g., "[CONFIDENTIAL] Q3 Financial Review")
  • File Metadata: Classification embedded in document properties (Word, PDF, Excel)
  • Database Fields: Classification tags in database metadata or data catalogs
  • Physical Documents: Color-coded stamps or labels on physical folders and documents

Color Coding Scheme (Example):

ClassificationColorHex CodeUsage
PublicGreen#28a745No restrictions, freely shareable
InternalBlue#007bffInternal use, standard protection
ConfidentialOrange#fd7e14Sensitive, controlled access
RestrictedRed#dc3545Highly sensitive, minimal access

Email Classification Rules:

  • All emails containing Confidential or Restricted attachments must have classification in the subject line
  • External emails containing Confidential data must be encrypted
  • Auto-classification plugins can scan email content and suggest classification
  • Distribution lists must be labeled with maximum classification they can handle

Handling Rules by Classification Level

Storage Rules:

ClassificationOn-Premises StorageCloud StorageEndpoint StorageMobile Storage
PublicStandard file sharesAny approved cloudAllowedAllowed
InternalStandard file shares with access controlApproved cloud with basic controlsAllowed with encryptionAllowed with password
ConfidentialEncrypted file shares with access controlApproved cloud with encryption, CASB, DLPEncrypted onlyNot allowed without MDM
RestrictedEncrypted, access-controlled, monitoredPrivate cloud/air-gapped onlyNot allowedNot allowed

Transmission Rules:

ClassificationEmailInstant MessagingFile TransferCloud Sharing
PublicAllowedAllowedAllowedAllowed
InternalAllowedAllowedAllowedAllowed with approved tools
ConfidentialEncrypted onlyApproved secure channels onlyEncrypted SFTP/FTPS onlyApproved secure sharing with access controls
RestrictedNot allowed (unless encrypted with legal approval)Not allowedDedicated secure transfer onlyNot allowed

Printing Rules:

ClassificationPrintingMarkingDisposal
PublicAllowedNo markingStandard recycling
InternalAllowedOptional headerStandard recycling
ConfidentialAllowed with loggingMandatory header/footerSecure shredding
RestrictedRestricted with approvalMandatory header/footer/watermarkSecure shredding with certificate

Disposal Rules:

ClassificationDigital DisposalPhysical DisposalRetention Period
PublicStandard deletionRecyclingPer business need
InternalStandard deletionRecycling3–7 years
ConfidentialSecure deletion (overwrite)Shredding7–10 years (or per regulation)
RestrictedCryptographic erase or physical destructionCertified shredding/destruction10+ years (or per regulation)

Data Mapping and Classification

Classification requires understanding where data flows:

Data Mapping Process:

  1. Identify Data Sources: Where is data created or collected? (Forms, sensors, APIs, manual entry, imports)
  2. Map Data Flows: How does data move between systems, departments, and external parties?
  3. Identify Storage Locations: Where is data stored at rest? (Databases, file shares, cloud, backups, archives)
  4. Identify Processing Points: Where is data transformed, analyzed, or enriched?
  5. Identify Access Points: Who accesses the data and through what channels?
  6. Identify Disposal Points: Where and how is data deleted or archived?
  7. Apply Classification: Assign classification to each data element based on its sensitivity and regulatory requirements
  8. Document Dependencies: Note systems and processes that depend on the data

Data Mapping Tools:

  • Microsoft Purview Data Map
  • OneTrust Data Mapping
  • BigID Data Intelligence
  • Informatica Data Catalog
  • Custom spreadsheets and diagrams for smaller organizations

Third-Party and Cloud Data Classification

Classification extends to data shared with third parties:

Cloud Service Classification:

  • Public data: Can be stored on any reputable cloud service
  • Internal data: Can be stored on approved cloud services with standard controls
  • Confidential data: Can be stored on approved cloud services with encryption, CASB, and contractual controls
  • Restricted data: Requires private cloud, dedicated instances, or on-premises storage with enhanced contractual controls

Third-Party Sharing Requirements:

  • Public data: No special requirements for sharing
  • Internal data: NDA required; standard contractual terms
  • Confidential data: Enhanced security addendum; encryption required; audit rights; DPA under DPDP Act
  • Restricted data: Dedicated security agreement; encryption mandatory; no subprocessors without approval; regular audits; limited data sets; strict return/destruction requirements

Data Residency and Classification:

  • DPDP Act and sectoral regulations may require certain data to remain in India
  • Classification determines which data is subject to data localization requirements
  • Cloud service selection must consider data residency requirements for each classification level

Tools and Technologies

Data Classification Platforms

PlatformTypeKey Featureslicensing Range
Microsoft PurviewEnterprise data governanceAuto-classification, data catalog, sensitivity labels, DLP integration, compliance scoringIncluded in Microsoft 365 E5 / –/user/year

DLP with Classification Integration

ToolClassification IntegrationKey Features
Microsoft Purview DLPNative sensitivity labelsDLP policies based on classification labels, auto-classification, endpoint, cloud, email
Symantec DLPCustom classification fieldsContent-aware detection, policy-based classification, integration with Titus/Boldon James
Forcepoint DLPClassification taggingUser-driven classification, automated detection, behavioral analytics
Digital GuardianEndpoint classificationContent classification, endpoint enforcement, cloud DLP
NetskopeCASB + classificationCloud data classification, SaaS DLP, shadow IT discovery
ProofpointEmail classificationEmail DLP with classification, encryption integration
MimecastEmail classificationContent classification, email security, data leak prevention

Open-Source and lightweight Options

ToolPurposeoverhead
Custom Scripts (Python/PowerShell)Pattern-based classificationFree (development time)
OpenDLPOpen-source data discoveryFree
grep/awk/sedBasic pattern matchingFree
Elastic StackLog-based data discoveryFree (open-source)
OpenMetadataOpen-source data governanceFree (open-source)
Apache AtlasOpen-source metadata managementFree (open-source)
Amundsen (Lyft)Open-source data catalogFree (open-source)
DataHub (LinkedIn)Open-source metadata platformFree (open-source)

Policy Templates and Documentation

Information Classification Policy (Template)

Template

Data Type Classification Matrix (Template)

Template

Handling Rules Matrix (Template)

Template


Risk Assessment

Figure · Risk grid

Classification risks by likelihood and impact

Very high11
High1
Medium2
MediumHigh

Likelihood across · impact up

  • Under-protecting sensitive dataHigh/Very high
  • Regulatory non-complianceHigh/High
  • Over-protecting low-value dataHigh/Medium
  • Inefficient security spendingHigh/Medium
  • Breach with severe impactMedium/Very high
The five risks this control addresses, plotted from the risk register below. Treatments are listed against each.

Risks of Inadequate Classification

RiskLikelihoodImpactRisk ScoreMitigation
Over-protection of low-value dataHighMediumMediumImplement classification scheme with proportionate controls
Under-protection of sensitive dataHighVery HighCriticalImplement classification with appropriate handling rules
Regulatory non-complianceHighHighCriticalAlign classification with regulatory requirements
Inefficient security spendingHighMediumHighRight-size controls based on classification
Data breach with severe impactMediumVery HighCriticalEnsure sensitive data receives enhanced protection
Inability to respond to incidentsHighHighCriticalClassification enables incident prioritization
Customer trust erosionMediumHighHighProtect customer data with appropriate classification
Competitive disadvantageMediumHighHighProtect trade secrets and strategic information
Audit failuresHighMediumHighDemonstrate classification-based control implementation
Employee confusionMediumMediumMediumTrain employees on classification scheme and rules

Risks of Classification Process

RiskLikelihoodImpactRisk ScoreMitigation
MisclassificationMediumHighHighTrain users, validate classifications, implement review
Overly complex schemeMediumMediumMediumKeep scheme simple (3–4 tiers maximum for most organizations)
Inconsistent applicationMediumHighHighAutomated tools, training, monitoring, enforcement
Classification fatigueMediumLowLowAutomate where possible, simplify manual processes
Labeling errorsMediumMediumMediumAutomated labeling, validation checks
Resistance to classificationMediumMediumMediumTraining, executive endorsement, demonstrate value

Risk Treatment Plan

RiskTreatmentOwnerTimeline
Under-protectionDeploy classification with DLP and access controlsCISO2 months
MisclassificationTrain users and implement validation workflowCISO2 months
Regulatory non-complianceAlign classification with regulatory requirementsCompliance Officer1 month
Inconsistent applicationDeploy automated classification toolsSecurity Manager3 months
Overly complex schemeSimplify to 3–4 tiers with clear handling rulesCISO1 month

Audit and Assessment Checklist

Documentation Review

  • Is there a documented Information Classification Policy?
  • Is the classification scheme clearly defined (3–4 tiers with descriptions)?
  • Are handling rules documented for each classification level?
  • Is there a Data Type Classification Matrix?
  • Are classification roles and responsibilities defined (creator, owner, CISO)?
  • Is there a classification dispute resolution process?
  • Is there a reclassification process with approval requirements?
  • Are labeling requirements documented?
  • Is there training material on classification?
  • Is there evidence of annual policy review?
  • Are handling rules aligned with regulatory requirements?
  • Is there a classification committee or governance structure?

Implementation Review

  • Is there evidence that information is being classified at creation?
  • Are classification labels visible on documents, emails, and systems?
  • Is there evidence of data owner validation of classifications?
  • Are DLP policies aligned with classification levels?
  • Are access controls proportionate to classification levels?
  • Is there evidence of encryption for Confidential and Restricted data?
  • Are there secure disposal procedures for Confidential and Restricted data?
  • Is there evidence of classification training delivery?
  • Are classification metrics tracked and reviewed?
  • Is there evidence of misclassification detection and correction?
  • Are third-party data sharing agreements aligned with classification?
  • Is there evidence of cloud storage classification enforcement?

Effectiveness Review

  • What percentage of information is classified? (Target: ≥95% of identified information)
  • What is the classification accuracy rate? (Target: ≥90%)
  • How many misclassifications are detected per quarter? (Target: decreasing trend)
  • Are DLP violations correlated with classification levels?
  • Is there evidence of overhead optimization from classification?
  • Are incidents appropriately prioritized based on classification?
  • Is there evidence of regulatory compliance based on classification?
  • Do employees understand and correctly apply the classification scheme?
  • Are there any unclassified sensitive data repositories?
  • Is the classification scheme still appropriate for the business?

Metrics and KPIs

Figure · Measures

The five measures that matter

  • Classification coverage≥95%Quarterly
  • New documents classified≥90%Monthly
  • Unclassified sensitive stores0Quarterly
  • Correct by data type≥95%Quarterly
  • Cloud resources tagged≥95%Monthly
Targets and cadence as defined in the KPI table. Formulas for each are given below.

Classification Coverage Metrics

KPIFormulaTargetFrequency
Classification Coverage Rate% of identified information assets with assigned classification≥95%Quarterly
New Information Classification Rate% of new documents/emails classified at creation≥90%Monthly
Unclassified Sensitive DataCount of sensitive data repositories without classification0Quarterly
Classification by Data Type% of each data type with correct classification≥95%Quarterly
Cloud Asset Classification% of cloud resources with classification tags≥95%Monthly

Classification Accuracy Metrics

KPIFormulaTargetFrequency
Classification Accuracy% of classifications verified as correct during audit≥90%Quarterly
Misclassification Detection RateNumber of misclassifications detected and correctedIncreasing trendMonthly
DLP Correlation Accuracy% of DLP alerts correctly aligned with classification≥95%Monthly
Access Control Alignment% of access controls aligned with classification≥95%Quarterly
Reclassification RateNumber of reclassifications per quarterStable or decreasingQuarterly

Operational Metrics

KPIFormulaTargetFrequency
Encryption Coverage% of Confidential/Restricted data encrypted100%Monthly
DLP Policy Coverage% of classified data under DLP monitoring≥90%Monthly
Secure Disposal Compliance% of Confidential/Restricted data disposed securely100%Quarterly
Access Review Compliance% of classified systems with completed access reviews100%Quarterly
Labeling Compliance% of documents with appropriate classification labels≥90%Monthly

Training and Awareness Metrics

KPIFormulaTargetFrequency
Training Completion Rate% of employees completing classification training≥95%Quarterly
Training Pass Rate% of employees passing classification knowledge test≥90%Per training
Classification Question VolumeNumber of classification clarification requestsIndicator of clarityMonthly
Self-Reported MisclassificationNumber of employees reporting misclassificationIncreasing trendMonthly

Business Impact Metrics

KPIFormulaTargetFrequency
Security overhead EfficiencySecurity spend per classification tier vs. risk reductionOptimizingAnnual
Incident Response TimeTime to respond by classification level≤2 hours for RestrictedPer incident
Compliance Audit FindingsNumber of classification-related audit findings0Annual
Data Breach Impact by ClassificationActual breach impact vs. predicted by classificationAlignedPer incident
Storage overhead OptimizationSavings from classification-based retention≥Annual

Common Pitfalls and How to Avoid Them

Too Many Classification Tiers

Pitfall: Creating 6–8 classification levels that confuse employees and create inconsistent application. Impact: Employees cannot remember or apply the scheme; misclassification increases; scheme becomes meaningless. Solution: Use 3–4 tiers maximum for most organizations. Public, Internal, Confidential, and Restricted cover 95% of needs. If you need more granularity, use sub-labels or metadata rather than additional tiers.

No Clear Handling Rules

Pitfall: Defining classification levels but not defining what each level means in practice for storage, transmission, printing, and disposal. Impact: Employees know something is "Confidential" but don't know what to do differently; controls are not implemented; policy is ineffective. Solution: Create detailed handling rules matrices for each classification level. Make rules concrete and actionable. Provide examples and scenarios in training.

Inconsistent Application

Pitfall: Different departments or individuals apply classification differently, creating inconsistency across the organization. Impact: Some data is over-protected, some under-protected; compliance gaps; audit findings; employee confusion. Solution: Implement automated classification tools where possible. Provide clear data type classification matrix. Train all employees. Monitor and enforce consistency. Use classification committee for disputes.

Lack of Executive Support

Pitfall: Classification is treated as an IT or security project without executive endorsement and modeling. Impact: Employees ignore classification; executives don't classify their documents; policy lacks authority. Solution: Obtain board/CEO approval for classification policy. Executives must model classification behavior. Include classification in executive communications. Make classification a board-reporting topic.

Ignoring Regulatory Alignment

Pitfall: Classification scheme is designed without considering regulatory requirements (DPDP Act, RBI, SEBI, PCI DSS). Impact: Regulatory non-compliance; penalties; inability to demonstrate appropriate controls; audit failures. Solution: Map regulatory requirements to classification levels. Involve compliance and legal in scheme design. Align handling rules with regulatory requirements. Review scheme when regulations change.

No Automated Enforcement

Pitfall: Classification is manual only, with no technical enforcement through DLP, access controls, or encryption. Impact: Classification relies on user compliance, which is inconsistent; sensitive data is not protected; policy becomes a suggestion rather than a control. Solution: Integrate classification with DLP, IAM, encryption, and email security. Implement automated classification tools. Use metadata tags for system enforcement. Monitor and alert on violations.

Failure to Review and Update

Pitfall: Classification scheme is implemented once and never reviewed, becoming outdated as business and regulations change. Impact: Classifications no longer reflect reality; new data types are unclassified; regulatory requirements are missed. Solution: Annual complete review. Event-triggered reviews for M&A, regulatory changes, and major incidents. Quarterly data owner reviews. Track classification currency metrics.

Over-Reliance on User Classification

Pitfall: Expecting users to manually classify all documents without automated assistance or validation. Impact: Users forget to classify, misclassify, or classify everything at the lowest level to avoid hassle. Solution: Deploy automated classification tools. Set default classifications by data type and location. Implement classification suggestions in email and document tools. Require classification before saving or sending. Use DLP to detect and remediate misclassification.

Neglecting Physical Documents

Pitfall: Classification focuses only on digital data, ignoring printed documents, whiteboards, and physical files. Impact: Sensitive information is exposed through printed documents, meeting room whiteboards, and physical files. Solution: Apply classification to physical documents with color-coded labels and stamps. Implement clean desk policy. Use secure printing for Confidential and Restricted. Provide secure disposal (shredding) bins. Train on physical data protection.

No Third-Party Classification Requirements

Pitfall: Classification stops at the organizational boundary, with no requirements for third parties handling organizational data. Impact: Sensitive data shared with vendors is not protected according to classification; supply chain breaches expose classified data. Solution: Extend classification requirements to contracts and NDAs. Require third parties to implement equivalent controls. Audit third-party classification compliance. Include classification in data sharing agreements.


Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian Private Bank, Classification Drives Regulatory Compliance and efficiency gains

Organization: Private sector bank with 200 branches, 5,000 employees, 2 million customers Sector: Banking and Financial Services (Regulated by RBI) Challenge: The bank had grown rapidly through acquisitions and digital expansion. Data was stored across 40+ systems with no consistent classification. The RBI cybersecurity examination identified this as a major gap, noting that the bank could not demonstrate differentiated protection for customer financial data vs. marketing materials. The bank was at risk of regulatory penalties and was overspending on uniform protection for all data.

Implementation:

  • Phase 1 (Weeks 1–4): Formed a cross-functional classification committee (CISO, CFO, Legal, Retail Banking Head, Compliance). Defined a 4-tier classification scheme aligned with RBI requirements and DPDP Act provisions.
  • Phase 2 (Weeks 5–10): Conducted data discovery across all 40+ systems using Microsoft Purview and manual surveys. Mapped all customer data, financial records, employee data, and operational information. Created a Data Type Classification Matrix with 45 data types.
  • Phase 3 (Weeks 11–16): Deployed automated classification with sensitivity labels in Microsoft 365. Integrated DLP policies with classification levels. Implemented encryption policies for Confidential and Restricted data. Rolled out training to all 5,000 employees with department-specific scenarios.
  • Phase 4 (Weeks 17–22): Validated classification accuracy through sampling and audit. Adjusted handling rules based on user feedback. Integrated classification with access controls and privileged access management. Established quarterly review process.

Results:

  • Regulatory compliance: Passed RBI cybersecurity examination with zero classification-related findings. RBI examiner noted the classification scheme as "best practice" for mid-sized banks.
  • overhead optimization: Identified that 72% of stored data was Internal or Public, requiring only standard controls. Reduced unnecessary encryption and monitoring overhead by s annually.
  • Enhanced protection: Customer financial data (22% of data) was classified as Restricted and received enhanced encryption, monitoring, and DLP. Payment card data (3%) received PCI DSS-aligned controls.
  • Incident response: When a phishing incident affected 12 employees, classification enabled rapid identification that only Internal data was at risk, no customer data exposure. Response time was 2 hours vs. previous average of 8 hours.
  • DPDP Act readiness: Classification mapped directly to personal data and sensitive personal data requirements, enabling rapid compliance assessment.
  • Employee adoption: 94% of employees correctly classified test scenarios after training. Classification questions to help desk decreased by 60% after 6 months.

Key Success Factors:

  • Cross-functional committee ensured business buy-in and regulatory alignment
  • Automated tools reduced manual classification burden and improved consistency
  • RBI alignment from the start ensured regulatory acceptance
  • efficiency gains provided business case justification beyond compliance
  • Training with real bank scenarios (customer data, loan applications, transaction records) made it relevant

Lessons Learned:

  • Banking classification must align with RBI from day one, retrofitting is harder
  • Automated classification is essential at scale, manual only works for small organizations
  • efficiency gains from right-sizing protection can fund the classification program
  • Data discovery often reveals surprising data locations ( shadow databases, Excel files with customer data)
  • Physical documents in branches are often the biggest classification gap

Quote from CISO:

"We went from treating every document like a state secret to knowing exactly what needs protection. Our customer data is safer, our overhead are lower, and the RBI actually praised us. Classification isn't just security, it's smart business."


Illustrative Scenario 2: Indian Healthcare Technology Company, Classification Enables DPDP Compliance and Patient Trust

Organization: Health tech startup (250 employees) providing telemedicine platform and patient management system to 300+ clinics and 15 hospitals Sector: Healthcare / Information Technology Challenge: The company processed health records, patient PII, doctor consultation notes, and payment data across cloud services, mobile apps, and third-party integrations. With the DPDP Act 2023 approaching, the company needed to demonstrate that it could identify and protect sensitive personal data. A previous data breach (unrelated to classification) had damaged patient trust, and the company needed to rebuild confidence.

Implementation:

  • Phase 1 (Weeks 1–3): Engaged Singahi to design a healthcare-specific classification scheme. Defined 4 tiers with special attention to health data, patient PII, and payment data. Aligned with DPDP Act definitions of personal data and sensitive personal data.
  • Phase 2 (Weeks 4–8): Deployed BigID for sensitive data discovery across AWS, Azure, MongoDB databases, and file storage. Discovered 18 unencrypted S3 buckets containing patient consultation recordings, 3 test databases with production patient data, and 45 employee laptops with downloaded patient records.
  • Phase 3 (Weeks 9–14): Implemented automated classification with field-level tagging in the patient database. Health records were classified as Restricted, patient PII as Confidential, appointment schedules as Internal, and marketing content as Public. Deployed DLP to prevent exfiltration of Restricted and Confidential data.
  • Phase 4 (Weeks 15–18): Trained all staff (clinical and technical) on healthcare-specific classification. Clinical staff learned to classify consultation notes and prescriptions. Technical staff learned to classify code, configuration, and system data. Implemented secure disposal for printed patient records in clinics.
  • Phase 5 (Weeks 19–24): Validated classification through internal audit. Updated all third-party agreements (payment processor, cloud provider, analytics vendor) with classification-based security requirements. Published patient-facing transparency report on data protection.

Results:

  • DPDP Act readiness: Complete data mapping and classification enabled the company to demonstrate "reasonable security safeguards" for personal data. Data subject access requests could be fulfilled within 48 hours because the company knew exactly where each patient's data resided.
  • Patient trust recovery: Published transparency report citing classification-based protection. Patient acquisition increased by 25% in the following quarter, attributed to improved data protection reputation.
  • Breach prevention: DLP blocked 340 data exfiltration attempts in the first 6 months, 90% of which were classified as Confidential or Restricted. All attempts were investigated; none resulted in data loss.
  • Operational efficiency: Classification enabled the company to prioritize security investments. The 15% of data classified as Restricted received 60% of security budget, while the 35% classified as Internal received standard controls. Total security spend was optimized by ** annually**.
  • Compliance expansion: The classification framework enabled rapid compliance with new partner requirements (a major hospital chain required proof of patient data classification as a condition of partnership).
  • Incident response: When a clinic employee accidentally emailed patient records to the wrong recipient, classification enabled immediate identification of the data scope (15 patients, Confidential classification) and appropriate notification within 24 hours.

Key Success Factors:

  • Healthcare-specific classification was essential, generic schemes don't address patient data nuances
  • Clinical staff engagement was critical, they are the creators of the most sensitive data
  • BigID discovery revealed hidden risks that would have been missed by manual surveys
  • Third-party agreement updates extended classification protection beyond organizational boundaries
  • Transparency reporting converted security investment into marketable patient trust

Lessons Learned:

  • Health data classification must be designed with clinical workflows in mind, not imposed from IT
  • Field-level classification in databases is more useful than document-level for healthcare
  • Patient trust is a competitive advantage that classification can enable
  • DPDP Act compliance is easier when classification is implemented before the law is fully enforced
  • Third-party integrations (payment, analytics, telephony) are often the weakest link in healthcare data protection

Quote from Chief Medical Officer:

"Our doctors create life-saving data every day. Classification protects that data without getting in the way of patient care. Our patients trust us more because they know we take their privacy seriously. The DPDP Act compliance was almost automatic once we had classification in place."


Multi-Framework Mapping

NIST CSF 2.0 Mapping

NIST CSF FunctionCategorySubcategoryMapping to A.5.12
IDENTIFY (ID)ID.AMID.AM-07Data assets are identified and classified
GOVERN (GV)GV.POGV.PO-01Classification policy informs organizational security policy
GOVERN (GV)GV.POGV.PO-02Classification establishes security rules and expectations
PROTECT (PR)PR.DSPR.DS-01Classification supports data protection through differentiated controls
PROTECT (PR)PR.DSPR.DS-02Classification drives data-at-rest protection
PROTECT (PR)PR.DSPR.DS-05Classification informs data protection measures
PROTECT (PR)PR.ACPR.AC-01Classification supports access control decisions
PROTECT (PR)PR.ACPR.AC-04Classification enables access permissions management
DETECT (DE)DE.CMDE.CM-01Classification determines monitoring scope and priority
RESPOND (RS)RS.ANRS.AN-05Classification supports incident analysis and prioritization

PCI DSS v4.0 Mapping

PCI DSS RequirementMapping to A.5.12
3.1, Data retentionClassification identifies CHD and SAD requiring retention limits
3.2, Sensitive authentication dataClassification identifies SAD and its handling requirements
3.3, Masking PANClassification drives masking requirements for cardholder data
3.4, Rendering PAN unreadableClassification determines encryption requirements for PAN
12.3.1, Asset inventoryClassification is part of asset inventory for CHD environment
12.3.2, Asset managementClassification supports management of assets with CHD

SOC 2 Type II Mapping

TSC CategoryMapping to A.5.12
CC1.1, Integrity and ethical valuesClassification establishes ethical handling expectations
CC2.1, Communication methodsClassification communicates security expectations
CC6.1, Logical access securityClassification drives logical access decisions
CC6.2, Access removalClassification supports access removal based on data sensitivity
CC7.1, System monitoringClassification determines monitoring scope
CC7.2, Incident detectionClassification enables incident prioritization
CC9.1, Risk identificationClassification identifies risks related to data sensitivity
CC9.2, Risk assessmentClassification enables risk assessment
CC9.3, Risk mitigationClassification drives mitigation priorities

COBIT 2019 Mapping

COBIT DomainCOBIT ComponentMapping to A.5.12
APO12, Managed RiskAPO12.01Classification supports risk identification
APO13, Managed SecurityAPO13.01Classification is part of security management
APO14, Managed DataAPO14.01Data classification and protection
APO14, Managed DataAPO14.02Data classification scheme management
APO14, Managed DataAPO14.03Data lifecycle management based on classification
APO14, Managed DataAPO14.04Data security and privacy based on classification
DSS01, Managed OperationsDSS01.04Operational security based on data classification
DSS05, Managed Security ServicesDSS05.02Security service management based on classification
MEA01, Managed PerformanceMEA01.02Performance monitoring of classification effectiveness

CIS Controls v8 Mapping

CIS ControlSafeguardMapping to A.5.12
Control 3, Data Protection3.1Establish and maintain data inventory
Control 3, Data Protection3.2Classify data according to sensitivity
Control 3, Data Protection3.3Implement data protection based on classification
Control 3, Data Protection3.4Encrypt sensitive data at rest
Control 3, Data Protection3.5Encrypt sensitive data in transit
Control 3, Data Protection3.6Implement data loss prevention
Control 3, Data Protection3.7Implement data retention and disposal
Control 6, Access Control Management6.1Access control based on data classification
Control 14, Security Awareness14.1Training on data classification and handling
Control 17, Incident Response17.1Incident response based on data classification

RBI Cybersecurity Framework Mapping

RBI RequirementMapping to A.5.12
Asset ManagementRBI requires banks to classify assets based on criticality and sensitivity
Cybersecurity OperationsRBI requires differentiated protection for sensitive customer data
IT GovernanceRBI requires data classification governance and accountability
ComplianceRBI requires classification to demonstrate compliance coverage
Risk AssessmentRBI requires asset-based risk assessment with classification

SEBI Cybersecurity Guidelines Mapping

SEBI RequirementMapping to A.5.12
Information ClassificationSEBI requires classification of market-sensitive information
Access ManagementSEBI requires access controls based on data sensitivity
Incident ManagementSEBI requires prioritization based on data sensitivity
ComplianceSEBI requires demonstration of appropriate data protection

DPDP Act 2023 Mapping

DPDP Act ProvisionMapping
Section 5, NoticeInform data principals about processing covered by this control
Section 6, ConsentObtain and manage consent for personal data processing
Section 8(1), Data Fiduciary responsibilityEnsure accountability for compliance with this control
Section 8(4), Technical and organisational measuresImplement appropriate measures to give effect to this control
Section 8(5), Reasonable security safeguardsProtect personal data through the safeguards in this control
Section 8(6), Personal data breach intimationDetect and notify relevant breaches to the Board and affected principals
Section 8(7), ErasureErase personal data when the purpose is no longer served
Section 8(10), Grievance redressal mechanismEstablish an effective grievance redressal mechanism
Section 9, Children and persons with disabilityApply enhanced safeguards when processing children's personal data
Section 10, Significant Data FiduciaryComply with additional SDF obligations (DPO, auditor, DPIA)
Section 11, Right to access informationEnable data principals to obtain information about their personal data
Section 12, Right to correction and erasureEnable correction, completion, updating and erasure requests
Section 13, Right of grievance redressalProvide readily available grievance redressal
Section 14, Right to nominationSupport nomination of a representative to exercise rights
Section 16, Cross-border transfersApply safeguards when transferring personal data outside India
Section 27, Powers and functions of BoardCooperate with the Data Protection Board of India
Section 33, PenaltiesNon-compliance may attract monetary penalties under the Schedule

Regulatory and Compliance Context

Indian Regulatory Requirements for Data Classification

Digital Personal Data Protection Act, 2023:

  • Distinguishes between "personal data" and "sensitive personal data" (children's data, financial data, health data, biometric data, genetic data, etc.)
  • Sensitive personal data requires enhanced security safeguards and explicit consent
  • Data fiduciaries must implement "reasonable security safeguards", classification is foundational to this
  • Data breach notification requirements differ based on data sensitivity
  • Data subject rights (access, correction, deletion) require knowing where personal data resides
  • Significant Data Fiduciaries have enhanced obligations that classification supports
  • Data Protection Board will expect organizations to demonstrate knowledge of their data processing activities
  • Classification must align with DPDP Act definitions and requirements

Information Technology Act, 2000:

  • Section 43A (prior to DPDP Act) required compensation for failure to protect sensitive personal data
  • Section 72 requires protection of confidentiality and privacy
  • CERT-In directions require protection of sensitive data and incident reporting
  • Classification supports compliance with these obligations

RBI Cybersecurity Framework for Banks:

  • Banks must classify information assets based on criticality and sensitivity
  • Customer data must be classified and protected according to RBI requirements
  • RBI examiners assess classification completeness and accuracy
  • Classification must support business continuity and risk assessment
  • UCBs and NBFCs have proportionate requirements

SEBI Cybersecurity Guidelines:

  • Market Infrastructure Institutions must classify information based on sensitivity
  • Market-sensitive information requires enhanced protection
  • Intermediaries must classify client data and trading information
  • SEBI cybersecurity audits review classification implementation

IRDAI Cybersecurity Guidelines:

  • Insurance companies must classify customer and policy data
  • Classification must support data protection and business continuity
  • Health and financial data require enhanced protection

NCIIPC (for CII):

  • Critical Information Infrastructure entities must classify critical information
  • Classification supports sectoral risk assessment and protection
  • National security data requires highest classification and protection
  • NCIIPC audits review classification completeness

Sectoral Requirements:

  • Telecom (DoT/TRAI): Customer data and network information classification
  • Healthcare (CDSCO/NABH): Patient data classification and protection
  • Government: Classification of official and classified information
  • Defense: Classification of strategic and defense-related information
  • Energy: Classification of critical infrastructure data

International Regulatory Alignment

GDPR (for EU data subjects):

  • Article 9 requires special categories of personal data (health, genetic, biometric, racial, political, religious) to receive enhanced protection
  • Article 32 requires security of processing with regard to state of the art and risk
  • Article 33 requires breach notification within 72 hours, classification enables rapid scoping
  • Article 30 requires records of processing activities, classification provides the "what" and "how sensitive"

PCI DSS:

  • Requirement 3 requires protection of CHD and SAD
  • Classification identifies which systems process, store, or transmit CHD
  • Classification determines scope of PCI DSS assessment (CDE scope)

HIPAA (for US healthcare data):

  • Requires identification of Protected Health Information (PHI)
  • Classification determines which data is subject to HIPAA safeguards
  • Breach notification requirements differ based on data type and volume

Other Frameworks:

  • SOX (Sarbanes-Oxley): Classification of financial reporting data
  • NERC CIP: Classification of critical cyber assets in energy sector
  • APRA CPS 234: Classification of information assets in Australian banking
  • FISMA: Classification of federal information in US government

RACI Matrix

Classification Activities RACI

ActivityBoardCISOData OwnerSecurity ManagerLegalITAll Employees
Strategy and Policy
Define classification strategyARCCCII
Approve classification policyARCCCII
Define classification schemeCACRCII
Implementation
Classify data at creationICACIIR
Validate classificationsICACIII
Deploy automated toolsIACRICI
Integrate with DLP/IAMIACRICI
Develop training materialsCACRCII
Deliver trainingIACRIII
Operations
Monitor classification complianceIACRICI
Investigate misclassificationIACRCII
Review classificationsIARCIII
Reclassify dataCARCCII
Audit and Compliance
Prepare audit evidenceIARRCCI
Respond to findingsARCCCII
Report to managementARCCIII

R = Responsible, A = Accountable, C = Consulted, I = Informed


Documentation and Record Keeping

Required Documentation

DocumentPurposeRetention PeriodOwner
Information Classification PolicyDefines classification scheme and rules7 yearsCISO
Data Type Classification MatrixDefault classifications by data type7 yearsCISO
Handling Rules MatrixStorage, transmission, printing, disposal rules7 yearsCISO
Classification RecordsClassification assignments for all informationDuration + 7 yearsData Owner
Reclassification RecordsChanges to classification with approvals7 yearsCISO
Classification Audit ReportsAccuracy and compliance assessments7 yearsCISO
Training RecordsEmployee training on classification3 yearsHR
DLP Classification RulesTechnical enforcement configurations3 yearsSecurity Manager
Third-Party Classification AgreementsContractual classification requirementsDuration of agreement + 7 yearsLegal
Data Mapping RecordsData flow and location documentation3 yearsData Owner
Classification Committee MinutesGovernance decisions and disputes7 yearsCISO
Annual Review ReportsComplete classification review7 yearsCISO

Record Keeping Best Practices

  • Centralized Repository: Maintain classification records in a centralized system with access control
  • Access Control: Restrict access to classification records based on need-to-know
  • Version Control: Track version history for classification policy and matrices
  • Audit Trail: Maintain complete audit trails for classification changes and decisions
  • Backup: Classification records are critical for compliance and must be backed up
  • Privacy Compliance: Handle personal data in classification records per DPDP Act
  • Legal Privilege: Protect classification records related to litigation or investigation
  • Cross-Reference: Link classification records to asset inventory and risk register
  • Retention Compliance: Align retention with legal and regulatory requirements
  • Secure Destruction: Securely destroy records when retention periods expire

Continuous Improvement

Maturity Model for A.5.12

LevelNameCharacteristicsEvidence
1InitialNo formal classification; ad-hoc labeling; inconsistent protection; no scheme; no trainingNo documentation, inconsistent handling, no labels
2DevelopingBasic scheme exists (2–3 tiers); manual classification; some labeling; limited training; annual reviewBasic policy, some labels, manual handling, basic training
3DefinedComplete scheme (4 tiers); documented handling rules; role-based training; data owner validation; quarterly review; basic DLP integrationComplete policy, handling matrices, training records, validation, DLP rules
4ManagedAutomated classification; integration with DLP, IAM, encryption; metadata tagging; shadow data discovery; cloud classification; third-party classification requirements; metrics-drivenAutomation, integration, metadata, cloud tagging, third-party requirements, metrics
5OptimizingAI-driven classification; predictive risk analytics; self-healing misclassification; real-time compliance monitoring; industry-leading practices; classification drives strategic decisions; continuous optimizationAI classification, predictive analytics, self-healing, real-time compliance, strategic integration

Improvement Cycle

Plan:

  • Annual classification scheme review with cross-functional input
  • Benchmarking against industry standards and peer organizations
  • Regulatory change assessment and alignment
  • Technology evaluation for automation and enhancement
  • Maturity assessment and target setting
  • Incident analysis for classification lessons

Do:

  • Implement new classification levels or adjustments
  • Deploy enhanced automated classification tools
  • Expand classification coverage to new data types and systems
  • Enhance integration with security and compliance tools
  • Deliver refresher training and awareness campaigns
  • Update third-party classification requirements

Check:

  • Quarterly classification accuracy audits
  • Monthly DLP alignment reviews
  • Annual complete classification effectiveness review
  • Compliance audit preparation and results
  • Employee feedback and comprehension assessment
  • overhead optimization and ROI measurement
  • Incident response effectiveness by classification

Act:

  • Update classification policy based on findings and emerging risks
  • Refine handling rules based on user feedback and incidents
  • Invest in tools that improve automation and accuracy
  • Expand training for high-risk roles and new data types
  • Report improvements to leadership and board
  • Share best practices and lessons learned
  • Benchmark against industry standards

Toolkit Download

The following toolkit assets are available for this control:

AssetDescriptionFormat
01-information-classification-policy-template.mdComplete classification policy templateMarkdown
02-data-type-classification-matrix.xlsxMatrix of default classifications by data typeExcel
03-handling-rules-matrix.xlsxStorage, transmission, printing, and disposal rules by levelExcel
04-classification-labeling-guide.mdGuide for headers, footers, watermarks, and metadataMarkdown
05-classification-authority-framework.mdFramework for classification roles and governanceMarkdown
06-data-discovery-checklist.mdChecklist for discovering and classifying data assetsMarkdown
07-classification-training-presentation.pptxTraining deck with scenarios and knowledge testPowerPoint
08-classification-audit-checklist.mdInternal audit checklist for classification complianceMarkdown
09-misclassification-incident-response-playbook.mdPlaybook for responding to misclassification incidentsMarkdown
10-third-party-classification-addendum-template.mdContract addendum for third-party data classificationMarkdown
11-dlp-policy-templates-by-classification.mdDLP policy templates aligned with classification levelsMarkdown
12-classification-metrics-dashboard.xlsxDashboard for tracking classification KPIsExcel
13-reclassification-request-form.docxForm for requesting classification changesWord
14-annual-review-template.pptxAnnual classification review presentation templatePowerPoint
15-audit-evidence-checklist.mdEvidence checklist for A.5.12 audit preparationMarkdown
16-cloud-classification-tagging-guide.mdGuide for tagging cloud resources by classificationMarkdown
17-maturity-assessment-questionnaire.mdSelf-assessment for classification program maturityMarkdown
README.mdIndex and usage guide for all toolkit assetsMarkdown

Frequently Asked Questions

Q1: Is information classification mandatory for ISO 27001 certification?

A: Yes. A.5.12 explicitly requires information to be classified according to the organization's security needs. Without classification, an organization cannot demonstrate proportionate security controls or conduct meaningful risk assessment. It is very difficult to justify non-applicability for A.5.12.

Q2: How many classification tiers should we have?

A: Most organizations should use 3–4 tiers:

  • 3 tiers: Public, Internal, Confidential (simplest, suitable for small organizations)
  • 4 tiers: Public, Internal, Confidential, Restricted (most common, suitable for most organizations)
  • 5+ tiers: Only for large, complex organizations with specific regulatory needs (e.g., government contractors with classified data)

More tiers create confusion and inconsistency. Fewer tiers may not provide enough granularity for differentiated protection. The 4-tier model is the sweet spot for most organizations.

Q3: Who should be the data owner?

A: The data owner should be a business manager who understands the data's value and usage, not an IT person. Examples:

  • Customer data: Customer Success Head or Sales Director
  • Financial data: CFO or Finance Manager
  • Employee data: HR Director
  • Source code: CTO or Engineering Manager
  • Marketing data: CMO or Marketing Manager
  • Product data: Product Manager or VP of Product

The data owner is accountable for classification decisions and access approvals. IT acts as the custodian, implementing technical controls.

Q4: Can we use the same classification scheme as another organization?

A: You can use another organization's scheme as a starting point, but you must customize it for your business, data types, regulatory requirements, and risk appetite. Copying a scheme without customization leads to misalignment and ineffective protection. The scheme must reflect your organization's specific needs.

Q5: How do we handle information that contains multiple data types with different classifications?

A: The document or file should be classified at the highest level of any data it contains. For example, a report containing both Public marketing data and Confidential financial data should be classified as Confidential. For databases, consider field-level classification where possible. When mixing data types, apply the "highest common denominator" principle.

Q6: What if employees resist classification as "too bureaucratic"?

A: Address resistance through: (1) executive endorsement demonstrating that classification applies to everyone, (2) showing how classification protects employee data too (not just customer data), (3) making classification as easy as possible with automated tools and clear defaults, (4) demonstrating that classification reduces security friction for low-sensitivity data (fewer controls for Internal data), (5) recognizing and rewarding good classification behavior, (6) framing classification as empowerment (employees know what to protect and why). If resistance persists, treat it as a disciplinary matter for repeated non-compliance.

Q7: How do we classify data in third-party systems (SaaS, cloud, outsourced)?

A: Classification extends to third-party systems. Steps: (1) classify data before sharing with third parties, (2) include classification requirements in contracts and DPAs, (3) require third parties to implement equivalent protection for the classification level, (4) audit third-party classification compliance, (5) use CASB to monitor how third-party services handle classified data, (6) restrict what classification levels can be shared with which third parties (e.g., Restricted data may not go to consumer-grade SaaS).

Q8: How do we handle classification for emails and instant messages?

A: Emails should be classified based on their content and attachments. Rules: (1) email subject line should include classification for Confidential and Restricted, (2) auto-classification plugins can suggest classification based on content, (3) DLP can enforce rules (e.g., block external sending of Confidential without encryption), (4) instant messages containing Confidential or Restricted data should use approved secure channels, (5) email retention policies should align with classification, (6) auto-forwarding rules should be restricted for Confidential and Restricted mailboxes.

Q9: What is the difference between data classification and data categorization?

A: Classification is about sensitivity and protection requirements (Public, Internal, Confidential, Restricted). Categorization is about type and purpose (customer data, financial data, HR data, marketing data). Both are useful and complementary. Your Data Type Classification Matrix combines both, it categorizes by type and assigns a default classification. Classification drives protection; categorization drives organization and retrieval.

Q10: How do we maintain classification when data is copied, transformed, or aggregated?

A: Classification should follow the data. When data is copied, the copy retains the classification. When data is transformed (e.g., anonymized), classification may be downgraded if the transformation genuinely reduces sensitivity. When data is aggregated, classification may be upgraded if the aggregate reveals more sensitive insights. These changes should be documented and approved. Automated tools can help track classification lineage.

Q11: Can we downgrade classification when data becomes less sensitive?

A: Yes, but with proper process. Downgrading requires: (1) data owner approval, (2) CISO review for significant downgrades, (3) documentation of the reason and approval, (4) notification to affected users, (5) adjustment of technical controls to match new classification, (6) audit trail of the change. Downgrading should not be used to circumvent controls or reduce protection unnecessarily. Some data (e.g., health records, financial records) may have legal retention requirements that prevent downgrading regardless of business sensitivity.

Q12: How do we handle classification for unstructured data (file shares, SharePoint, etc.)?

A: Unstructured data is challenging because it lacks the structure of databases. Approaches: (1) classify folders and directories by default classification (e.g., "Finance" folder = Confidential), (2) use automated tools to scan file contents and suggest classification, (3) train users to classify documents at creation, (4) implement DLP to monitor and enforce classification rules, (5) periodic audits of file shares to identify misclassified data, (6) migrate unclassified data to classified folders with appropriate controls. The key is to make classification the path of least resistance.

Q13: Should we classify data in development and test environments?

A: Yes. Development and test environments often contain copies of production data. Classification rules: (1) production data in dev/test should retain its production classification, (2) use data masking or synthetic data for dev/test where possible, (3) dev/test environments should have equivalent controls to production for the classification level, (4) access to dev/test with production data should be restricted, (5) data in dev/test should be clearly labeled with its classification, (6) dev/test data should be securely disposed when environments are decommissioned. The 2023 OWASP Top 10 includes "A01:2021 – Broken Access Control" which often manifests in dev/test data exposure.

Q15: How do we handle classification during a merger or acquisition?

A: M&A creates classification challenges: (1) classify target company's data before acquisition close, (2) harmonize classification schemes if both companies have different schemes, (3) handle data with different classifications for the same data type (e.g., target's "Confidential" may be equivalent to acquirer's "Restricted"), (4) integrate data protection controls, (5) train acquired employees on the new classification scheme, (6) identify data that may need reclassification due to changed business context. Create a dedicated M&A classification integration project with clear timelines and responsibilities.


The following toolkit assets are available for this control:

#Toolkit FileDescription
101-classification-of-information-policy-template.mdPolicy Template
202-classification-of-information-procedure.mdProcedure
303-classification-of-information-checklist.mdChecklist
404-audit-evidence-checklist.mdAudit Evidence Checklist
505-implementation-roadmap.mdImplementation Roadmap
606-quick-reference-card.mdQuick Reference Card
707-training-materials.mdTraining Materials
808-incident-response-playbook.mdIncident Response Playbook
909-risk-assessment-template.mdRisk Assessment Template
1010-vendor-security-template.mdVendor Security Template
1111-metrics-and-kpi-dashboard.mdMetrics and KPI Dashboard
1212-gap-analysis-template.mdGap Analysis Template
1313-raci-matrix.mdRACI Matrix
1414-tool-comparison-matrix.mdTool Comparison Matrix
1515-communication-plan.mdCommunication Plan
1616-roles-and-responsibilities.mdRoles and Responsibilities
1717-regulatory-mapping.mdRegulatory Mapping

References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
  • ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
  • NIST Cybersecurity Framework 2.0 (2024)
  • NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations
  • NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories
  • CIS Controls v8, Controls 3 (Data Protection)
  • COBIT 2019, APO14 (Managed Data)
  • ITIL 4, Information Security Management Practice
  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000 (as amended through 2008)
  • CERT-In "Information Security Directions" (2022)
  • RBI Cybersecurity Framework for Banks (2016, updated)
  • SEBI Cybersecurity Guidelines for Market Infrastructure Institutions (2019)
  • IRDAI Cybersecurity Guidelines for Insurance Companies (2017)
  • NCIIPC Guidelines for Protection of Critical Information Infrastructure
  • Indian Penal Code, 1860 (relevant sections on data theft and breach of trust)

Industry and Research Sources

  • Gartner Research on Data Classification and Data Governance
  • Forrester Research on Data Security and Privacy
  • SANS Institute, Data Protection and Classification Resources
  • ISACA, Data Classification and Information Governance Guidance
  • Ponemon Institute, impact of Data Breach Studies (classification impact on breach overhead)
  • Verizon Data Breach Investigations Report (data sensitivity statistics)
  • IAPP (International Association of Privacy Professionals), Classification and Data Mapping Resources

Tool Documentation

  • Microsoft Purview Documentation, Sensitivity Labels and Data Classification
  • Titus Classification Suite Documentation
  • Boldon James Classification Documentation
  • BigID Data Intelligence Platform Documentation
  • Varonis Data Security Platform Documentation
  • Spirion Data Privacy Platform Documentation
  • OneTrust Privacy and Data Governance Documentation
  • Informatica Data Catalog Documentation
  • Collibra Data Governance Documentation

Open Source Resources

  • OpenDLP, Open-source data loss prevention and discovery
  • OpenMetadata, Open-source metadata management and data discovery
  • Apache Atlas, Open-source metadata management and governance
  • DataHub (LinkedIn), Open-source metadata platform
  • Amundsen (Lyft), Open-source data catalog
  • Elastic Stack, Log-based data discovery and monitoring
  • Custom Python/Regex scripts for basic pattern-based classification

Document Control

  • Version: 1.0
  • Author: Singahi, ISO 27001 Implementation Experts
  • Review Cycle: Quarterly + Annual
  • Next Review: September 2026 (quarterly) / June 2027 (annual)
  • Classification: TLP:CLEAR, Public Information

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.