ISO/IEC 27001:2022 Annex A · Control 5.12
Classification of Information: A Practical Implementation Guide
Apply protection according to information value, sensitivity, legal duties and business impact.
Information classification provides a consistent basis for deciding how information should be accessed, stored, shared, retained and disposed of.
What should the control achieve?
- A manageable classification scheme is defined.
- Information owners classify important information.
- Handling rules correspond to each level.
- Classification is reviewed as information changes.
Step-by-step implementation
Design the scheme
Use a small number of clear levels based on confidentiality, integrity, availability and obligations.
Define handling rules
Specify access, sharing, encryption, storage, transmission, retention and disposal for each level.
Assign ownership
Information owners determine classification using documented criteria.
Embed into workflows
Add classification to document templates, repositories, data catalogues and project intake.
Train with examples
Use realistic information from each department.
Review and reclassify
Change classification when sensitivity, legal duties or business value changes.
What this could look like in practice
A company uses Public, Internal, Confidential and Restricted. Payroll data is Restricted and requires limited role-based access, encryption and approved transfer channels. Marketing material becomes Public only after formal release.
| Activity | Practical implementation | Evidence |
|---|---|---|
| New data set | Owner assesses impact and records classification. | Data catalogue entry |
| Document creation | Template prompts author to select classification. | Document metadata |
| External sharing | Confidential content requires approved recipients and channel. | Sharing record |
Implementation evidence
- Classification policy
- Classification criteria
- Handling matrix
- Information register
- Labeled examples
- Repository configuration
- Training records
- Reclassification history
Useful metrics
- Critical information sets classified
- Misclassification incidents
- Repositories enforcing labels
- Overdue classification reviews
Common mistakes
- Creating too many levels.
- Classifying everything at the highest level.
- Focusing only on confidentiality.
- Providing labels without handling instructions.
- Never reducing classification after conditions change.
Questions an auditor may ask
- How were classification levels chosen?
- Who classifies information?
- What handling changes between levels?
- Show classification applied in a real workflow.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.