ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.12: Classification of information

Information is to be classified according to the organization's security needs, judged on confidentiality, integrity, availability and the requirements of relevant interested parties. Purpose: make the protection needs of information known and understood in proportion to its importance. Guidance: set a topic-specific classification policy and share it with all relevant interested parties. The scheme accounts for confidentiality, integrity and availability, business needs to share or restrict, legal requirements, and may extend to other assets according to the information they hold or process. Information owners are accountable for classifying their information. The scheme sets classification conventions and criteria for reviewing classifications over time, and classifications are updated as value, sensitivity and criticality change across the life cycle. It should align with the access control policy, meet specific business needs, may base levels on the impact of compromise, and should give each level a meaningful name. It must be applied consistently across the organization and built into procedures so everyone classifies the same way. Because other organizations' schemes differ even with similar level names, and information may be treated differently in each context, information-sharing agreements should include how to identify and interpret the other party's classifications, matching levels by equivalent handling and protection. Other information: classification gives handlers a quick signal of how to protect information and avoids assessing risk and designing controls item by item; sensitivity can lapse (published information still needs integrity and availability protection); over-classifying adds cost and under-classifying leaves information exposed; a four-level confidentiality example runs from no harm, through minor reputational or operational impact and significant short-term impact, to serious long-term impact or a threat to survival.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 51 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 6 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications

NIST SP 800-53 Rev 5 · 5 controls

  • SEC07-BP01 Understand your data classification scheme
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • SEC07-BP03 Automate identification and classification
  • SEC07-BP04 Define scalable data lifecycle management

CIS Controls v8 · 3 controls

  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity
  • CIS-3.7 Establish and Maintain a Data Classification Scheme
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • 0058 0058 Originator controls sanitisation, reclassification and declassification
  • 0059 0059 Assess value, importance and sensitivity by potential damage
  • 0060 0060 Classify at the lowest reasonable level
  • ISM-0323 Classifying media by data held
  • ISM-0325 Reclassifying media to a higher classification
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-GS-3 Define and implement data protection strategy

ISO 22301:2019 · 2 controls

  • 7.5 Documented information
  • 7.5.3 Control of documented information
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram

APPI · 1 control

  • APPI-A20 Proper Acquisition and Special Care Required Personal Information

APRA CPS 234 · 1 control

  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

C5 (Germany) · 1 control

  • C5-AM-06 Asset Classification and Labelling

CMMC 2.0 · 1 control

DORA · 1 control

FedRAMP High · 1 control

  • RA-2 Security Categorization

FedRAMP Moderate · 1 control

  • RA-2 Security Categorization

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.12 Classification of information

ISO 27017:2015 · 1 control

  • 8.2 Information classification

ISO 27701:2019 · 1 control

  • 6.5.2 Information classification

MTCS (Singapore) · 1 control

  • 12.2 Data classification

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • INV-DATA Keep an inventory of data assets by type

PCI DSS 4.0 · 1 control

  • 9.4.2 9.4.2 Classification of media by data sensitivity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.