Information is to be classified according to the organization's security needs, judged on confidentiality, integrity, availability and the requirements of relevant interested parties. Purpose: make the protection needs of information known and understood in proportion to its importance. Guidance: set a topic-specific classification policy and share it with all relevant interested parties. The scheme accounts for confidentiality, integrity and availability, business needs to share or restrict, legal requirements, and may extend to other assets according to the information they hold or process. Information owners are accountable for classifying their information. The scheme sets classification conventions and criteria for reviewing classifications over time, and classifications are updated as value, sensitivity and criticality change across the life cycle. It should align with the access control policy, meet specific business needs, may base levels on the impact of compromise, and should give each level a meaningful name. It must be applied consistently across the organization and built into procedures so everyone classifies the same way. Because other organizations' schemes differ even with similar level names, and information may be treated differently in each context, information-sharing agreements should include how to identify and interpret the other party's classifications, matching levels by equivalent handling and protection. Other information: classification gives handlers a quick signal of how to protect information and avoids assessing risk and designing controls item by item; sensitivity can lapse (published information still needs integrity and availability protection); over-classifying adds cost and under-classifying leaves information exposed; a four-level confidentiality example runs from no harm, through minor reputational or operational impact and significant short-term impact, to serious long-term impact or a threat to survival.
This control maps to 51 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 5.12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.