Skip to content
compliancebase
ISO 27001A.5 — Classification of information

A.5.12

Classification of information

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Classify information according to security and business needs so handling rules can be applied consistently.

Points of focus

  • Classification scheme defined
  • Owners understand how to classify
  • Handling rules per class
  • Periodic reclassification of critical assets

Implementation notes

Publish a 3–4 level scheme with examples for source code, customer content, credentials, and marketing. Wire class into tickets, DLP rules, and encryption expectations (A.8.24). Revisit classifications when launching new products. Align GDPR data-minimisation and records of processing with Restricted/Confidential buckets without claiming legal advice.

Audit tip: Pick one customer-data store and show its class plus the handling rules that apply.

Evidence auditors typically request:

  • Data classification standard
  • Examples mapped to product data types
  • Ticket fields or labels enforcing class
  • Training snippet on classification

Common gaps

  • Everything marked Confidential — scheme useless
  • Customer data unmarked in shared drives
  • No link from class to technical controls

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.12This control
SOC 2CC6.1Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

No. Focus on systems of record and data stores; train people on high-risk sharing mistakes.

A.5.12 defines classes; A.5.13 covers labelling/marking so handlers see the class.

Often supports CC6 asset protection narratives — keep one classification standard for both programs.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above