ISO 27001A.5 — Classification of information
A.5.12
Classification of information
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Classify information according to security and business needs so handling rules can be applied consistently.
Points of focus
- Classification scheme defined
- Owners understand how to classify
- Handling rules per class
- Periodic reclassification of critical assets
Implementation notes
Publish a 3–4 level scheme with examples for source code, customer content, credentials, and marketing. Wire class into tickets, DLP rules, and encryption expectations (A.8.24). Revisit classifications when launching new products. Align GDPR data-minimisation and records of processing with Restricted/Confidential buckets without claiming legal advice.
Audit tip: Pick one customer-data store and show its class plus the handling rules that apply.
Evidence auditors typically request:
- Data classification standard
- Examples mapped to product data types
- Ticket fields or labels enforcing class
- Training snippet on classification
Common gaps
- Everything marked Confidential — scheme useless
- Customer data unmarked in shared drives
- No link from class to technical controls
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.12 | This control |
| SOC 2 | CC6.1 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.12)
Frequently Asked Questions
No. Focus on systems of record and data stores; train people on high-risk sharing mistakes.
A.5.12 defines classes; A.5.13 covers labelling/marking so handlers see the class.
Often supports CC6 asset protection narratives — keep one classification standard for both programs.