ISO27001:2022 – A5.12 Classification of information

Annex 5.12 Classification of Information

We’ve previously said that you can’t protect what you don’t understand — and to add to that, you also can’t protect everything equally. So how do you know what’s most important to secure? That’s where classification comes in.

ISO 27001 – A5.12 requires you to identify and categorise information based on its sensitivity and value to the organisation.

What does ISO 27001 – A5.12 require?

The standard states that:

“Information shall be classified according to the information security needs of the organisation based on confidentiality, integrity, availability and relevant interested party requirements.” (A5.12 Classification of Information)

Why is this required?

Not all data is equal. For example, HR data might include sensitive information like payroll records, ID documents, and health details, while marketing brochures are typically public. Each requires a different level of control.

Without classification, you’re forced to apply the same level of security to all data — which is inefficient and risky. Too strict, and you stifle productivity; too loose, and you risk breaches. Either way, you jeopardise compliance and fail your audit.

What the auditor is looking for

The auditor will expect to see a documented classification scheme that defines levels of information sensitivity and maps them to appropriate protection measures. A practical, commonly used model includes:

  • Highly Confidential
  • Confidential
  • Internal Protected
  • Public

Each classification level should include examples of applicable information and outline how it should be handled. For instance, “Highly Confidential” data might require encryption and board-level approval for external sharing. Examples could include personal data, sales reports, or intellectual property.

To develop your scheme, assess the value of each data type using the CIA triad:

Confidentiality

How important is it to prevent unauthorised access?

Integrity

How critical is it to prevent unauthorised modification or corruption?

Availability

How vital is timely access to this information? How hard would it be to replace it?

Use a simple scoring system (High, Medium, Low) to evaluate each aspect, then assign an overall classification accordingly.

Document this in a spreadsheet with fields for:

  • Classification level
  • Examples of data
  • How data is handled and stored
  • How data is destroyed or disposed of

Where possible, link this to your Records of Processing Activities (RoPA) — especially for personal data — and reference it in your asset inventory (A5.9). While RoPA focuses on personal data, don’t forget to include company information as well.

Q & A

How many levels should we have in the classification scheme?

There’s no fixed rule, but simplicity is key. The four-level scheme above works well, or you can customise it to suit your organisation.

Is it possible to get this wrong?

Yes — usually by making it too complex. If people can’t understand or use it, they’ll ignore it. Keep it practical and user-friendly.

Difficulty rating

We rate this a 1 out of 5. No technical skills are required — just an organised approach and collaboration across teams. You’ll need to document the classification scheme clearly.

More questions?

As always, ISO27001 controls are interlinked. Review our FAQ for related guidance. If you’re unsure how to build or implement your classification scheme, get in touch and we’ll be happy to support you.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… The Real Easy Guide to ISO27001”, available on Amazon.

ISO 27001 – A5.12