Information classification is one of the most interesting parts of information security management, but also one of the most misunderstood. It is the process by which organizations assess the data they possess and the level of protection that should be provided to it.
Typically, organizations classify information based on its confidentiality, establishing who is allowed to view it. This process applies to both data and information. In a classification context, data and information are generally treated the same way.
A typical system contains four levels of confidentiality:
- confidential (access is restricted to management);
- restricted (most employees can access it);
- internal (all employees have access);
- public information (everyone has access)
Larger and more complex organizations may need more levels that take into account specific groups of employees who need access to certain information. ISO 27001, the leading standard for information security, describes best practices for creating and maintaining an information security management system, and the classification we have just seen plays a crucial role in managing information that must receive an appropriate level of protection.
The standard does not explain how to do it operationally, but you can follow four simple steps:
- collect all information in a single register, noting who is responsible for it and in what format it is found (electronic documents, databases, paper documents, storage media, etc.);
- classify the information according to the guidelines that management will have provided in the meantime and according to what the managers of each type of information consider right based on the possible risks related to its dissemination. Information that would be affected by more significant risks if disclosed should usually be subject to a higher level of confidentiality. But be careful, because it is not always the case;
- establish the correct management for each type of information. You will need different processes to manage digitally and physically stored information, but the processes should be consistent and clear;
- establish clear rules on how to protect each resource based on its classification and format. For example, you might stipulate that internal paper documents must be kept in a cabinet to which all employees have access. In contrast, confidential information should be placed in a locked cabinet, and highly confidential information kept in a secure location.
Additional rules should be established for data in transit, whether sent via email or carried by employees. You can keep track of all these rules using a simple table that contains all the information to be able to trace it. If you have implemented ISO 27001 "Information technology - Security techniques - Information security management systems" and want to be certified, we are the right partner for you. Contact us by phone 02.58320936 or by email: