ISO 27001:2022 Annex A 5.12 Classification of Information Explained

ISO 27001 Annex A 5.12 Classification of information

In this guide you will learn how to implement ISO 27001 Annex A 5.12 Classification of Information and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.12 is an ISO 27001 control that requires that an organisation should classify information based on the needs of the organisation and relevant interest parities.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.12 is to ensure the identification and understanding of the protection needs of information in accordance with its importance to the organisation.

The ISO 27001 standard defines ISO 27001 Annex A 5.12 as:

Information should be classified according to the information security needs of the organisation based on confidentiality, integrity, availability and relevant interested party requirements.

ISO 27001:2022 Annex A 5.12 Classification of Information

FREE ISO 27001 Annex A 5.12 Training Video

In this free training video you will learn How to implement ISO 27001 Classification Of Information (ISO 27001 Annex A 5.12) & Pass Your Audit.

ISO 27001 Annex A 5.12 Requirements and Guidance

Information classification scheme

You must decide on the information classification scheme that you will adopt.

The information classification scheme is the definition of the information classification levels and the rules that apply to those various levels.

It is used to guide your employees and people that work with you and explain to them is expected for handling and managing data.

Classification schemes can be as complicated or as simple as you want to make them. My advice would be to keep it simple.

Your starting point for deciding what classification scheme to adopt is to review the laws and regulations that relate to you and customer requirements that may contractually oblige you to have a certain scheme in place.

The 3 levels of information classification

Classification LevelDescriptionExamples
PublicThis is for documentation that poses little to no risk to you and that you don’t really need to protect.Marketing, website, promotional materials.
InternalThis is for documentation that’s specific to the organisation. If it became public it could cause some minor embarrassment and poses a medium risk to you.Your process documentation, certain management reports, broad based internal communications.
ConfidentialThis is the highest level of classification. If it became public it could cause major embarrassment, cost you money, put your operations at risk, expose your intellectual property, violate laws and regulations.HR data relating to individuals, payroll data, health data, intellectual property, bespoke and proprietary technical and systems information such as code, schematics and information security protections.

If you have the benefit of defining your own classification scheme then three levels of information classification for smaller organisation I have found works well.

Implementation guide

You have options when it comes to classifying your information. The preferred option is to keep it as simple as possible. For the majority of people we would recommend a simple, 3 tier approach to information classification. As with all aspects of information security you must take into consideration the needs of your customers. Some customers, such as government departments, may have a classification scheme that they expect you to adopt and implement. If this is the case then follow their lead. For everyone else, keep it simple.

Key Points

  • You need to understand the information and data that you have and then decide the protection to put in place proportionate and appropriate to that the value of the data.
  • The approach has to be consistent across the organisation and remove personal judgment.
  • The protections are to maintain information security being the confidentiality, integrity and availability of data.
  • It does form one of the foundation blocks of building your information security management system, so take time getting this right and making it appropriate to you.

Data Classification Policy

You need to write an information and classification handling policy. The policy should set out what your levels of classification are. It should address how you approach data protection in terms of the classification of data covered by data protection laws. The policy should lay out all of the expected controls per classification. The scope of the policy will cover the entire information life cycle.

ISO 27001 Data Classification Policy Template

The information classification and handling policy sets out your approach to information classification and how you handle data and assets for each classification.

ISO 27001 Information Classification and Handling Policy Template - ISO 27001 Annex A 5.12 Classification of Information Template
ISO 27001 Information Classification and Handling Policy Template

Information Classification Summary Template

The information classification summary is a quick reference, one page guide to the classification levels and what must be done for each classification.

ISO 27001 Information Classification Summary Template - ISO 27001 Annex A 5.12 Classification of Information Template
ISO 27001 Information Classification Summary Template

Define the classification scheme

You’re working with the business to understand the needs of the business, operationalise the business and help the business move forward. Whether you choose a predefined classification scheme, have one imposed on you or write your own, you need to define your classification scheme. Examples are provided above and in the policy template.

The classification scheme has to take into account the confidentiality, integrity and availability requirements.

Base on business need

The needs of the business are paramount and classifications and controls should take into account those needs. Consider the sharing or restricting of information. The availability requirements for information and the protection of information integrity.

Working with your legal team and referencing back to the work done on the legal register you are going to ensure that your classification scheme fully meets the requirements of the law and relevant regulators.

When you assess the legal and regulatory requirements and create your legal register you are considering the laws that apply to you that impact information security. Ensuring those legal requirements are considered and baked into your information classification scheme and controls. Legal requirements will always take a priority over your own classification.

Assign Information Owners

The owners of the information are responsible for the classification of the information. Information owners play a key role in information security and if you haven’t already assigned them then you should assign them now.

Data Asset Register Template

The data asset register is where you record the information owners who are responsible for the information classification.

ISO 27001 Data Asset Register Template  - ISO 27001 Annex A 5.12 Classification of Information Template
ISO 27001 Data Asset Register Template

Review and update information classification

ISO 27001 is a standard based on continual improvement and as such the classification of data and the actual classification scheme should be reviewed and updated on a periodic basis.

Information changes over time in context, use, value. The classification of information should be regularly reviewed over time, at least annually and as significant changes occur.

Align to the topic specific policy requirement for access control

The standard explicitly calls out aligning to the topic specific policy requirement for access control. Access control is directly aligned to information classification.

Be consistent across the organisation

Everyone in the organisation should be consistent in following the information classification and applying it. Everyone classifies information in the same way. Everyone has a common understanding of the protection requirements and applies controls and protection in a common way.

Be consistent between organisations

Make sure that your classification scheme maps to that of third parties and customers. Your ability to map where relevant and applicable, to map your information classification scheme to that of other organisations.

As different organisations have different schemes and approaches you will need to put in place a mechanism to ensure consistency of the schemes used. This will be dependant on use and context but the idea is that you have in place an agreement on the interpretation of classification and classification levels.

In addition

  • Put in place an information classification process that describes exactly what you do through the information management lifecycle
  • Keep a data asset register up to date that shows who is allocated what asset and what level of classification the data is – which we covered in ISO 27001 Annex A 5.9 Inventory Of Information And Other Associated Assets Beginner’s Guide
  • Follow best practice and your information classification policy for marking data with its classification. This can be visually on the data but also it can be in the meta data. You need to be able to identify the classification level of the information.
  • Put in place controls appropriate to the level of information classification and based on the risk to the business.
  • Communicate your information classification approach to employees. A great way to do this is with this simple one page information classification summary.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

How to implement ISO 27001 Annex A 5.12

Implementing ISO 27001 Annex A 5.12 requires a transition from ad hoc data handling to a formalised, risk-based governance structure. By categorising information based on its value and legal sensitivity, organisations ensure that security controls are applied proportionally. This action-orientated guide provides the technical and procedural steps necessary to establish a compliant classification framework that satisfies lead auditor requirements.

1. Formalise the Information Classification Policy

  • Define a clear classification scheme tailored to your business needs, such as a three-tier model: Public, Internal, and Confidential.
  • Document the specific criteria for each level to remove ambiguity during data categorisation.
  • Ensure the policy details the exact security controls expected for each tier throughout the entire information lifecycle.

2. Integrate Legal and Regulatory Requirements

  • Map data protection laws, such as GDPR, directly to your classification tiers.
  • Identify personal and special category data to ensure it is never classified as Public.
  • Prioritise legal obligations over internal business preferences when applying security restrictions.

3. Assign Information Asset Owners

  • Provision clear ownership for all critical data sets within your organisation.
  • Delegate the responsibility of determining the correct classification level to these assigned owners.
  • Mandate that owners oversee the secure handling of their assigned assets throughout the data lifecycle.

4. Deploy a Centralised Data Asset Register

  • Deploy a comprehensive Data Asset Register to centralise your inventory of information assets.
  • Record the assigned owner, classification level, and specific location for every documented asset.
  • Update the register dynamically to reflect new assets or changes in data sensitivity.

5. Implement Visual and Metadata Labelling

  • Implement visual markers, such as watermarks or headers, on physical and digital documents to clearly indicate their classification.
  • Configure metadata labels within your digital files to support automated security tools.
  • Integrate these labels with Data Loss Prevention (DLP) software to block unauthorised data exfiltration.

6. Align Access Control Mechanisms

  • Configure Identity and Access Management (IAM) roles based on the principle of least privilege.
  • Enforce Multi-Factor Authentication (MFA) for any system hosting Internal or Confidential information.
  • Align your access control policy directly with your classification scheme to prevent unauthorised data exposure.

7. Establish Secure Data Handling Processes

  • Formalise Rules of Engagement (ROE) documents for the creation, storage, transmission, and destruction of classified data.
  • Enforce encryption protocols for data at rest and data in transit, specifically for highly sensitive information.
  • Standardise secure disposal methods, such as cryptographic wiping or physical destruction, for end-of-life assets.

8. Synchronise Classification with Third Parties

  • Audit the classification schemes of your suppliers, vendors, and clients to understand their data protection standards.
  • Synchronise your internal classification levels with third-party frameworks to maintain consistent security across external boundaries.
  • Draft formal agreements on the handling and interpretation of shared confidential data.

9. Execute Employee Awareness Training

  • Execute mandatory security awareness training to educate staff on the new classification framework.
  • Distribute a one-page information classification summary to all employees for quick, daily reference.
  • Test employee comprehension regarding how to securely process and transmit classified documentation.

10. Audit and Review Classification Schemes

  • Schedule periodic audits, at least annually, to review the effectiveness of your information classification scheme.
  • Revoke outdated classifications and update the Data Asset Register to reflect changes in business context or risk.
  • Remediate any non-conformities discovered during internal audits to ensure readiness for the formal ISO 27001 certification audit.

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.12 Classification of Information Templates
ISO 27001 Templates

How to audit ISO 27001 Annex A 5.12

As an ISO 27001 Lead Auditor, I expect to see hard evidence that your classification scheme is not just documented, but actively enforced across your entire organisation. Auditing Annex A 5.12 requires you to identify the gap between written policy and daily practice. This 10-step guide outlines exactly how to evaluate your information classification controls, inspect your asset registers, and verify your technical security configurations to guarantee a successful compliance audit.

1. Formalise the Audit Scope and Objectives

  • Establish the exact boundaries of the classification audit to ensure all relevant departments and systems are reviewed.
  • Identify the core physical and digital repositories that store critical business and customer data.
  • Communicate the audit timetable and expected deliverables to department heads and assigned information owners.

2. Evaluate the Information Classification Policy

  • Review the documented classification scheme to confirm it utilises a logical, tiered approach such as Public, Internal, and Confidential.
  • Ensure the policy clearly defines the handling rules and mandated security controls for each specific tier.
  • Verify that the policy has been formally approved by management and updated within the last 12 months.

3. Inspect the Centralised Data Asset Register

  • Examine the Data Asset Register to verify that all critical information assets are accurately logged and categorised.
  • Check that every listed asset has an explicitly assigned classification level that matches the approved policy scheme.
  • Cross-reference a random sample of physical and digital assets against the register to confirm inventory accuracy.

4. Verify Information Asset Ownership

  • Audit the assignment of information owners within the Data Asset Register to ensure no data is left orphaned.
  • Interview selected asset owners to confirm they understand their responsibility for determining classification levels.
  • Check that owners actively review and authorise access requests based on the designated classification of their assets.

5. Audit Legal and Data Protection Alignment

  • Review the classification of assets containing Personally Identifiable Information (PII) to ensure compliance with GDPR and relevant privacy laws.
  • Verify that special category data is strictly categorised as Confidential or higher, never as Public.
  • Confirm that regulatory requirements dictate the minimum classification level applied to legally protected information.

6. Assess Visual and Metadata Labelling Practices

  • Sample physical documents and internal reports to check for clear visual markers, such as headers or footers indicating classification.
  • Inspect digital files to ensure metadata tagging aligns with the assigned classification level.
  • Test automated systems, such as Data Loss Prevention (DLP) tools, to verify they correctly read and restrict files based on metadata labels.

7. Test Identity and Access Management Configurations

  • Audit IAM roles to ensure user access is restricted based on the principle of least privilege and aligns with data classification.
  • Verify that Multi-Factor Authentication (MFA) is strictly enforced for any system granting access to Confidential or highly sensitive data.
  • Review system access logs to detect any unauthorised attempts to access restricted information tiers.

8. Review Secure Data Handling Procedures

  • Evaluate the formal Rules of Engagement (ROE) governing how classified data is transmitted both internally and externally.
  • Verify that strong encryption protocols are actively applied to Confidential data at rest and in transit.
  • Audit the asset disposal logs to confirm sensitive information is destroyed using approved methods, such as cryptographic wiping.

9. Examine Employee Competence and Awareness

  • Conduct brief interviews with a sample of employees to test their practical knowledge of the classification scheme.
  • Ask staff to demonstrate how they would securely package and transmit a Confidential document to an external client.
  • Review training records to ensure all personnel have completed recent awareness sessions on information classification.

10. Document Non-Conformities and Remediate

  • Compile all audit findings into a formal report, explicitly detailing any misaligned classifications or missing labels.
  • Categorise findings by severity to prioritise the remediation of critical vulnerabilities or compliance gaps.
  • Assign corrective actions to the relevant asset owners and schedule a follow-up review to verify successful resolution.

What the auditor will check

The audit is going to check a number of areas. Lets go through them

1. That information classification has been defined

The audit will check you have a clearly defined your information classification scheme. It will want to see the levels of classification that you have adopted and what that means. The audit will review the types of information covered by each classification level. It will then check that the controls that are in place to protect information of each level are appropriate to that level. They will check that information is clearly marked with its level of classification.

2. There is an up to date asset register

The asset register will be checked to see that it meets the requirements of the standard and as a minimum that assets are allocated to owners. They will want to see that the owners have defined the level of classification and the level of classification is documented and communicated.

3. That data protection has been considered

Irrespective of where you are in the world, data protection laws and regulations will apply to you. To a greater or lesser degree. When defining your information classification levels be sure to include those data protection requirements. The main example of this is the classification of special category data as confidential. Any personal data will be expected to be protected and not be classified as public. Seek specialist help where required.

Top 3 mistakes people make and how to avoid them

The top 3 Mistakes People Make For ISO 27001 Annex A 5.12 are

1. Your information assets are not marked with classification

You have an information classification scheme but you have not marked up your information assets in a way that clearly and readily indicates its level of classification. If a document is a confidential document, have the word confidential on it. Consider the use of meta data.

2. Making the classification too complicated

It can be easy to get carried away and think you need many levels of classification. This is rarely the case. Keep it simple. The more simple, the easier to manage. Remember we are using classification to help us allocate our limited to resources to the protection of the things we care most about. Having crazy classification levels such as public, internal public, internal confidential, confidential secret, top secret rarely add any value. The admin to implement is just too much.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

How to comply

To comply with ISO 27001 Annex A 5.12 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to

  • Decide on your information classification scheme
  • Have a data asset register
  • Assign owners to the data assets
  • Have the data owners decide on the classification level of the information
  • Put in place controls to protect the information that are based on the classification

ISO 27001 Annex A 5.12 FAQ

What are the common levels of information classification?

Most organisations implement a four-tier scheme to ensure clarity and usability for staff across the business.
Public: Information that can be disclosed without harm (e.g., marketing materials).
Internal: Standard business data not intended for public release (e.g., internal memos).
Confidential: Sensitive data that could cause damage if leaked (e.g., PII or customer contracts).
Secret: Highly sensitive data that would cause critical harm (e.g., intellectual property or M&A plans).

Is a documented Information Classification Policy mandatory?

Yes, a formalised policy is required to satisfy the requirements of Annex A 5.12 and to provide a consistent standard for the ISMS.
It must define the specific classification tiers used by the organisation.
It should assign responsibility for classifying assets to the Information Owner.
It must outline the specific handling and protection rules for each tier.
It acts as a primary piece of evidence during an external certification audit.

Who is responsible for classifying information?

The Information Owner (or Asset Owner) is the individual responsible for determining the correct classification level for the assets they manage.
They assess the potential impact of unauthorised disclosure or loss.
They ensure that the classification remains accurate throughout the asset’s lifecycle.
They are responsible for reviewing classification levels periodically.
They determine who is authorised to access the classified information.

What is the difference between Annex A 5.12 and 5.13?

The primary difference is that Annex A 5.12 defines the sensitivity level (Classification), whereas Annex A 5.13 defines the visible markers used to communicate that level (Labelling).
5.12: The decision on the data’s value and risk.
5.13: The tactical application of tags, watermarks, or metadata.
Classification (5.12) must always occur before labelling (5.13).

How does information classification assist with GDPR compliance?

Information classification acts as a foundational mapping exercise that helps organisations identify where Personal Identifiable Information (PII) resides.
Identifies data that requires specific protection under the “Confidential” tier.
Simplifies Subject Access Requests (SARs) by categorising personal data locations.
Ensures appropriate encryption and storage for sensitive personal data.
Assists in performing Data Protection Impact Assessments (DPIAs).

How often should classification levels be reviewed?

Classification levels should be reviewed at least annually or whenever a significant change occurs in the asset’s value or the organisation’s risk landscape.
Ensures that data is not over-protected, which can hinder productivity.
Identifies “classification creep” where data sensitivity has decreased over time.
Confirms that Asset Owners are still relevant and current.
Aligns with the internal audit cycle required by Clause 9.2.

ISO 27001 controls and attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveConfidentialityIdentifyInformation ProtectionProtection
IntegrityDefence
Availability

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top