In this guide you will learn how to implement ISO 27001 Annex A 5.12 Classification of Information and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.12 is an ISO 27001 control that requires that an organisation should classify information based on the needs of the organisation and relevant interest parities.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.12 Training Video
- ISO 27001 Annex A 5.12 Requirements and Guidance
- Information classification scheme
- The 3 levels of information classification
- Implementation guide
- Key Points
- Data Classification Policy
- ISO 27001 Data Classification Policy Template
- Information Classification Summary Template
- Define the classification scheme
- Base on business need
- Meet Legal and Regulatory Requirements
- Assign Information Owners
- Data Asset Register Template
- Review and update information classification
- Align to the topic specific policy requirement for access control
- Be consistent across the organisation
- Be consistent between organisations
- In addition
- How to implement ISO 27001 Annex A 5.12
- 1. Formalise the Information Classification Policy
- 2. Integrate Legal and Regulatory Requirements
- 3. Assign Information Asset Owners
- 4. Deploy a Centralised Data Asset Register
- 5. Implement Visual and Metadata Labelling
- 6. Align Access Control Mechanisms
- 7. Establish Secure Data Handling Processes
- 8. Synchronise Classification with Third Parties
- 9. Execute Employee Awareness Training
- 10. Audit and Review Classification Schemes
- ISO 27001 Templates
- What the auditor will check
- Top 3 mistakes people make and how to avoid them
- How to comply
- ISO 27001 Annex A 5.12 FAQ
- ISO 27001 controls and attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.12 is to ensure the identification and understanding of the protection needs of information in accordance with its importance to the organisation.
The ISO 27001 standard defines ISO 27001 Annex A 5.12 as:
Information should be classified according to the information security needs of the organisation based on confidentiality, integrity, availability and relevant interested party requirements.
ISO 27001:2022 Annex A 5.12 Classification of Information
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.12 Training Video
In this free training video you will learn How to implement ISO 27001 Classification Of Information (ISO 27001 Annex A 5.12) & Pass Your Audit.
ISO 27001 Annex A 5.12 Requirements and Guidance
Information classification scheme
You must decide on the information classification scheme that you will adopt.
The information classification scheme is the definition of the information classification levels and the rules that apply to those various levels.
It is used to guide your employees and people that work with you and explain to them is expected for handling and managing data.
Classification schemes can be as complicated or as simple as you want to make them. My advice would be to keep it simple.
Your starting point for deciding what classification scheme to adopt is to review the laws and regulations that relate to you and customer requirements that may contractually oblige you to have a certain scheme in place.
The 3 levels of information classification
| Classification Level | Description | Examples |
|---|---|---|
| Public | This is for documentation that poses little to no risk to you and that you don’t really need to protect. | Marketing, website, promotional materials. |
| Internal | This is for documentation that’s specific to the organisation. If it became public it could cause some minor embarrassment and poses a medium risk to you. | Your process documentation, certain management reports, broad based internal communications. |
| Confidential | This is the highest level of classification. If it became public it could cause major embarrassment, cost you money, put your operations at risk, expose your intellectual property, violate laws and regulations. | HR data relating to individuals, payroll data, health data, intellectual property, bespoke and proprietary technical and systems information such as code, schematics and information security protections. |
If you have the benefit of defining your own classification scheme then three levels of information classification for smaller organisation I have found works well.
Implementation guide
You have options when it comes to classifying your information. The preferred option is to keep it as simple as possible. For the majority of people we would recommend a simple, 3 tier approach to information classification. As with all aspects of information security you must take into consideration the needs of your customers. Some customers, such as government departments, may have a classification scheme that they expect you to adopt and implement. If this is the case then follow their lead. For everyone else, keep it simple.
Key Points
- You need to understand the information and data that you have and then decide the protection to put in place proportionate and appropriate to that the value of the data.
- The approach has to be consistent across the organisation and remove personal judgment.
- The protections are to maintain information security being the confidentiality, integrity and availability of data.
- It does form one of the foundation blocks of building your information security management system, so take time getting this right and making it appropriate to you.
Data Classification Policy
You need to write an information and classification handling policy. The policy should set out what your levels of classification are. It should address how you approach data protection in terms of the classification of data covered by data protection laws. The policy should lay out all of the expected controls per classification. The scope of the policy will cover the entire information life cycle.
ISO 27001 Data Classification Policy Template
The information classification and handling policy sets out your approach to information classification and how you handle data and assets for each classification.

Information Classification Summary Template
The information classification summary is a quick reference, one page guide to the classification levels and what must be done for each classification.

Define the classification scheme
You’re working with the business to understand the needs of the business, operationalise the business and help the business move forward. Whether you choose a predefined classification scheme, have one imposed on you or write your own, you need to define your classification scheme. Examples are provided above and in the policy template.
The classification scheme has to take into account the confidentiality, integrity and availability requirements.
Base on business need
The needs of the business are paramount and classifications and controls should take into account those needs. Consider the sharing or restricting of information. The availability requirements for information and the protection of information integrity.
Meet Legal and Regulatory Requirements
Working with your legal team and referencing back to the work done on the legal register you are going to ensure that your classification scheme fully meets the requirements of the law and relevant regulators.
When you assess the legal and regulatory requirements and create your legal register you are considering the laws that apply to you that impact information security. Ensuring those legal requirements are considered and baked into your information classification scheme and controls. Legal requirements will always take a priority over your own classification.
Assign Information Owners
The owners of the information are responsible for the classification of the information. Information owners play a key role in information security and if you haven’t already assigned them then you should assign them now.
Data Asset Register Template
The data asset register is where you record the information owners who are responsible for the information classification.

Review and update information classification
ISO 27001 is a standard based on continual improvement and as such the classification of data and the actual classification scheme should be reviewed and updated on a periodic basis.
Information changes over time in context, use, value. The classification of information should be regularly reviewed over time, at least annually and as significant changes occur.
Align to the topic specific policy requirement for access control
The standard explicitly calls out aligning to the topic specific policy requirement for access control. Access control is directly aligned to information classification.
Be consistent across the organisation
Everyone in the organisation should be consistent in following the information classification and applying it. Everyone classifies information in the same way. Everyone has a common understanding of the protection requirements and applies controls and protection in a common way.
Be consistent between organisations
Make sure that your classification scheme maps to that of third parties and customers. Your ability to map where relevant and applicable, to map your information classification scheme to that of other organisations.
As different organisations have different schemes and approaches you will need to put in place a mechanism to ensure consistency of the schemes used. This will be dependant on use and context but the idea is that you have in place an agreement on the interpretation of classification and classification levels.
In addition
- Put in place an information classification process that describes exactly what you do through the information management lifecycle
- Keep a data asset register up to date that shows who is allocated what asset and what level of classification the data is – which we covered in ISO 27001 Annex A 5.9 Inventory Of Information And Other Associated Assets Beginner’s Guide
- Follow best practice and your information classification policy for marking data with its classification. This can be visually on the data but also it can be in the meta data. You need to be able to identify the classification level of the information.
- Put in place controls appropriate to the level of information classification and based on the risk to the business.
- Communicate your information classification approach to employees. A great way to do this is with this simple one page information classification summary.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

How to implement ISO 27001 Annex A 5.12
Implementing ISO 27001 Annex A 5.12 requires a transition from ad hoc data handling to a formalised, risk-based governance structure. By categorising information based on its value and legal sensitivity, organisations ensure that security controls are applied proportionally. This action-orientated guide provides the technical and procedural steps necessary to establish a compliant classification framework that satisfies lead auditor requirements.
1. Formalise the Information Classification Policy
- Define a clear classification scheme tailored to your business needs, such as a three-tier model: Public, Internal, and Confidential.
- Document the specific criteria for each level to remove ambiguity during data categorisation.
- Ensure the policy details the exact security controls expected for each tier throughout the entire information lifecycle.
2. Integrate Legal and Regulatory Requirements
- Map data protection laws, such as GDPR, directly to your classification tiers.
- Identify personal and special category data to ensure it is never classified as Public.
- Prioritise legal obligations over internal business preferences when applying security restrictions.
3. Assign Information Asset Owners
- Provision clear ownership for all critical data sets within your organisation.
- Delegate the responsibility of determining the correct classification level to these assigned owners.
- Mandate that owners oversee the secure handling of their assigned assets throughout the data lifecycle.
4. Deploy a Centralised Data Asset Register
- Deploy a comprehensive Data Asset Register to centralise your inventory of information assets.
- Record the assigned owner, classification level, and specific location for every documented asset.
- Update the register dynamically to reflect new assets or changes in data sensitivity.
5. Implement Visual and Metadata Labelling
- Implement visual markers, such as watermarks or headers, on physical and digital documents to clearly indicate their classification.
- Configure metadata labels within your digital files to support automated security tools.
- Integrate these labels with Data Loss Prevention (DLP) software to block unauthorised data exfiltration.
6. Align Access Control Mechanisms
- Configure Identity and Access Management (IAM) roles based on the principle of least privilege.
- Enforce Multi-Factor Authentication (MFA) for any system hosting Internal or Confidential information.
- Align your access control policy directly with your classification scheme to prevent unauthorised data exposure.
7. Establish Secure Data Handling Processes
- Formalise Rules of Engagement (ROE) documents for the creation, storage, transmission, and destruction of classified data.
- Enforce encryption protocols for data at rest and data in transit, specifically for highly sensitive information.
- Standardise secure disposal methods, such as cryptographic wiping or physical destruction, for end-of-life assets.
8. Synchronise Classification with Third Parties
- Audit the classification schemes of your suppliers, vendors, and clients to understand their data protection standards.
- Synchronise your internal classification levels with third-party frameworks to maintain consistent security across external boundaries.
- Draft formal agreements on the handling and interpretation of shared confidential data.
9. Execute Employee Awareness Training
- Execute mandatory security awareness training to educate staff on the new classification framework.
- Distribute a one-page information classification summary to all employees for quick, daily reference.
- Test employee comprehension regarding how to securely process and transmit classified documentation.
10. Audit and Review Classification Schemes
- Schedule periodic audits, at least annually, to review the effectiveness of your information classification scheme.
- Revoke outdated classifications and update the Data Asset Register to reflect changes in business context or risk.
- Remediate any non-conformities discovered during internal audits to ensure readiness for the formal ISO 27001 certification audit.
ISO 27001 Templates

What the auditor will check
The audit is going to check a number of areas. Lets go through them
1. That information classification has been defined
The audit will check you have a clearly defined your information classification scheme. It will want to see the levels of classification that you have adopted and what that means. The audit will review the types of information covered by each classification level. It will then check that the controls that are in place to protect information of each level are appropriate to that level. They will check that information is clearly marked with its level of classification.
2. There is an up to date asset register
The asset register will be checked to see that it meets the requirements of the standard and as a minimum that assets are allocated to owners. They will want to see that the owners have defined the level of classification and the level of classification is documented and communicated.
3. That data protection has been considered
Irrespective of where you are in the world, data protection laws and regulations will apply to you. To a greater or lesser degree. When defining your information classification levels be sure to include those data protection requirements. The main example of this is the classification of special category data as confidential. Any personal data will be expected to be protected and not be classified as public. Seek specialist help where required.
Top 3 mistakes people make and how to avoid them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.12 are
1. Your information assets are not marked with classification
You have an information classification scheme but you have not marked up your information assets in a way that clearly and readily indicates its level of classification. If a document is a confidential document, have the word confidential on it. Consider the use of meta data.
2. Making the classification too complicated
It can be easy to get carried away and think you need many levels of classification. This is rarely the case. Keep it simple. The more simple, the easier to manage. Remember we are using classification to help us allocate our limited to resources to the protection of the things we care most about. Having crazy classification levels such as public, internal public, internal confidential, confidential secret, top secret rarely add any value. The admin to implement is just too much.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
How to comply
To comply with ISO 27001 Annex A 5.12 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Decide on your information classification scheme
- Have a data asset register
- Assign owners to the data assets
- Have the data owners decide on the classification level of the information
- Put in place controls to protect the information that are based on the classification
ISO 27001 Annex A 5.12 FAQ
Most organisations implement a four-tier scheme to ensure clarity and usability for staff across the business.
Public: Information that can be disclosed without harm (e.g., marketing materials).
Internal: Standard business data not intended for public release (e.g., internal memos).
Confidential: Sensitive data that could cause damage if leaked (e.g., PII or customer contracts).
Secret: Highly sensitive data that would cause critical harm (e.g., intellectual property or M&A plans).
Yes, a formalised policy is required to satisfy the requirements of Annex A 5.12 and to provide a consistent standard for the ISMS.
It must define the specific classification tiers used by the organisation.
It should assign responsibility for classifying assets to the Information Owner.
It must outline the specific handling and protection rules for each tier.
It acts as a primary piece of evidence during an external certification audit.
The Information Owner (or Asset Owner) is the individual responsible for determining the correct classification level for the assets they manage.
They assess the potential impact of unauthorised disclosure or loss.
They ensure that the classification remains accurate throughout the asset’s lifecycle.
They are responsible for reviewing classification levels periodically.
They determine who is authorised to access the classified information.
The primary difference is that Annex A 5.12 defines the sensitivity level (Classification), whereas Annex A 5.13 defines the visible markers used to communicate that level (Labelling).
5.12: The decision on the data’s value and risk.
5.13: The tactical application of tags, watermarks, or metadata.
Classification (5.12) must always occur before labelling (5.13).
Information classification acts as a foundational mapping exercise that helps organisations identify where Personal Identifiable Information (PII) resides.
Identifies data that requires specific protection under the “Confidential” tier.
Simplifies Subject Access Requests (SARs) by categorising personal data locations.
Ensures appropriate encryption and storage for sensitive personal data.
Assists in performing Data Protection Impact Assessments (DPIAs).
Classification levels should be reviewed at least annually or whenever a significant change occurs in the asset’s value or the organisation’s risk landscape.
Ensures that data is not over-protected, which can hinder productivity.
Identifies “classification creep” where data sensitivity has decreased over time.
Confirms that Asset Owners are still relevant and current.
Aligns with the internal audit cycle required by Clause 9.2.
ISO 27001 controls and attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Information Protection | Protection |
| Integrity | Defence | |||
| Availability |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.
