Policy Register

Information classification and handling policy

The classification scheme, the criteria for each level, the label each carries and the handling rules for each level in each medium.

How the register reads it

Also calleddata classification, handling rules, protective marking
FamilyAssets, data and classification
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 is ticked and no line resolves to it (ISO 27701 requires it too, inside a parent document, so it does not list it separately).
TemplateData classification policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.12 Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.

Evidence an auditor accepts: The classification scheme, defining the levels and the criteria for each against confidentiality, integrity and availability; evidence the criteria account for the requirements of relevant interested parties, such as customers, regulators and contracts; classification applied to actual information assets in the inventory, not only defined in policy
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.13 Labelling of information

Label information consistently with the classification scheme so handling rules can follow it.

What the ISO 27002 guidance expects the document to say: Requires a matching set of information labelling procedures to be developed and implemented, so that information carries markings consistent with the classification scheme the organisation has adopted.

Evidence an auditor accepts: The labelling procedures showing how labels are applied for each medium, covering documents, email, physical media, screens and system records; samples of labelled information from live systems, in each classification level in use; evidence labelling extends to information shared with third parties
Common gap: Labels applied inconsistently across departments
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 A.3.5 Classification of information

The organization's information classification scheme shall explicitly consider PII, including its type and any special categories, so that classification is the means by which the organization understands what PII it processes, where that PII is stored and the systems through which it can flow.

Evidence an auditor accepts: Classification scheme with PII and special categories as explicit classes; data inventory or map derived from the classification showing where PII resides and flows; evidence systems processing PII are classified accordingly
Common gap: PII treated as ordinary confidential information with no distinction for special categories
Source: ISO/IEC 27701:2025
ISO 27701 A.3.6 Labelling of information

The organization shall ensure that people under its control are made aware of the definition of PII and of how to recognise information that is PII, so that labelling and handling rules are applied to PII wherever it occurs.

Evidence an auditor accepts: Definition of PII communicated to personnel with examples; labelling conventions for PII in systems and documents; evidence personnel can recognise PII in practice, for example through spot checks
Common gap: Labelling limited to a confidentiality marking that says nothing about PII
Source: ISO/IEC 27701:2025

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Data governance policy · Information transfer policy