Information classification and handling policy
The classification scheme, the criteria for each level, the label each carries and the handling rules for each level in each medium.
How the register reads it
| Also called | data classification, handling rules, protective marking |
|---|---|
| Family | Assets, data and classification |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 is ticked and no line resolves to it (ISO 27701 requires it too, inside a parent document, so it does not list it separately). |
| Template | Data classification policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.12 Classification of informationClassify information by confidentiality, integrity, availability and interested-party requirements.
What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.13 Labelling of informationLabel information consistently with the classification scheme so handling rules can follow it.
What the ISO 27002 guidance expects the document to say: Requires a matching set of information labelling procedures to be developed and implemented, so that information carries markings consistent with the classification scheme the organisation has adopted.
Common gap: Labels applied inconsistently across departments
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 A.3.5 Classification of informationThe organization's information classification scheme shall explicitly consider PII, including its type and any special categories, so that classification is the means by which the organization understands what PII it processes, where that PII is stored and the systems through which it can flow.
Common gap: PII treated as ordinary confidential information with no distinction for special categories
Source: ISO/IEC 27701:2025
ISO 27701 A.3.6 Labelling of informationThe organization shall ensure that people under its control are made aware of the definition of PII and of how to recognise information that is PII, so that labelling and handling rules are applied to PII wherever it occurs.
Common gap: Labelling limited to a confidentiality marking that says nothing about PII
Source: ISO/IEC 27701:2025
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register