2.1 Information & Asset Classification
Information & Asset Classification at a glance
Organisations cannot protect every piece of information and every asset in exactly the same way.
Classification helps determine how important or sensitive something is so that appropriate security requirements can be applied.
Identify
Understand what information and assets the organisation possesses.
What do we have?Classify
Determine sensitivity, criticality and business importance.
How important is it?Protect
Classification helps determine appropriate security requirements.
How much protection does it need?Classification thinking flow
1 What is an Asset? Anything of value to the organisation
In cybersecurity, an asset is not limited to a physical computer or server.
An asset is something that has value to the organisation or its stakeholders.
Tangible assets
Tangible assets have a physical form.
Intangible assets
Intangible assets may have enormous organisational value even though they are not physical objects.
A company laptop may cost ยฃ1,500.
The unreleased product design stored on that laptop could be worth millions of pounds to the organisation.
The value of the information may greatly exceed the value of the physical device containing it.Do not automatically equate the purchase price of an asset with its value to the organisation.
2 Data Classification vs Asset Classification Related concepts with different objects of focus
Categorises information according to its sensitivity, importance, value and protection requirements.
Think: How sensitive is the INFORMATION?
Categorises assets according to characteristics such as business value, criticality, sensitivity or security requirements.
Think: How important is the ASSET?
A database contains customer payment information.
The information may receive a highly sensitive classification because unauthorised disclosure could cause serious harm.
The database service may also be classified as a highly critical asset because important business processes depend on its availability and integrity.
3 Why classify information and assets? Protection should reflect business need
Classification allows organisations to apply security controls proportionately.
Without classification, two common problems appear.
Highly sensitive or critical information receives insufficient security.
Low-value information receives controls that create unnecessary cost and complexity.
Encrypting, tightly restricting and manually approving access to every public marketing brochure would probably provide little benefit.
Applying the same weak protections to cryptographic private keys would be clearly inappropriate.
More sensitive or critical assets normally justify stronger protection than information intended for unrestricted public use.
๐ Types of Information Understand what kind of information you are protecting
Organisations hold many different types of information.
Information relating to identifiable individuals.
Transactions, payment information, forecasts and financial records.
Medical and health-related information.
Information owned by the organisation that provides business value.
Credentials, vulnerabilities, configurations and security designs.
Legal advice, investigations and contractual information.
Information necessary to operate business processes and services.
Information intentionally approved for public disclosure.
Laws, regulations, contractual requirements and organisational policies may establish particular protection requirements for specific types of information.
4 Sensitivity How much protection does the information require?
Sensitivity reflects the importance assigned to information for the purpose of determining its need for protection.
A useful way to think about sensitivity is:
Factors may include
A document describing an unreleased acquisition could be extremely sensitive because premature disclosure could affect markets, negotiations and regulatory obligations.
5 Criticality How important is the asset to business operations?
Criticality concerns how important an asset, system or information resource is to achieving organisational or business objectives.
"What happens to the business if this asset becomes unavailable, unreliable or unusable?"
A public website may contain information that is not confidential at all.
However, if the organisation depends on that website for nearly all of its sales, its availability may be highly critical.
Sensitive does not automatically mean critical.
Critical does not automatically mean confidential.
Sensitivity vs Criticality
Sensitivity = PROTECTION ยท Criticality = DEPENDENCY
๐ Asset Value Value is more than purchase price
Asset value can be influenced by much more than its direct financial replacement cost.
Replacement cost, revenue contribution or financial loss.
Importance to daily business operations.
Legal or evidential importance.
Consequences associated with regulated information or services.
Importance to long-term organisational objectives.
Effect on customer, partner or public trust.
The replacement cost of a database server may be ยฃ10,000.
But the system may support ยฃ20 million of annual revenue and contain information that would create major regulatory consequences if disclosed.
Asset value must be understood in business context.6 Classification and the CIA Triad Consider the consequences of compromise
Classification decisions can consider the potential impact of losing confidentiality, integrity or availability.
What would happen if unauthorised people saw the information?
What would happen if the information were modified incorrectly?
What would happen if the information or asset could not be accessed?
Confidentiality: High importance because unauthorised disclosure exposes personal and financial information.
Integrity: High importance because incorrect salary or account data could create financial harm.
Availability: Particularly important around payroll processing periods.
Do not assume confidentiality is always the dominant consideration.
๐ Impact-Based Categorisation A useful example from NIST
NIST's FIPS 199 framework provides a useful example of categorising information and systems based on the potential impact of a loss of confidentiality, integrity or availability.
Compromise would be expected to have a limited adverse effect.
Compromise would be expected to have a serious adverse effect.
Compromise would be expected to have a severe or catastrophic adverse effect.
FIPS 199 is a U.S. federal security categorisation standard.
It is useful for understanding impact-driven classification thinking, but organisations may use completely different classification schemes.
7 Classification Criteria What factors should influence classification?
Classification should be based on meaningful organisational criteria rather than personal preference.
How valuable is the information or asset to the organisation?
What happens if unauthorised disclosure occurs?
What happens if the information is changed incorrectly?
What happens if the asset is unavailable?
Are there external obligations governing protection?
Have customers or partners established security obligations?
Would disclosure benefit competitors?
How dependent is the organisation on the asset?
Could the required classification change as information ages?
Example corporate classification scheme
Organisations define their own classification models. A simple commercial model might look like this:
| Classification | Meaning | Example |
|---|---|---|
| Public | Approved for unrestricted public disclosure. | Published marketing material. |
| Internal | Intended primarily for use within the organisation. | Internal operating instructions. |
| Confidential | Unauthorised disclosure could cause meaningful harm. | Customer records or commercially sensitive plans. |
| Restricted | Highly sensitive information requiring particularly strong protection. | Private cryptographic keys or highly sensitive strategic data. |
There is no universal commercial classification naming scheme.
Organisations may use different labels, numbers, colours or categories depending on their needs.
๐๏ธ Commercial vs Government Classification Do not assume all classification schemes use the same terminology
Commercial organisations commonly create their own information classification structures.
Government environments may use classification systems established by national law, regulation or government policy.
Do not assume that terms such as Confidential, Secret or Top Secret can be freely mapped to a commercial classification scheme.
Always understand which classification framework applies to the organisation and jurisdiction in question.
8 Who determines classification? Classification needs accountable ownership
Information should have an accountable owner capable of understanding its business purpose and protection requirements.
Has authority and accountability for the information and its protection requirements.
Classification decisions are commonly associated with this role.
Implements or operates controls according to requirements established by appropriate owners and policies.
The custodian does not normally invent the business classification.
The HR function owns employee information and determines its business sensitivity and handling requirements.
The infrastructure team manages the database and backups containing that information.
Operating the technology does not automatically make infrastructure the business owner of the information.Classification should ultimately reflect the business value and consequences associated with the information.
9 Labelling and Marking Communicate classification to people and systems
Classification has limited value if people handling the information cannot determine how it should be treated.
Organisations may therefore use labels or metadata to communicate the classification.
Examples
A document is marked:
CONFIDENTIAL โ CUSTOMER INFORMATION
Security tools may also read the document's metadata and apply appropriate controls automatically.
Classification determines the protection category.
Labelling communicates that classification.
๐ค Manual and Automated Classification Classification can be supported by technology
A user or owner selects the appropriate classification according to policy.
Technology analyses information and applies or recommends classification based on configured rules or detection methods.
A document contains a large quantity of payment-card information.
A data-protection system detects the content and automatically applies an appropriate sensitivity label.
Automated classification depends on appropriate rules, business definitions and oversight.
๐ฆ Classification drives handling requirements The classification should have practical consequences
Classification is useful because it can determine security requirements throughout the information lifecycle.
CISSP objective 2.2 focuses specifically on establishing information and asset handling requirements.
For 2.1, the important concept is that classification determines the level of protection that later handling rules should provide.
๐งฉ Aggregation and Classification Several low-risk pieces can become much more sensitive together
Combining information can sometimes create greater sensitivity or risk than looking at each individual item separately.
Individual employee names may not be particularly sensitive.
Office locations may also be widely known.
But a combined dataset containing:
- employee name;
- home address;
- salary;
- bank details;
- national identification information;
- medical information;
may require significantly stronger protection.
๐ง Classification depends on context The same type of information can have different value in different situations
The CEO's name is publicly available on the company's website.
Classification: Public.
The CEO's personal mobile number and home address are stored in a corporate contact database.
These details may require considerably stronger protection.
Understand the content, purpose, context and potential consequences.
โณ Classification can change over time Sensitivity is not necessarily permanent
The value or sensitivity of information can change during its lifecycle.
A company's quarterly financial results are highly sensitive before they are officially announced.
After authorised public release, much of the same information becomes public.
Classification review may be triggered by:
๐ข Worked classification example Compare different organisational assets
Asset 1 โ Published company brochure
Very low concern โ public disclosure is intentional.
Still relevant โ unauthorised modification could misrepresent the organisation.
Public
Asset 2 โ Internal organisational chart
Some information may not be intended for unrestricted external distribution.
Internal
Asset 3 โ Customer database
High importance because personal or commercially sensitive data may be present.
High importance because incorrect customer records can cause operational and financial harm.
May be highly important if customer-facing processes depend on it.
Confidential
Asset 4 โ Production signing key
Extremely important because disclosure could allow unauthorised parties to impersonate trusted signing processes.
Extremely important because manipulation could undermine trust in signed software or transactions.
Restricted
Ask what would happen if confidentiality, integrity or availability were compromised.
Higher classification usually means stronger controls
Exact controls depend on organisational policy, but the general relationship can be visualised like this:
| Classification | Typical protection approach |
|---|---|
| Public | Protect integrity and availability as appropriate, but disclosure is permitted. |
| Internal | Limit routine distribution to authorised organisational users. |
| Confidential | Stronger access, storage and transmission controls. |
| Restricted | Highly controlled access and stronger technical and procedural safeguards. |
This table illustrates the relationship between classification and protection. Actual requirements must come from the organisation's classification and handling policies.
โ๏ธ Overclassification and Underclassification Classification needs to be proportionate
Information receives less protection than its actual sensitivity requires.
Result: unnecessary risk.
Information receives stronger restrictions than its real sensitivity requires.
Result: unnecessary cost and friction.
If every internal document is classified at the organisation's highest level, employees may struggle to share ordinary working information.
Overuse of the highest classification may also reduce the practical meaning of the classification system.
๐ป Unknown and Unclassified Assets You cannot classify what you do not know exists
Classification depends on asset visibility.
Organisations may struggle to protect:
A project team exports sensitive customer records into an unmanaged cloud collaboration service.
The organisation's formal database remains correctly classified and protected.
But another copy of the same information now exists outside the expected controls.The organisation first needs reasonable visibility of its information and assets before it can classify and protect them consistently.
โ ๏ธ Common mistakes Classification concepts frequently misunderstood
Assets can also include information, software, services, intellectual property, people, capabilities and reputation.
Business value includes operational, legal, regulatory, strategic and reputational consequences as well as replacement cost.
Sensitivity concerns protection needs, while criticality concerns the organisation's dependence on the asset or information.
Public information may not require confidentiality, but its integrity and availability may still be important.
Technical teams can advise and implement controls, but classification should reflect appropriate business ownership and organisational policy.
Overclassification can create unnecessary cost and operational friction.
Sensitivity and business value may change, so classification may require review.
Classification determines the security category. Labelling communicates that category.
Aggregating information can increase sensitivity and potential impact.
The sensitivity derives from the information and its business context, not simply from the technology storing it.
Start with business value and impact
CISSP classification questions often test whether you understand that protection requirements should follow the value, sensitivity and criticality of information and assets.
๐ Identify clues
๐ Value clues
๐ Confidentiality clues
โ Integrity clues
โก Availability clues
๐ท๏ธ Classification clues
When asked how something should be protected, first determine what it is worth, how sensitive it is, how critical it is and what the business consequences of compromise would be.
๐ Practice scenarios Apply classification thinking
Scenario 1
An organisation has a publicly available product catalogue.
Does the information require confidentiality?
Normally very little, because public disclosure is intentional. Integrity and availability may still matter.
Scenario 2
Employee medical records are stored in an HR system.
Which classification factor is especially important?
Information sensitivity and the potential privacy impact of unauthorised disclosure.
Scenario 3
An e-commerce website contains only publicly available product information but generates 90% of company revenue.
What concept is particularly important?
Criticality. Confidentiality may be low, while availability is highly important.
Scenario 4
A network engineer manages the server containing customer records.
Does this automatically make the engineer the information owner?
No. Technical administration or custody does not automatically create business ownership of the information.
Scenario 5
Every company document is assigned the organisation's highest classification.
What problem may result?
Overclassification, creating unnecessary cost and operational restrictions.
Scenario 6
A public press release is accidentally modified on the company website to contain false information.
Which CIA property has primarily been affected?
Integrity.
Scenario 7
Quarterly financial results are highly restricted before public announcement.
The same results are later published on the company's website.
What does this demonstrate?
Classification can change as the sensitivity and context of information changes.
Scenario 8
A user selects "Confidential" from a document menu.
Is that classification or labelling?
The business classification is the security category assigned to the information. The visible marker communicating it is the label.
Scenario 9
A company discovers an unmanaged cloud database containing customer information.
What fundamental problem existed before classification could even be applied?
The organisation lacked visibility of the asset.
Scenario 10
A source-code repository contains a production private key.
Which item would likely drive particularly strong protection?
The private key because compromise could enable unauthorised use of the associated cryptographic identity or function.
Scenario 11
Several individually low-sensitivity datasets are combined into a detailed customer profile.
What should happen?
Reassess the sensitivity and classification of the combined dataset.
Scenario 12
A security analyst believes that a business document should be highly restricted. The business owner believes the information is already intended for public release.
Whose business context is particularly important?
The accountable information owner should determine classification according to organisational policy, with security providing relevant advice.
Classification memory aid
Identify. Value. Classify. Label. Protect.
Classification impact questions
Disclosure. Modification. Unavailability.
Key takeaways
CISSP Domain 2.1 requires understanding both information classification and asset classification.
Assets can be tangible or intangible and include much more than physical IT equipment.
Information, software, intellectual property, services, people, cryptographic material and reputation can all represent valuable assets.
Classification helps organisations apply protection proportionately.
Information classification focuses on the sensitivity, value and protection requirements of information.
Asset classification focuses on the importance, criticality and security requirements of organisational assets.
Sensitivity concerns how much protection information requires.
Criticality concerns how dependent the organisation is on an asset or information resource.
Sensitive and critical are therefore related but not interchangeable.
Classification should consider the business consequences associated with losing confidentiality, integrity or availability.
Asset value should not be judged only by replacement cost.
Financial, operational, legal, regulatory, reputational and strategic consequences can all contribute to value.
Organisations may use very different classification schemes. Labels such as Public, Internal, Confidential and Restricted are examples rather than universal standards.
Classification and labelling are different: classification determines the security category, while labelling communicates it.
Information ownership matters because classification should reflect business purpose and impact rather than simply technical opinion.
Aggregating information can increase sensitivity even when individual pieces of data appear relatively harmless.
Classification can change over time as information loses sensitivity, becomes public or is used for a new purpose.
Overclassification creates unnecessary cost and restrictions, while underclassification creates unnecessary risk.
Most importantly: understand what the organisation has, understand why it matters, and classify it according to the consequences of compromise.
๐ Sources & Further Reading Authoritative references
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - NIST FIPS 199 โ Standards for Security Categorization of Federal Information and Information Systems
View NIST publication - NIST SP 800-60 Vol. 1 Rev. 1 โ Guide for Mapping Types of Information and Information Systems to Security Categories
View NIST guidance - NIST โ Asset Glossary Definition
View NIST definition - NIST โ Sensitivity Glossary Definition
View NIST definition - NIST โ Criticality Glossary Definition
View NIST definition - NIST โ Information Owner Glossary Definition
View NIST definition
