2.1 Information & Asset Classification

CISSP Domain 2 ยท 2.1

Information & Asset Classification at a glance

Organisations cannot protect every piece of information and every asset in exactly the same way.

Classification helps determine how important or sensitive something is so that appropriate security requirements can be applied.

๐Ÿ”Ž

Identify

Understand what information and assets the organisation possesses.

What do we have?
๐Ÿท๏ธ

Classify

Determine sensitivity, criticality and business importance.

How important is it?
๐Ÿ›ก๏ธ

Protect

Classification helps determine appropriate security requirements.

How much protection does it need?

Classification thinking flow

๐Ÿ”Ž Identify โ†’ What information or asset exists?
๐Ÿ’Ž Value โ†’ Why is it important?
โš ๏ธ Impact โ†’ What happens if it is compromised?
๐Ÿท๏ธ Classify โ†’ Assign the appropriate classification
๐Ÿ“ Label โ†’ Communicate the classification where appropriate
๐Ÿ›ก๏ธ Protect โ†’ Apply controls according to requirements
1 What is an Asset? Anything of value to the organisation

In cybersecurity, an asset is not limited to a physical computer or server.

An asset is something that has value to the organisation or its stakeholders.

Tangible assets

Tangible assets have a physical form.

Laptops Servers Network Equipment Phones Buildings Storage Media Security Devices

Intangible assets

Intangible assets may have enormous organisational value even though they are not physical objects.

Information Software Services Intellectual Property Reputation Business Processes Cryptographic Keys Source Code People & Knowledge
Example

A company laptop may cost ยฃ1,500.

The unreleased product design stored on that laptop could be worth millions of pounds to the organisation.

The value of the information may greatly exceed the value of the physical device containing it.
CISSP mindset

Do not automatically equate the purchase price of an asset with its value to the organisation.

2 Data Classification vs Asset Classification Related concepts with different objects of focus
Data / Information Classification

Categorises information according to its sensitivity, importance, value and protection requirements.

Think: How sensitive is the INFORMATION?

Asset Classification

Categorises assets according to characteristics such as business value, criticality, sensitivity or security requirements.

Think: How important is the ASSET?

Example

A database contains customer payment information.

The information may receive a highly sensitive classification because unauthorised disclosure could cause serious harm.

The database service may also be classified as a highly critical asset because important business processes depend on its availability and integrity.

Information and the system containing it are related โ€” but they are not the same thing.
3 Why classify information and assets? Protection should reflect business need

Classification allows organisations to apply security controls proportionately.

Without classification, two common problems appear.

Under-protection

Highly sensitive or critical information receives insufficient security.

Over-protection

Low-value information receives controls that create unnecessary cost and complexity.

Example

Encrypting, tightly restricting and manually approving access to every public marketing brochure would probably provide little benefit.

Applying the same weak protections to cryptographic private keys would be clearly inappropriate.

Classification supports proportional security

More sensitive or critical assets normally justify stronger protection than information intended for unrestricted public use.

๐Ÿ“„ Types of Information Understand what kind of information you are protecting

Organisations hold many different types of information.

Personal Information

Information relating to identifiable individuals.

Financial Information

Transactions, payment information, forecasts and financial records.

Health Information

Medical and health-related information.

Proprietary Information

Information owned by the organisation that provides business value.

Security Information

Credentials, vulnerabilities, configurations and security designs.

Legal Information

Legal advice, investigations and contractual information.

Operational Information

Information necessary to operate business processes and services.

Public Information

Information intentionally approved for public disclosure.

Information type can influence classification

Laws, regulations, contractual requirements and organisational policies may establish particular protection requirements for specific types of information.

4 Sensitivity How much protection does the information require?

Sensitivity reflects the importance assigned to information for the purpose of determining its need for protection.

A useful way to think about sensitivity is:

What harm could result if this information were seen, changed or used by someone who should not have access to it?

Factors may include

Privacy Impact Financial Loss Legal Consequences Regulatory Consequences Competitive Harm Fraud Reputation Security Exposure
Example

A document describing an unreleased acquisition could be extremely sensitive because premature disclosure could affect markets, negotiations and regulatory obligations.

5 Criticality How important is the asset to business operations?

Criticality concerns how important an asset, system or information resource is to achieving organisational or business objectives.

Ask:

"What happens to the business if this asset becomes unavailable, unreliable or unusable?"

Example

A public website may contain information that is not confidential at all.

However, if the organisation depends on that website for nearly all of its sales, its availability may be highly critical.

Important distinction

Sensitive does not automatically mean critical.

Critical does not automatically mean confidential.

Sensitivity vs Criticality

Sensitivity How much PROTECTION does the information need?
Criticality How much does the BUSINESS depend on it?
Sensitive example Employee medical information
Critical example Public customer booking service

Sensitivity = PROTECTION ยท Criticality = DEPENDENCY

๐Ÿ’Ž Asset Value Value is more than purchase price

Asset value can be influenced by much more than its direct financial replacement cost.

Financial Value

Replacement cost, revenue contribution or financial loss.

Operational Value

Importance to daily business operations.

Legal Value

Legal or evidential importance.

Regulatory Value

Consequences associated with regulated information or services.

Strategic Value

Importance to long-term organisational objectives.

Reputational Value

Effect on customer, partner or public trust.

Example

The replacement cost of a database server may be ยฃ10,000.

But the system may support ยฃ20 million of annual revenue and contain information that would create major regulatory consequences if disclosed.

Asset value must be understood in business context.
6 Classification and the CIA Triad Consider the consequences of compromise

Classification decisions can consider the potential impact of losing confidentiality, integrity or availability.

๐Ÿ”’ Confidentiality

What would happen if unauthorised people saw the information?

โœ… Integrity

What would happen if the information were modified incorrectly?

โšก Availability

What would happen if the information or asset could not be accessed?

Example: employee payroll information

Confidentiality: High importance because unauthorised disclosure exposes personal and financial information.

Integrity: High importance because incorrect salary or account data could create financial harm.

Availability: Particularly important around payroll processing periods.

Different CIA dimensions can have different importance

Do not assume confidentiality is always the dominant consideration.

๐Ÿ“Š Impact-Based Categorisation A useful example from NIST

NIST's FIPS 199 framework provides a useful example of categorising information and systems based on the potential impact of a loss of confidentiality, integrity or availability.

Low Impact

Compromise would be expected to have a limited adverse effect.

Moderate Impact

Compromise would be expected to have a serious adverse effect.

High Impact

Compromise would be expected to have a severe or catastrophic adverse effect.

Important

FIPS 199 is a U.S. federal security categorisation standard.

It is useful for understanding impact-driven classification thinking, but organisations may use completely different classification schemes.

7 Classification Criteria What factors should influence classification?

Classification should be based on meaningful organisational criteria rather than personal preference.

Business Value

How valuable is the information or asset to the organisation?

Confidentiality Impact

What happens if unauthorised disclosure occurs?

Integrity Impact

What happens if the information is changed incorrectly?

Availability Impact

What happens if the asset is unavailable?

Legal and Regulatory Requirements

Are there external obligations governing protection?

Contractual Requirements

Have customers or partners established security obligations?

Competitive Value

Would disclosure benefit competitors?

Business Criticality

How dependent is the organisation on the asset?

Time Sensitivity

Could the required classification change as information ages?

Example corporate classification scheme

Organisations define their own classification models. A simple commercial model might look like this:

ClassificationMeaningExample
PublicApproved for unrestricted public disclosure.Published marketing material.
InternalIntended primarily for use within the organisation.Internal operating instructions.
ConfidentialUnauthorised disclosure could cause meaningful harm.Customer records or commercially sensitive plans.
RestrictedHighly sensitive information requiring particularly strong protection.Private cryptographic keys or highly sensitive strategic data.
This is an illustrative model

There is no universal commercial classification naming scheme.

Organisations may use different labels, numbers, colours or categories depending on their needs.

๐Ÿ›๏ธ Commercial vs Government Classification Do not assume all classification schemes use the same terminology

Commercial organisations commonly create their own information classification structures.

Government environments may use classification systems established by national law, regulation or government policy.

Important CISSP principle

Do not assume that terms such as Confidential, Secret or Top Secret can be freely mapped to a commercial classification scheme.

Always understand which classification framework applies to the organisation and jurisdiction in question.

8 Who determines classification? Classification needs accountable ownership

Information should have an accountable owner capable of understanding its business purpose and protection requirements.

Information / Data Owner

Has authority and accountability for the information and its protection requirements.

Classification decisions are commonly associated with this role.

Custodian

Implements or operates controls according to requirements established by appropriate owners and policies.

The custodian does not normally invent the business classification.

Example

The HR function owns employee information and determines its business sensitivity and handling requirements.

The infrastructure team manages the database and backups containing that information.

Operating the technology does not automatically make infrastructure the business owner of the information.
CISSP mindset

Classification should ultimately reflect the business value and consequences associated with the information.

9 Labelling and Marking Communicate classification to people and systems

Classification has limited value if people handling the information cannot determine how it should be treated.

Organisations may therefore use labels or metadata to communicate the classification.

Examples

Document Headers Document Footers Email Labels File Metadata Database Tags Cloud Labels Physical Media Labels
Example

A document is marked:

CONFIDENTIAL โ€” CUSTOMER INFORMATION

Security tools may also read the document's metadata and apply appropriate controls automatically.

Classification and labelling are related but different

Classification determines the protection category.

Labelling communicates that classification.

๐Ÿค– Manual and Automated Classification Classification can be supported by technology
Manual Classification

A user or owner selects the appropriate classification according to policy.

Automated Classification

Technology analyses information and applies or recommends classification based on configured rules or detection methods.

Example

A document contains a large quantity of payment-card information.

A data-protection system detects the content and automatically applies an appropriate sensitivity label.

Automation still needs governance

Automated classification depends on appropriate rules, business definitions and oversight.

๐Ÿ“ฆ Classification drives handling requirements The classification should have practical consequences

Classification is useful because it can determine security requirements throughout the information lifecycle.

๐Ÿท๏ธ Classification โ†’ How sensitive or important is it?
๐Ÿ‘ค Access โ†’ Who may use it?
๐Ÿ’พ Storage โ†’ Where may it be stored?
๐Ÿ“ค Transmission โ†’ How may it be sent?
๐Ÿ—‘๏ธ Disposal โ†’ How must it eventually be destroyed?
Coming next in Domain 2

CISSP objective 2.2 focuses specifically on establishing information and asset handling requirements.

For 2.1, the important concept is that classification determines the level of protection that later handling rules should provide.

๐Ÿงฉ Aggregation and Classification Several low-risk pieces can become much more sensitive together

Combining information can sometimes create greater sensitivity or risk than looking at each individual item separately.

Example

Individual employee names may not be particularly sensitive.

Office locations may also be widely known.

But a combined dataset containing:

  • employee name;
  • home address;
  • salary;
  • bank details;
  • national identification information;
  • medical information;

may require significantly stronger protection.

Classification may need reassessment when information is combined.
๐Ÿง  Classification depends on context The same type of information can have different value in different situations
Example 1

The CEO's name is publicly available on the company's website.

Classification: Public.

Example 2

The CEO's personal mobile number and home address are stored in a corporate contact database.

These details may require considerably stronger protection.

Do not classify based only on a field name

Understand the content, purpose, context and potential consequences.

โณ Classification can change over time Sensitivity is not necessarily permanent

The value or sensitivity of information can change during its lifecycle.

Example

A company's quarterly financial results are highly sensitive before they are officially announced.

After authorised public release, much of the same information becomes public.

Classification review may be triggered by:

Public Release Age of Information Business Change Legal Change Contract Change Asset Disposal New Use
Classification should be reviewed rather than assumed to remain correct forever.
๐Ÿข Worked classification example Compare different organisational assets

Asset 1 โ€” Published company brochure

Confidentiality

Very low concern โ€” public disclosure is intentional.

Integrity

Still relevant โ€” unauthorised modification could misrepresent the organisation.

Illustrative classification

Public

Asset 2 โ€” Internal organisational chart

Confidentiality

Some information may not be intended for unrestricted external distribution.

Illustrative classification

Internal

Asset 3 โ€” Customer database

Confidentiality

High importance because personal or commercially sensitive data may be present.

Integrity

High importance because incorrect customer records can cause operational and financial harm.

Availability

May be highly important if customer-facing processes depend on it.

Illustrative classification

Confidential

Asset 4 โ€” Production signing key

Confidentiality

Extremely important because disclosure could allow unauthorised parties to impersonate trusted signing processes.

Integrity

Extremely important because manipulation could undermine trust in signed software or transactions.

Illustrative classification

Restricted

The classification is driven by consequence

Ask what would happen if confidentiality, integrity or availability were compromised.

Higher classification usually means stronger controls

Exact controls depend on organisational policy, but the general relationship can be visualised like this:

ClassificationTypical protection approach
PublicProtect integrity and availability as appropriate, but disclosure is permitted.
InternalLimit routine distribution to authorised organisational users.
ConfidentialStronger access, storage and transmission controls.
RestrictedHighly controlled access and stronger technical and procedural safeguards.

This table illustrates the relationship between classification and protection. Actual requirements must come from the organisation's classification and handling policies.

โš–๏ธ Overclassification and Underclassification Classification needs to be proportionate
Underclassification

Information receives less protection than its actual sensitivity requires.

Result: unnecessary risk.

Overclassification

Information receives stronger restrictions than its real sensitivity requires.

Result: unnecessary cost and friction.

Example

If every internal document is classified at the organisation's highest level, employees may struggle to share ordinary working information.

Overuse of the highest classification may also reduce the practical meaning of the classification system.

Classification should be appropriate, not automatically maximum.
๐Ÿ‘ป Unknown and Unclassified Assets You cannot classify what you do not know exists

Classification depends on asset visibility.

Organisations may struggle to protect:

Shadow IT Unknown Cloud Storage Forgotten Databases Unmanaged Devices Old Backups Personal Copies Unregistered Applications
Example

A project team exports sensitive customer records into an unmanaged cloud collaboration service.

The organisation's formal database remains correctly classified and protected.

But another copy of the same information now exists outside the expected controls.
Asset discovery supports classification

The organisation first needs reasonable visibility of its information and assets before it can classify and protect them consistently.

โš ๏ธ Common mistakes Classification concepts frequently misunderstood
"Assets are physical devices."

Assets can also include information, software, services, intellectual property, people, capabilities and reputation.

"The most expensive asset is automatically the most important."

Business value includes operational, legal, regulatory, strategic and reputational consequences as well as replacement cost.

"Sensitive and critical mean the same thing."

Sensitivity concerns protection needs, while criticality concerns the organisation's dependence on the asset or information.

"Public information does not need security."

Public information may not require confidentiality, but its integrity and availability may still be important.

"IT decides how business information is classified."

Technical teams can advise and implement controls, but classification should reflect appropriate business ownership and organisational policy.

"Everything should be classified at the highest level to be safe."

Overclassification can create unnecessary cost and operational friction.

"Once classified, information keeps that classification forever."

Sensitivity and business value may change, so classification may require review.

"Labelling and classification are the same thing."

Classification determines the security category. Labelling communicates that category.

"If each individual data item is low sensitivity, the combined dataset must also be low sensitivity."

Aggregating information can increase sensitivity and potential impact.

"A server determines how sensitive the information is."

The sensitivity derives from the information and its business context, not simply from the technology storing it.

CISSP Exam Perspective

Start with business value and impact

CISSP classification questions often test whether you understand that protection requirements should follow the value, sensitivity and criticality of information and assets.

๐Ÿ”Ž Identify clues

Asset Information Inventory Business Purpose Owner

๐Ÿ’Ž Value clues

Sensitivity Criticality Business Impact Legal Regulatory

๐Ÿ”’ Confidentiality clues

Disclosure Privacy Secrets Need-to-Know

โœ… Integrity clues

Accuracy Modification Trust Correctness

โšก Availability clues

Critical Service Downtime Business Dependency Operations

๐Ÿท๏ธ Classification clues

Owner Label Classification Level Protection Review
Exam shortcut

When asked how something should be protected, first determine what it is worth, how sensitive it is, how critical it is and what the business consequences of compromise would be.

๐Ÿ“ Practice scenarios Apply classification thinking

Scenario 1

An organisation has a publicly available product catalogue.

Does the information require confidentiality?

Normally very little, because public disclosure is intentional. Integrity and availability may still matter.

Scenario 2

Employee medical records are stored in an HR system.

Which classification factor is especially important?

Information sensitivity and the potential privacy impact of unauthorised disclosure.

Scenario 3

An e-commerce website contains only publicly available product information but generates 90% of company revenue.

What concept is particularly important?

Criticality. Confidentiality may be low, while availability is highly important.

Scenario 4

A network engineer manages the server containing customer records.

Does this automatically make the engineer the information owner?

No. Technical administration or custody does not automatically create business ownership of the information.

Scenario 5

Every company document is assigned the organisation's highest classification.

What problem may result?

Overclassification, creating unnecessary cost and operational restrictions.

Scenario 6

A public press release is accidentally modified on the company website to contain false information.

Which CIA property has primarily been affected?

Integrity.

Scenario 7

Quarterly financial results are highly restricted before public announcement.

The same results are later published on the company's website.

What does this demonstrate?

Classification can change as the sensitivity and context of information changes.

Scenario 8

A user selects "Confidential" from a document menu.

Is that classification or labelling?

The business classification is the security category assigned to the information. The visible marker communicating it is the label.

Scenario 9

A company discovers an unmanaged cloud database containing customer information.

What fundamental problem existed before classification could even be applied?

The organisation lacked visibility of the asset.

Scenario 10

A source-code repository contains a production private key.

Which item would likely drive particularly strong protection?

The private key because compromise could enable unauthorised use of the associated cryptographic identity or function.

Scenario 11

Several individually low-sensitivity datasets are combined into a detailed customer profile.

What should happen?

Reassess the sensitivity and classification of the combined dataset.

Scenario 12

A security analyst believes that a business document should be highly restricted. The business owner believes the information is already intended for public release.

Whose business context is particularly important?

The accountable information owner should determine classification according to organisational policy, with security providing relevant advice.

Classification memory aid

Identify What do we HAVE?
Value Why does it MATTER?
Sensitivity How much PROTECTION?
Criticality How much DEPENDENCY?
Classify Which CATEGORY?
Label How do we COMMUNICATE it?

Identify. Value. Classify. Label. Protect.

Classification impact questions

Confidentiality What if someone SEES it?
Integrity What if someone CHANGES it?
Availability What if we cannot ACCESS it?

Disclosure. Modification. Unavailability.

Key takeaways

CISSP Domain 2.1 requires understanding both information classification and asset classification.

Assets can be tangible or intangible and include much more than physical IT equipment.

Information, software, intellectual property, services, people, cryptographic material and reputation can all represent valuable assets.

Classification helps organisations apply protection proportionately.

Information classification focuses on the sensitivity, value and protection requirements of information.

Asset classification focuses on the importance, criticality and security requirements of organisational assets.

Sensitivity concerns how much protection information requires.

Criticality concerns how dependent the organisation is on an asset or information resource.

Sensitive and critical are therefore related but not interchangeable.

Classification should consider the business consequences associated with losing confidentiality, integrity or availability.

Asset value should not be judged only by replacement cost.

Financial, operational, legal, regulatory, reputational and strategic consequences can all contribute to value.

Organisations may use very different classification schemes. Labels such as Public, Internal, Confidential and Restricted are examples rather than universal standards.

Classification and labelling are different: classification determines the security category, while labelling communicates it.

Information ownership matters because classification should reflect business purpose and impact rather than simply technical opinion.

Aggregating information can increase sensitivity even when individual pieces of data appear relatively harmless.

Classification can change over time as information loses sensitivity, becomes public or is used for a new purpose.

Overclassification creates unnecessary cost and restrictions, while underclassification creates unnecessary risk.

Most importantly: understand what the organisation has, understand why it matters, and classify it according to the consequences of compromise.

๐Ÿ“š Sources & Further Reading Authoritative references