Expert Advice Community

Guest

Categorizing information

  Quote
Guest
Guest user Created:   Jul 11, 2018 Last commented:   Jul 11, 2018

Categorizing information

How to categorize information into levels according to the confidentially?
0 0

Assign topic to the user

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

Expert
Rhand Leal Jul 11, 2018

Answer: Usually, information categorization is done based on the results of the risk assessment: the higher the value of information (the higher the consequence of breaching the confidentiality), the higher the classification level should be. As for the number of levels, ISO 27001 does not prescribe the levels of classification – this is something you should develop on your own, based on what is common in your country or in your industry. The most common arrangements consider 3 or 5 levels.

This article will provide you further explanation about information classification:
- Information classification according to ISO 27001 https://advisera.com/27001academy/blog/2014/05/12/information-classification-according-to-iso-27001/

These materials will also help you regarding information classification:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 11, 2018

Jul 11, 2018

Suggested Topics

Guest user Created:   Mar 15, 2018 ISO 27001 & 22301
Replies: 1
0 0

Risk Assessment

ISO Created:   Dec 26, 2023 ISO 27001 & 22301
Replies: 1
0 0

Information Security Goals