Expert Advice Community

Guest

Level of information classification

  Quote
Guest
Guest user Created:   Feb 20, 2020 Last commented:   Feb 20, 2020

Level of information classification

Hello all, I wanted to know what would be the most appropriate level of information classification given to the sensitive and Non-sensitive PII.
Are they considered confidential or less? or just restricted?

0 0

Assign topic to the user

ISO 27001 INFORMATION CLASSIFICATION POLICY

Define the classification levels and how to protect the information.

ISO 27001 INFORMATION CLASSIFICATION POLICY

Define the classification levels and how to protect the information.

Expert
Rhand Leal Feb 20, 2020

Considering ISO 27001 requirements and controls, to define the proper classification level for your information, you have to consider:

  • the results of risk assessment
  • legal requirements (e.g., laws, regulations, and contracts) applicable to your organization

For example, Article 9 of EU GDPR defines special categories of personal data https://advisera.com/eugdpracademy/gdpr/processing-of-special-categories-of-personal-data/ which you should classify with a higher confidentiality level, while the rest of the personal data you can classify with lower confidentiality level.

 This article will provide you a further explanation about information classification:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 20, 2020

Feb 20, 2020