DAT-001 Data Classification Scheme
Description
A documented data classification scheme exists that categorises all information by sensitivity level (e.g. Public, Internal, Confidential, Restricted). All information assets are classified at creation or ingestion, and handling controls are proportionate to the assigned classification.
Rationale
Classification is the prerequisite for all other data protection controls. Without it, encryption strength, access scoping, retention periods and transfer rules cannot be applied proportionately.
Applicability (9 profiles)
Framework Mappings (18)
| DCS-06 | Assets Classification | full |
| DSP-01 | Security and Privacy Policy and Procedures | partial |
| DSP-04 | Data Classification | full |
| IAM-16 | Knowledge Access Control - Need to Know | informative |
| DCS-06 | Assets Classification | full |
| DSP-01 | Security and Privacy Policy and Procedures | partial |
| DSP-04 | Data Classification | full |
| GDPR-Art.5.1c | Data Minimisation | informative |
| HIPAA-164.308.a.4.i | Information Access Management | informative |
| 5.12 | Classification of information | full |
| 5.13 | Labelling of information | informative |
| AML.M0000 | Limit Public Release of Information | informative |
| NIS2-CIR-12.1 | Asset Classification | partial |
| NIS2-CIR-9 | Cryptography | informative |
| AC-22 | Publicly Accessible Content | partial |
| RA-2 | Security Categorization | full |
| GV-6.1-001 | Third-Party AI Risk Policies | GV-6.1-001 | informative |
| C1.1 | Confidential Information Identification and Maintenance | full |
Evidence (2)
Data classification policy defining sensitivity tiers, their criteria, and handling requirements for each tier across storage, transmission, sharing and disposal.
Example: Data Classification Policy v2.1 (Confluence / Google Drive), approved by DPO and CISO, defining Public / Internal / Confidential / Restricted tiers with explicit handling rules per tier
Test: Request the data classification policy. Verify: (1) defines at least 3 distinct sensitivity tiers with unambiguous criteria for each, (2) specifies handling requirements for storage, transmission, sharing and disposal per tier, (3) document is approved by a named owner and dated within the last 12 months, (4) policy is accessible to all staff.
Data inventory or asset register showing each data asset classified against the published sensitivity tiers.
Example: Data Asset Register (Notion / spreadsheet), listing data stores, classification tier assigned, date last reviewed, and responsible data owner, exported at audit date
Test: Request the data asset register and the list of data stores held in the system component inventory. Verify: (1) every data store or data category in the register carries a classification drawn from the published scheme, (2) every data store holding personal data carries a classification, (3) every entry carries a last-reviewed date within the defined interval, (4) every data store present in the component inventory appears in the register, (5) every classification used in the register is one the scheme defines.
Questions (3)
Does your organisation maintain a documented data classification scheme?
The policy should define at least three tiers (e.g. Public / Internal / Confidential / Restricted) and specify handling rules for storage, transmission, sharing and disposal at each tier. It must be approved by a named owner and reviewed within the last 12 months.
How are data assets assigned a classification tier?
Automated tooling provides the most reliable coverage at scale. Manual classification by data owners is acceptable for smaller or less dynamic data sets, provided a data inventory confirms consistent application.
For which of the following does the classification scheme define handling controls at each sensitivity level?
A scheme that names sensitivity levels without saying what changes between them gives an asset owner nothing to apply. Answer against the scheme as written, not against what the organisation does in practice.