Expert TipControls & Evidence

Asset Management: Classifying Without Overthinking It

A pragmatic approach to information asset classification that satisfies ISO 27001 without creating bureaucratic overhead.

Updated 9 Mar 2026

The Problem

Many organisations either don't classify assets at all or create a 10-level classification scheme that nobody uses. Both extremes fail.

A Three-Level Scheme That Works

Public

Information intended for public consumption.

Marketing materials, published documentation, public APIs
Handling No special restrictions

Internal

Information for internal use that would cause minor impact if disclosed.

Internal procedures, project plans, meeting notes
Handling Don't share externally, basic access controls

Confidential

Information that would cause significant harm if disclosed.

Customer data, financial records, security configurations, source code, HR records
Handling Encrypted storage and transmission, access logging, strict need-to-know

Optional Fourth Level

Restricted

For highly sensitive information.

Cryptographic keys, incident forensics, board-level strategy
Handling Named access list, enhanced encryption, additional audit logging

Making Classification Stick

1. Label at Creation

Classify documents and data when they're created, not retrospectively.

2. Default to Internal

If unsure, classify as Internal. It's safer than Public and less burdensome than Confidential.

3. Embed in Tools

Use document templates with classification headers. Configure cloud storage folders by classification level.

4. Train Once, Remind Often

A one-time training session won't stick. Use regular reminders and make classification part of document review checklists.

What Auditors Check

Is there a documented classification scheme?
Are assets actually classified? (They'll sample check)
Do handling procedures match classification levels?
Is the scheme practical and understood by staff?
Is there an asset inventory linked to classification?

Common Mistakes

A classification policy exists but nothing is actually classified
Over-classifying everything as Confidential (if everything is confidential, nothing is)
No handling procedures defined for each level
Forgetting to classify data in cloud services and SaaS tools

Related Modules

Standard Controls
Risk Register
Documents

Related Controls / Clauses

A.5.9
A.5.10
A.5.12
A.5.13
A.5.14

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.