ISO 27001 5.12 Classification of Information Requirement:
"Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements."[1]
ISO 27001 5.12 Classification of Information Requirement Explanation:
The organization must create several information/data classification categories. Data classification helps determine the security controls required to protect a certain type of data or information. Common data classifications include "Internal Use Only" "Business Confidential" and "Public". Depending on the organization's legal requirements additional classifications may be required.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you