Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.12 Classification of information
ISO/IEC 27001:2022 Annex A 5.12 Classification of information
Information is to be classified according to the organization's security needs, judged on confidentiality, integrity, availability and the requirements of relevant interested parties. Purpose (stated in ISO/IEC 27002:2022): ensures the protection needs of information are identified and understood according to its importance.
Steps that cite it
- KC-01 S1 Classify the information the vendor will handle
Evidence commonly asked for
- Statement of Applicability entry for control A.5.12, showing inclusion or justified exclusion, implementation status and the risks it treats
- The topic-specific classification policy with named levels, criteria based on impact, and conventions covering confidentiality, integrity and availability
- Evidence the scheme was communicated to relevant interested parties and built into procedures
- Classification records in the asset inventory or labels showing owner-assigned classifications
Accepted citation forms are listed on the answer format page.