Information classification
Security work that does not know which information matters ends up either too expensive or too thin. We build a classification model the business understands, classify the information together with you and tie the classes to concrete protective measures.
Who it is for and when
Suits organisations about to start working systematically with information security, and businesses that have a model on paper but not in practice.
- You are building a management system and need to know what to protect first.
- Access, encryption and permissions are set differently in different systems with no common basis.
- You are moving information to the cloud and need to know what may go where.
- You have a classification model but nobody has classified anything since it was written.
What we do
- A model tailored to you. We build or adjust a classification model across confidentiality, integrity and availability, with as few levels as the business can actually work with.
- Information owners and information assets. We identify your information assets and who owns them, so that the decisions are made by the business and not by IT.
- Classification in workshops. We classify together with the business in working sessions, document the decisions and settle the borderline cases while everyone is in the room.
- Protective measures per class. Each class is tied to concrete requirements on access, encryption, logging, storage, retention and handling at suppliers.
- Rollout and management. We hand over the model, the classifications and a routine for classifying new information assets, linked to your governing documents.
You get
- A classification model tailored to your organisation
- A record of information assets with named information owners
- Documented classifications from the working sessions
- Protective measures per class, tied to your systems and suppliers
- A routine for continued classification and management
Scope and price
From a few days for a defined operation to about a week when many administrations or information assets are involved. The classification is done in working sessions with the business.
The price varies from engagement to engagement and depends on how many information assets and parts of the business are in scope. You get a clear proposal after the first conversation.
How it works
- A first conversation. We listen to your situation and explain how we usually set the work up. You get our assessment straight away, at no cost.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work alongside your organisation, report as we go and hand over so that you can manage the result yourselves.
Frequently asked questions
How many classes should we have?
As few as possible, usually three or four levels per aspect. A model with many levels looks thorough but goes unused, and then the information is not protected anyway.
Who should classify the information?
The business, through named information owners. IT can describe what is technically possible, but the value of the information and the consequence of it leaking or disappearing is decided in the business.
Does this connect to the GDPR?
Yes. The classification shows where personal data sits and how sensitive it is, which is the basis for records of processing, impact assessments and retention.
What does it cost?
It varies from engagement to engagement and depends on how many information assets and parts of the business are in scope. We give a clear proposal after the first conversation.
Would you like to know which information needs protecting first?
Contact us