Summary: Information classification should not result in yet another spreadsheet of levels. The purpose is to understand how serious the consequences would be if information were disclosed, altered incorrectly or made unavailable – and to use the classification to choose the right security measures, supplier requirements and ways of working.
Information classification sounds simple. You identify information, assign a class, done. But the real question comes afterwards: what should the organisation do differently because the information received this classification?
If the answer is ”nothing”, the classification probably has limited value.
What are we actually classifying?
Information classification is normally based on the consequences if the protection of the information is affected. KLASSA, the classification tool from the Swedish Association of Local Authorities and Regions (SKR), describes the model along three dimensions:
- confidentiality
- integrity
- availability
Consequences can affect the organisation itself, other organisations or individuals. A type of information can therefore have completely different needs across the three dimensions.
A public document, for example, may have a low confidentiality requirement. But if the wrong information is published, integrity can be very important. A system may contain information that is not particularly secret but that the business absolutely must be able to access within minutes. Then availability is central.
Classify the consequence – not how secret it feels
It is easy to get stuck on the question ”is this sensitive?”. But the classification becomes more useful if you ask instead:
- What happens if the information ends up with the wrong person?
- What happens if it is incorrect?
- What happens if we cannot access it?
That forces the business to think in terms of consequences. The SKR model assesses precisely the undesired impact on the organisation, another party or an individual as a result of a loss of confidentiality, integrity or availability.
The business needs to own the classification
IT can help. Information security can facilitate. But the people who best understand the consequences are normally the business users of the information.
IT knows how the system is built. But the business owner knows what happens if the order information is wrong, if the patient record is missing, if the customer list leaks or if the production data cannot be used. Information classification therefore also becomes a way of creating dialogue between the business and IT.
The classification should drive the security requirements
This is where the classification starts to create value. If information has a high confidentiality requirement, it can affect access, external sharing, authentication, encryption, logging and supplier requirements, for example.
High integrity requirements can affect change permissions, validation, logging, approval, backup and version control.
High availability requirements can affect redundancy, backup, recovery time objectives (RTO), fallback procedures, monitoring, and support and SLAs.
The classification thus becomes a bridge between the needs of the business and the technical and organisational controls.
Information classification and system classification are not exactly the same
The organisation should start with the needs of the information. Then it needs to understand which systems handle that information. A system can handle several types of information with different classifications. That means the system’s protection level needs to take into account the information actually held there, how it is combined and which parts of the business depend on it.
The SKR guidance also shows how aggregated information can have different consequences from a single data point. That is particularly important for large registers and analytics platforms, for example.
Information classification and Microsoft 365
The classification can also become a practical foundation for modern information governance. For example, the organisation may decide on four levels:
- Public – can be shared externally without particular restrictions.
- Internal – intended for the organisation but not for general publication.
- Confidential – restricted sharing and clear access requirements.
- Highly confidential – stronger restrictions and control.
The classification can then be linked to technology such as sensitivity labels in Microsoft Purview, access rules and other controls. But the technology should come after the classification model is understandable. Otherwise you are simply automating an unclear process.
Do not make the model too sophisticated
A common trap is to create six levels, twelve special rules and hundreds of exceptions. It looks sophisticated. But the user is still standing there with a document in hand, wondering which class to choose.
A simpler model that is actually used is often better than a perfect model that only the information security function understands.
Not everything can be top class
If almost all information ends up at the highest level, prioritisation disappears. That leads either to overly expensive protective measures or to users starting to ignore the rules. The classification therefore needs to be realistic and consequence-based.
How a classification workshop can work
A practical approach is to bring together the information owner, a business representative, IT or the system owner, information security and, where needed, data protection or legal. For each set of information the group discusses:
- What is the information used for?
- Who needs it?
- What harm could result from disclosure?
- What harm could result from inaccuracy?
- How long can the business cope without it?
- Are there external or regulatory requirements?
The result is documented together with the reasoning. The reasoning matters. A number that says ”3” helps very little if nobody remembers why it became a 3.
The classification needs to be maintained
Information sets change. Systems gain new integrations. New regulatory requirements arrive. The business becomes more dependent on certain systems. So the classification is not permanent either.
The methodology guidance from the Swedish National Cyber Security Centre (NCSC) structures information security work as a cycle of identification and analysis, design, use, and follow-up and improvement. Information classification needs to live in the same cycle.
How Kristensson i Skåne can help
Kristensson i Skåne helps organisations with both the method and the delivery of information classification, as part of our work on information security and governance. Support can include, for example:
- classification model
- information inventory
- workshops and facilitation
- mapping to security measures
- system requirements
- supplier requirements
- Microsoft 365 and Purview
- documentation and ongoing management
An example of what this looks like in practice is our information classification engagement at a municipality, which you can find among our reference cases.
Frequently asked questions
What is the difference between information classification and risk analysis?
The classification describes the protection needs of the information. The risk analysis assesses which threats and vulnerabilities could affect it and which measures are needed.
Who should carry out the classification?
The information owner and the business should normally play a central role, supported by information security and IT.
Does every document have to be classified individually?
No. It is often more practical to classify sets or types of information than individual documents.
How often should the classification be updated?
Whenever the business, systems, information content or risk picture changes, and as part of the regular follow-up of information security work.
Do you have a classification model that does not drive anything in practice, or no model at all? Read more about our information security and governance services or contact us for an informal conversation.
Sources: Swedish Association of Local Authorities and Regions (SKR), KLASSA – tool and guidance for information classification; Swedish National Cyber Security Centre (NCSC), methodology guidance for systematic information security work.
This text is general information. Which classification model and which protective measures are appropriate always depends on the individual organisation.

