A.5.12 Classification of Information
Control Objective
Information shall be classified according to the information security needs of the organisation based on confidentiality, integrity, availability and relevant interested party requirements.
Policy Statement
anDREa systematically classifies its data, applications, and infrastructure assets to ensure that information receives an appropriate level of protection. Data is categorized based on its Confidentiality, Integrity, Availability, Auditability, and Authenticity (mydre CIA-AA Classification) profile, ensuring strict alignment with ISO/IEC 27001, NIS 2, and GDPR requirements.
Information Classification Matrix
anDREa defines two primary information classification levels based on operational and security impact:
| Classification | Core CIA-AA Profile | Impact Description | Handling Requirements & Guidelines |
|---|---|---|---|
| Low / Public | Low to Medium across all dimensions | Loss, alteration, or public exposure of the asset results in minimal operational impact and involves no proprietary or privacy-sensitive data. |
|
| High / Confidential | High across all dimensions | Loss, alteration, or unauthorized exposure of the asset can cause severe impact, including the compromise of proprietary source code, trade secrets, or PII belonging to anDREa, partners, prospects, or clients. |
|