Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.12 Classification of Information

Control Objective

Information shall be classified according to the information security needs of the organisation based on confidentiality, integrity, availability and relevant interested party requirements.

Policy Statement

anDREa systematically classifies its data, applications, and infrastructure assets to ensure that information receives an appropriate level of protection. Data is categorized based on its Confidentiality, Integrity, Availability, Auditability, and Authenticity (mydre CIA-AA Classification) profile, ensuring strict alignment with ISO/IEC 27001, NIS 2, and GDPR requirements.


Information Classification Matrix

anDREa defines two primary information classification levels based on operational and security impact:

ClassificationCore CIA-AA ProfileImpact DescriptionHandling Requirements & Guidelines
Low / PublicLow to Medium across all dimensionsLoss, alteration, or public exposure of the asset results in minimal operational impact and involves no proprietary or privacy-sensitive data.
  • Handle with care and use as intended.
  • Follow individual asset lifecycle instructions when applicable.
High / ConfidentialHigh across all dimensionsLoss, alteration, or unauthorized exposure of the asset can cause severe impact, including the compromise of proprietary source code, trade secrets, or PII belonging to anDREa, partners, prospects, or clients.
  • Access restricted via Role-Based Access Control (RBAC) on a strict need-to-know, least-privilege basis.
  • Mandatorily password/passphrase protected.
  • Storage must be cryptographically encrypted (e.g., BitLocker).
  • Untrusted network connections require an encrypted VPN (Home, secure personal hotspots, and Eduroam are pre-approved safely).
  • Shared devices must utilize isolated, separate user accounts.
  • Local environments must be locked securely when unattended.
  • Upon offboarding, all local copies must be securely sanitized/erased beyond recovery.