Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.13 Labelling of Information

Control Objective

An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organisation.

Policy Statement

anDREa enforces clear metadata and labelling requirements for its information assets in alignment with our formal classification scheme. Labelling ensures that internal personnel, users, and external auditors can immediately recognize the sensitivity of an asset and handle it according to its defined lifecycle controls.


Labelling and Versioning Standards

All assets, documents, and records must be explicitly designated under one of the two core classification tiers and paired with strict version control:

  • Labelling Formats: Information assets must be definitively marked as either Low / Public or High / Confidential.
  • Mandatory Metadata: Every document, policy, or major dataset must feature a clear Version Number or Review Date combined with its exact Publication/Update Date to prevent the utilization of obsolete or unapproved revisions.
note

At anDREa versions are managed through dates. This makes the chain of revisions easier to follow and directly shows when what was applicable.


Practical Application & Storage Baselines

To maintain our commitment to transparency while safeguarding critical corporate and user data, assets are managed as follows:

  • Public ISMS Documentation: To ensure open compliance verification, the policy documents comprising anDREa’s Information Security Management System (ISMS) are classified as Low / Public and are openly accessible within our public Knowledge Base.
  • Sensitive Records: Operational data and application state logs are securely stored under High / Confidential protections. Technical enforcement is applied via Role-Based Access Control (RBAC), utilizing the principles of least-privilege and need-to-know.
  • Legal and HR Assets: Customer agreements, supplier contracts, and employee personnel files are mandatorily classified as High / Confidential. These repositories are isolated, restricted, and audited under strict RBAC configurations.