N.1.09 Organizing information
Control Overview
This control requires the organization to categorize its business information into distinct classification tiers based on sensitivity and confidentiality. For each tier, explicit rules must be defined governing how data is handled, stored, transmitted, and destroyed. Additionally, a clear labeling convention must be established so employees can recognize the confidentiality level of a document or dataset at a glance, eliminating handling errors caused by ambiguity or a lack of awareness.
Applicability Note: This control is fully applicable to the anDREa platform and governs all internal documentation, corporate records, and customer-tenant data tiers.
Compliance & Strategic Approach
Our approach integrates information classification directly into our ISO/IEC 27001-based ISMS, avoiding complex, bureaucratic schemas in favor of a lean, highly operationalized framework.
Instead of overwhelming staff with excessive classification layers, anDREa utilizes a streamlined, two-tier classification scheme: Low/Public and High/Confidential. This classification maps directly to our CIA-AA (Confidentiality, Integrity, Availability, Accountability, and Authenticity) matrix. High/Confidential data automatically triggers stringent technical guardrails—including mandatory encryption, VPN enforcement, strict Role-Based Access Control (RBAC), and secure destruction protocols. To ensure clarity, our labeling convention binds the data classification tier to versioning and date metrics, embedding data lifecycle management directly into our daily operations.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.12 - Classification of information | Enforces the categorization of information into defined schema tiers based on business and privacy risks. |
| ISO/IEC 27001 | A.05.13 - Labelling of information | Mandates the implementation of visible metadata and markings (classification, version, date) on information assets. |
| ISO/IEC 27001 | A.05.15 - Access control | Links High/Confidential data classifications directly to access enforcement mechanisms. |
| Core Security Policy | A.05.12 - Classification of information Data Handling Policy | The authoritative text defining the two-tier classification system, labeling formats, and explicit handling rules. |
| Risk Matrix | Compliance and Risk Matrices | The technical architectural profile mapping security attributes and risk priorities to our primary data environments. |
| Access Enforcement | Asset Overview | Technical configurations restricting access to High/Confidential information (e.g., personnel records or client tenant master data) to authorized roles based on the principle of least privilege. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The classification scheme, mandatory labeling formats, handling rules, and technical RBAC cross-references are simple, operationalized, and auditable.