Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.09 Organizing information

Control Overview

This control requires the organization to categorize its business information into distinct classification tiers based on sensitivity and confidentiality. For each tier, explicit rules must be defined governing how data is handled, stored, transmitted, and destroyed. Additionally, a clear labeling convention must be established so employees can recognize the confidentiality level of a document or dataset at a glance, eliminating handling errors caused by ambiguity or a lack of awareness.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs all internal documentation, corporate records, and customer-tenant data tiers.

Compliance & Strategic Approach

Our approach integrates information classification directly into our ISO/IEC 27001-based ISMS, avoiding complex, bureaucratic schemas in favor of a lean, highly operationalized framework.

Instead of overwhelming staff with excessive classification layers, anDREa utilizes a streamlined, two-tier classification scheme: Low/Public and High/Confidential. This classification maps directly to our CIA-AA (Confidentiality, Integrity, Availability, Accountability, and Authenticity) matrix. High/Confidential data automatically triggers stringent technical guardrails—including mandatory encryption, VPN enforcement, strict Role-Based Access Control (RBAC), and secure destruction protocols. To ensure clarity, our labeling convention binds the data classification tier to versioning and date metrics, embedding data lifecycle management directly into our daily operations.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.12 - Classification of informationEnforces the categorization of information into defined schema tiers based on business and privacy risks.
ISO/IEC 27001A.05.13 - Labelling of informationMandates the implementation of visible metadata and markings (classification, version, date) on information assets.
ISO/IEC 27001A.05.15 - Access controlLinks High/Confidential data classifications directly to access enforcement mechanisms.
Core Security PolicyA.05.12 - Classification of information
Data Handling Policy
The authoritative text defining the two-tier classification system, labeling formats, and explicit handling rules.
Risk MatrixCompliance and Risk MatricesThe technical architectural profile mapping security attributes and risk priorities to our primary data environments.
Access EnforcementAsset OverviewTechnical configurations restricting access to High/Confidential information (e.g., personnel records or client tenant master data) to authorized roles based on the principle of least privilege.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The classification scheme, mandatory labeling formats, handling rules, and technical RBAC cross-references are simple, operationalized, and auditable.