SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.12Classification of information

Classify information by how sensitive it is and the impact if it were exposed, so you can apply the right level of protection to each type. A simple tiered scheme is usually enough to start.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0043Data inventory · PolicyenablesKnowing where personal and sensitive data lives is a precondition for classifying it correctly, making the data inventory a foundation A.5.12's classification scheme depends on.RCF-0044Data inventory · ProcessenablesKeeping the data map current as flows change is what stops a classification scheme from going stale the moment new systems or vendors are added.RCF-0045Data inventory · TechnicalenablesAutomated discovery finds sensitive data sitting in unexpected places, giving classification something to act on beyond what people remember to tag by hand.RCF-0052Criticality tagging · PolicyrelatedCriticality tagging rates assets by business importance, a related but distinct dimension from A.5.12's sensitivity classification; the two schemes often sit side by side on the same asset register.RCF-0053Criticality tagging · ProcessrelatedRe-rating criticality as an asset's business role changes mirrors the discipline A.5.12 expects for sensitivity labels, applied to a different axis of risk.RCF-0091Data classification · PolicysupportsSekit's Data classification control defines the sensitivity tiers, such as public, internal and confidential, and the handling each requires, but the policy alone does not classify anything: applying those labels to real documents is a separate practice mapped on this page.RCF-0092Data classification · ProcesssupportsLabelling, storing and sharing documents according to their tier is what makes A.5.12's classification scheme operate in daily work instead of staying a policy document.RCF-0093Data classification · TechnicalsupportsEnforcing handling rules automatically from classification labels, restricted folders, sharing limits, external-share warnings, closes the gap between a written scheme and what people do with a file.RCF-0103DLP monitoring · PolicysupportsMonitoring for sensitive data leaving through unmonitored channels checks that A.5.12's classification tiers are respected in practice, catching confidential data that slips past its intended handling.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Data inventory and classification
The record of the personal and sensitive data the company holds, where it lives and how it is classified by sensitivity.
From the Sekit evidence catalog

In practice

Small companies get the most value from a three-tier scheme, public, internal, confidential, with one concrete example of each so staff do not have to guess. Auditors pull a sample of documents from shared drives and check whether the label matches the content: a spreadsheet of customer identification numbers marked internal rather than confidential is a classic finding. The scheme fails in practice when it stays a policy paragraph nobody applies day to day; the data inventory and classification evidence should show real folders, labels or metadata tags, not only a definitions table.

Common gaps

The classification scheme is defined in policy but no document, folder or file in daily use carries any of the defined labels.
Confidential data such as payroll or health records sits in a shared drive with the same access permissions as general internal documents.
Staff were never told which handling rules apply to each classification tier, so labels exist without any consistent behaviour behind them.

Questions your auditor will ask

What sensitivity levels does your classification scheme use, and what handling does each require?
Show the defined tiers, such as public, internal and confidential, from the classification policy, with the specific handling rule attached to each one.
Can you show an example of a document classified at each level?
Open the data inventory and classification records and point to a real, labelled example at each tier along with its storage location.
How is a document's classification enforced when someone tries to share it externally?
Describe any automated handling rules, such as restricted folders or sharing warnings, tied to the classification label in the systems that support it.

Where regulation demands it

NIS2 art. 12.1 (Asset classification) requires the same tiered sensitivity scheme A.5.12 asks organizations to define and apply.
ENS mp.si.1 (Marcado de soportes) sets the equivalent baseline for marking information according to its sensitivity level.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.12?”
Also via MCP, free with account