Classify information by how sensitive it is and the impact if it were exposed, so you can apply the right level of protection to each type. A simple tiered scheme is usually enough to start.
Mapping at a glance
A.5.12Classification of informationISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Data inventory and classification
The record of the personal and sensitive data the company holds, where it lives and how it is classified by sensitivity.
From the Sekit evidence catalog
In practice
Small companies get the most value from a three-tier scheme, public, internal, confidential, with one concrete example of each so staff do not have to guess. Auditors pull a sample of documents from shared drives and check whether the label matches the content: a spreadsheet of customer identification numbers marked internal rather than confidential is a classic finding. The scheme fails in practice when it stays a policy paragraph nobody applies day to day; the data inventory and classification evidence should show real folders, labels or metadata tags, not only a definitions table.
Common gaps
The classification scheme is defined in policy but no document, folder or file in daily use carries any of the defined labels.
Confidential data such as payroll or health records sits in a shared drive with the same access permissions as general internal documents.
Staff were never told which handling rules apply to each classification tier, so labels exist without any consistent behaviour behind them.
Questions your auditor will ask
What sensitivity levels does your classification scheme use, and what handling does each require?
Show the defined tiers, such as public, internal and confidential, from the classification policy, with the specific handling rule attached to each one.
Can you show an example of a document classified at each level?
Open the data inventory and classification records and point to a real, labelled example at each tier along with its storage location.
How is a document's classification enforced when someone tries to share it externally?
Describe any automated handling rules, such as restricted folders or sharing warnings, tied to the classification label in the systems that support it.
Where regulation demands it
NIS2 art. 12.1 (Asset classification) requires the same tiered sensitivity scheme A.5.12 asks organizations to define and apply.
ENS mp.si.1 (Marcado de soportes) sets the equivalent baseline for marking information according to its sensitivity level.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.