← Reference · Home · Print this page
Cybersecurity · Awareness
Information Classification and Handling
Reference entry · last updated 20261006
Information classification assigns information to categories so that an organisation can apply appropriate controls. Handling is how that information is accessed, stored, shared, transported, and destroyed.[1][2]
First principles and definitions
Classification begins with the information and its protection needs. The NIST SP 1800-39 initial public draft describes discovering, identifying, and labelling data by sensitivity, type, or business function. It demonstrates practices with synthetic data and commercial tools; it does not set classification policy for every industry.[1]
The UK government ties protective controls to the threat and the potential impact of compromise, loss, or incorrect disclosure. Its guidance covers electronic, paper, and verbal information.[2]
Illustrative impact check: exposure of a published brochure has a different consequence from exposure of an employee payroll file. The file format alone does not decide the category.
Labels depend on policy
The UK government uses OFFICIAL, SECRET, and TOP SECRET. These are labels in that government's policy.[2] NIST's draft demonstrates different classification schemas for different organisations.[1]
The table below is an illustrative business scheme. Its names and controls are not universal and do not replace an employer's policy.
| Illustrative label | Example | Possible handling rule |
|---|---|---|
| Public | Approved brochure | Publish through an approved channel after release approval. |
| Internal | Routine staff procedure | Use the staff workspace; check before external sharing. |
| Confidential | Customer contract | Limit access to authorised roles and use approved protected transfer. |
| Restricted | Authentication secrets | Use a designated secrets store; limit access and prohibit ordinary message sharing. |
Controls across the information lifecycle
The U.S. Federal Trade Commission (FTC) recommends inventorying sensitive personal information and its flow, limiting access to the resources each job needs, and retaining information only while needed. Its business guidance also covers locked paper storage, encryption, secure disposal, and incident planning.[3]
This checklist translates those themes into an illustrative handling review. The applicable policy decides the exact controls.
- Identify the record, its owner, its classification, and where copies exist.
- Confirm the recipient's identity and need for access before sending.
- Choose the approved storage and transfer method for the category. Check permissions on shared links.
- Protect paper copies and screens from unintended readers.
- Apply the retention schedule. Use the approved disposal process for paper and devices.
- Report a wrong recipient, lost record, or other suspected exposure through the incident process.
Ownership and uncertain classification
NIST's email demonstration classifies the message using its content and attachments. Labels come from the organisation's schema, and its policy determines how email should be controlled.[1]
Illustrative decision rule: when a label is missing or unclear, ask the information owner or security contact to resolve it before external sharing. Record the decision. A blank label is not a release approval.
In a sample payroll workflow, a summary intended for publication would be prepared separately from the employee-level spreadsheet. The owner would check that the summary excludes private fields before approving release. Changing the spreadsheet's label alone would not perform that check.
A handling check before sending
For the illustrative scheme above, a sender checks the whole package: message, attachment, recipient, and link permissions. A correctly labelled attachment sent to the wrong person still fails the handling rule. An approved document in a publicly accessible folder also fails when the category requires restricted access.
See also
References
- NIST NCCoE, Data Classification Practices, SP 1800-39, February 2026, initial public draft, §§1.3, 2.1, 4.4.1, and 4.4.2.
- UK Cabinet Office, Government Security Classifications Policy Quick Read, summary and baseline security behaviours.
- Federal Trade Commission, Protecting Personal Information: A Guide for Business, inventory, access, retention, storage, disposal, and response sections.