Posts

Showing posts with the label classification

ISO 27001 Annex : A.8.2 Information Classification

Image
ISO 27001 Annex : A.8.2 Information Classification  Its objective is  To ensure that the information is properly secured, in accordance with its significance to the organization. A.8.2.1 Classification of Information Control-  Information should be classification the basis of their legal provisions, criticality, and  vulnerability  to unwanted release or alteration Implementation Guidance-  Classifications and associated  information security  measures will also include regulatory standards, which take into account market demands for information sharing or restriction. Assets other than information may also be classified according to the information classification stored, processed, otherwise handled or protected by the asset. Information asset owners would be responsible for their classification. The classification system will include classification standards, as well as classification analysis guidelines over time. The level of sec...