Data classification is one of the most underrated parts of an ISMS. The 2022 version of ISO 27001 explicitly requires classification (control 5.12) and labelling of information (control 5.13), and the GDPR demands security appropriate to the sensitivity of the data. Yet in many SMEs it stops at a neat four-tier scheme in a policy document that no one uses in practice. And that is exactly what an auditor sees through: where do those labels show up in daily work?
Why classification is the foundation
Classification is not a goal in itself but the engine underneath your other controls. Without knowing which information is sensitive, you cannot target access control, encryption, retention or supplier agreements. You would have to protect everything equally heavily — unaffordable — or everything equally lightly — irresponsible. Classification lets you differentiate: strict measures where needed, light where possible. That makes your ISMS both safer and more workable.
A workable scheme for SMEs
Keep it simple. Four levels are enough for almost any SME; more levels only cause doubt and mislabelling.
- Public — can go out with no risk (press releases, job ads, marketing).
- Internal — not meant for outside, but no harm if leaked (internal memos, general process notes).
- Confidential — harm if leaked (customer data, contracts, quotes, HR files).
- Strictly confidential — serious harm (special categories of personal data, source code, access keys, M&A files).
For each level, briefly define what it means, who may have access and which measures apply (for example: strictly confidential always encrypted, never on personal devices, shared only through the secured environment). That turns a label into an instruction rather than a sticker.
Start with your most important data
Do not try to classify everything at once — that is guaranteed to stall. Start with the five data flows that really matter: customer data, HR and payroll, financial records, contracts and (for tech companies) source code and customer environments. For each flow, determine where it lives, who can access it and which level fits. This exercise immediately feeds your risk assessment and your Statement of Applicability.
From policy to daily use
This is where it stands or falls. A classification policy that only exists in Word is worthless to an auditor. Make labelling part of the tools people already use:
- Microsoft 365 sensitivity labels (or a comparable solution) that let users label a document or email in one click — and to which you automatically attach measures such as encryption or a block on external sharing.
- Automatic classification for patterns you can reliably detect (national IDs, IBANs, credit-card numbers), so sensitive documents get a label even without manual action.
- A SaaS matrix: record which application may hold which level of data. Customer data in an approved CRM: fine. Strictly confidential data in a free note-taking app: not. Include that matrix in your SoA.
Behaviour and training
Labels only work if people know how and why to apply them. That does not need to be a full-day course: a ten-minute onboarding (“here is how you label a document, this is what the levels mean”) plus a short annual refresher usually suffices. More important than the theory is that management sets the example and that mislabelling can be discussed without a blame culture — otherwise everyone labels everything “confidential” out of uncertainty and the scheme loses its value.
What the auditor wants to see
Not your policy document, but evidence that classification is alive: labelled documents and emails in practice, the configuration of your labels and the attached measures (screenshots or exports), the SaaS matrix, and a record of incidents and DLP alerts around misclassified data. A certification body accepts no intention without a sample — so show that you periodically check whether labels are correct and adjust where needed.
Common mistakes
- Too many levels — causes doubt and inconsistent labels. Stick to four.
- Policy without tooling — if labelling is not in the daily tools, it does not happen.
- Everything “confidential” — over-classification makes your measures unworkable and expensive; the scheme loses meaning.
- Set once and forget — data flows change; without review your classification ages.
The review cycle
Schedule a short quarterly evaluation: how many misclassification incidents were there, which DLP alerts came in, and does the scheme still cover your most important data? Discuss the trend in your management review. That shows the board and the auditor that classification is a living part of your ISMS — precisely the PDCA cycle ISO 27001 expects.
Getting started
Start small: define four levels, classify your top five data flows and turn on labelling in your email and document environment. For most SME audits that is already a solid, demonstrable base. Want to know where your organisation stands? Review the ISO 27001 route or take the free readiness scan.
