Skip to main content

Pro audit program · v1.0

Data Classification Snapshot

Do you actually classify data — and is the classification reflected in access control, encryption and retention? Quick snapshot.

  • General target area
  • ISO 27001 framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Do you actually classify data — and is the classification reflected in access control, encryption and retention? Quick snapshot.

Risks addressed

  • High Confidential data treated like public data u2014 over-shared
  • Medium No owners u2014 nobody decides who can access what
  • High Restricted data exfiltrated without detection
  • Medium Data kept indefinitely, increasing breach blast radius

Controls (6)

  1. Classification scheme published

    High

    This control requires the organization to develop, approve, and publish a formal data classification scheme that defines categories of information based on sensitivity, criticality, and regulatory requirements. The scheme must specify classification levels (e.g., Public, Internal, Confidential, Restricted), criteria for…

    How to test + evidence

    Testing procedure: A simple, agreed scheme (e.g. Public / Internal / Confidential / Restricted) is documented.

    Evidence to collect: Classification policy.

  2. Owners assigned per data type

    High

    This control requires formal assignment of accountable data owners for each defined data classification type or category within the organization's inventory. Data owners are responsible for determining access rights, classification levels, retention policies, and acceptable use for their assigned data…

    How to test + evidence

    Testing procedure: Each data type has a named information owner.

    Evidence to collect: Data owner register.

  3. Labels applied to documents at source

    Medium

    This control ensures that classification labels (e.g., Public, Internal, Confidential, Restricted) are assigned to documents, records, and data assets at the point of creation or initial receipt into the organization's custody. Labeling at source prevents ambiguity, ensures consistent handling from…

    How to test + evidence

    Testing procedure: Office / Google docs apply labels; spot-check sample of recent docs.

    Evidence to collect: Labelling tool config + samples.

  4. Access controls reflect classification

    High

    This control ensures that access permissions, authentication requirements, and authorization levels are directly tied to the sensitivity classification of data and systems (e.g., public, internal, confidential, restricted). Organizations establish access control matrices or role-based access control (RBAC) schemes that enforce…

    How to test + evidence

    Testing procedure: Confidential / Restricted data is access-restricted, encrypted, and audited.

    Evidence to collect: ACL extracts + encryption posture.

  5. Retention rules per classification

    Medium

    This control requires organizations to define and enforce data retention periods that are explicitly mapped to data classification levels (e.g., public, internal, confidential, restricted). Each classification tier receives specific retention durations and destruction schedules based on regulatory, legal, business, and…

    How to test + evidence

    Testing procedure: Retention policy maps classification to retention period.

    Evidence to collect: Retention policy.

  6. DLP / outbound monitoring on Restricted data

    High

    Data Loss Prevention (DLP) systems monitor and control the movement of sensitive data classified as Restricted across network boundaries, endpoints, and cloud services. The control uses content inspection, pattern matching, and policy enforcement to detect and block unauthorized transmission of…

    How to test + evidence

    Testing procedure: DLP rules detect/block exfil of Restricted-labelled data through email / cloud / removable media.

    Evidence to collect: DLP policy export.