Seed-stage B2B SaaS startup
Sample for a fictional organisation · 2,367 words[Company] Information Classification Policy
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
3. Classification Levels
[Company] gives all the information it holds one of four levels, from most to least sensitive: Restricted, Confidential, Internal and Public. A level reflects the harm that could follow if the information reached someone who should not have it.
- Restricted: information whose release could cause serious harm to [Company], to its customers or to the people the information is about.
- Confidential: information whose release could harm [Company], its customers or the people the information is about, and that only the staff who need it for their work may see.
- Internal: information that is for use inside [Company] and has not been made public, and whose release would cause little or no harm.
- Public: information that [Company] has published or approved for release to anyone. Public information must still be accurate, so only its information owner changes it.
Where another [Company] policy speaks of confidential information without naming a level, it means information at the Confidential or Restricted level.
4. Classifying Information
The table below gives the level of the kinds of information staff most often handle. Where [Company] holds information of a kind in the table, that information has the level the table gives.
| Kind of information | Level |
|---|---|
| Passwords, encryption keys, access tokens and other secrets that give access to systems | Restricted |
| Payroll, tax and benefits records of staff | Restricted |
| Customer data that no row above covers | Confidential |
| Personal data about people outside [Company] that no other row covers | Confidential |
| Personnel and recruitment records | Confidential |
| Contracts and agreements, and the terms agreed in them | Confidential |
| Accounting and tax records, forecasts and other financial information that [Company] has not published | Confidential |
| Audit and assessment evidence and security incident records | Confidential |
| Source code and system designs | Confidential |
| Policies, procedures and risk assessments | Internal |
| Security, access and system logs | Internal |
| Names and work contact details of staff | Internal |
| Working documents, guides, meeting notes and announcements for staff that no row above covers | Internal |
| Information [Company] has published or approved for release | Public |
- The information owner gives a level to each kind of information the table does not list, using the definitions in section 3. An information owner may give information a higher level than the table gives, and never a lower one except by approving its release as Public under section 7.
- Information that fits more than one row takes the highest level that applies, except that information [Company] has published with the approval of its information owner is Public.
- A system, a folder or a set of records that holds information at more than one level meets the rules in section 6 on where information is kept and on encryption for the highest of those levels. Access to each item in it follows the level of that item.
- Where items together reveal more than each does alone, the information owner may give the collection a higher level than any item in it.
- Where staff are unsure which of two levels applies, they use the higher one until the information owner decides.
- The CTO keeps a list of the kinds of information [Company] holds, which records for each kind its information owner, its level and the systems approved to hold it.
6. Handling Information
The table below sets the rules for handling information at each level. A rule applies to information at that level wherever it is held and whatever form it takes, except that the rows on where it is kept and on encryption do not apply to paper copies, which the last row covers.
| Rule | Restricted | Confidential | Internal | Public |
|---|---|---|---|---|
| Label on a document, a file or a record | On the item itself | On the item or the place that holds it | On the item or the place that holds it | None |
| Access by staff | Only staff whose access the information owner has approved | Only staff who need it for their work | All staff, unless the information owner limits it | All staff |
| Where it is kept | Only in systems the information owner has approved for Restricted information | Only in systems [Company] has approved | Only in systems [Company] has approved | In any system [Company] has approved, and anywhere it has been published |
| Encryption | Required where it is kept and when it is sent | Required where it is kept and when it is sent | Required when it is sent outside [Company] | Not required |
| Sharing outside [Company] | Only with the information owner's approval and under a written agreement that protects it | Only where the work needs it and under a written agreement that protects it | Only where the work needs it | Allowed |
| AI tools | Only a tool [Company] has approved for Restricted information, and only with the information owner's approval | Only a tool [Company] has approved for Confidential information | Any tool [Company] has approved | Any tool [Company] has approved |
| Personal devices and removable media | Only on devices and media [Company] has approved, and only with the information owner's approval | Only on devices and media [Company] has approved | Only on devices and media [Company] has approved | Allowed |
| Paper copies | Only with the information owner's approval, locked away when not in use and shredded when no longer needed | Only where the work needs it, kept out of sight when not in use and shredded when no longer needed | Kept out of sight of visitors | Allowed |
Where a contract, or a marking given by whoever supplied the information, sets a stricter rule than the table, the stricter rule applies to that information. Where what is said aloud is Confidential or Restricted, staff make sure that only people allowed to have it can hear it.
The information owner may give an approval that the table requires for a kind of use or for a group of staff, and keeps a record of each approval it gives. Passwords, encryption keys, access tokens and other secrets that give access to systems are never entered into an AI tool.
Nothing in this policy stops [Company] giving information to the person it is about or to an authority where the law requires it. Nothing in it stops staff discussing their own pay and working conditions, or reporting a concern to an authority as the law allows.
Read the full example
[Company] Information Classification Policy
- Version: 1.0
- Owner: CTO
- Approved by: CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This policy sets how [Company] classifies its information: the four levels it uses, how a level is chosen, how information is labeled and how information at each level is handled. It sits beneath [Company]'s information security policy, and where another [Company] policy covers the same subject, both apply and the stricter rule applies.
This policy covers all information that [Company] holds or that is held for it, in any form: data in systems, documents, messages, paper and what is said aloud. It covers information that belongs to [Company] and information that its customers, its suppliers and others entrust to it.
This policy applies to everyone who is given access to [Company]'s systems, accounts or information: employees, contractors and anyone else working on its behalf. This policy calls them staff.
- Information owner: the role accountable for a kind of information, as section 2 describes. Another [Company] policy may call this role the data owner.
- Label: the name of a level, written on information or on the place that holds it, as section 5 describes.
- Unlabeled: carrying no label and held in no place that carries one, as section 5 describes.
2. Roles and Responsibilities
- The CTO: keeps this policy and reviews it under section 10; keeps the list that section 4 describes; names an information owner for any kind of information that has none; decides the level where information owners disagree; makes sure staff are shown this policy under section 9; and approves exceptions under section 10.
- The CEO: approves this policy and each change to it.
- Information owners: each kind of information has one information owner, which is the role accountable for the work or the system the information belongs to. The information owner gives the information its level under section 4, gives the approvals that the table in section 6 requires, reviews the level under section 7 and approves any release of the information as Public.
- All staff: handle information as the table in section 6 requires for its level, label what they create or receive from outside [Company] under section 5, and report under section 9.
3. Classification Levels
[Company] gives all the information it holds one of four levels, from most to least sensitive: Restricted, Confidential, Internal and Public. A level reflects the harm that could follow if the information reached someone who should not have it.
- Restricted: information whose release could cause serious harm to [Company], to its customers or to the people the information is about.
- Confidential: information whose release could harm [Company], its customers or the people the information is about, and that only the staff who need it for their work may see.
- Internal: information that is for use inside [Company] and has not been made public, and whose release would cause little or no harm.
- Public: information that [Company] has published or approved for release to anyone. Public information must still be accurate, so only its information owner changes it.
Where another [Company] policy speaks of confidential information without naming a level, it means information at the Confidential or Restricted level.
4. Classifying Information
The table below gives the level of the kinds of information staff most often handle. Where [Company] holds information of a kind in the table, that information has the level the table gives.
| Kind of information | Level |
|---|---|
| Passwords, encryption keys, access tokens and other secrets that give access to systems | Restricted |
| Payroll, tax and benefits records of staff | Restricted |
| Customer data that no row above covers | Confidential |
| Personal data about people outside [Company] that no other row covers | Confidential |
| Personnel and recruitment records | Confidential |
| Contracts and agreements, and the terms agreed in them | Confidential |
| Accounting and tax records, forecasts and other financial information that [Company] has not published | Confidential |
| Audit and assessment evidence and security incident records | Confidential |
| Source code and system designs | Confidential |
| Policies, procedures and risk assessments | Internal |
| Security, access and system logs | Internal |
| Names and work contact details of staff | Internal |
| Working documents, guides, meeting notes and announcements for staff that no row above covers | Internal |
| Information [Company] has published or approved for release | Public |
- The information owner gives a level to each kind of information the table does not list, using the definitions in section 3. An information owner may give information a higher level than the table gives, and never a lower one except by approving its release as Public under section 7.
- Information that fits more than one row takes the highest level that applies, except that information [Company] has published with the approval of its information owner is Public.
- A system, a folder or a set of records that holds information at more than one level meets the rules in section 6 on where information is kept and on encryption for the highest of those levels. Access to each item in it follows the level of that item.
- Where items together reveal more than each does alone, the information owner may give the collection a higher level than any item in it.
- Where staff are unsure which of two levels applies, they use the higher one until the information owner decides.
- The CTO keeps a list of the kinds of information [Company] holds, which records for each kind its information owner, its level and the systems approved to hold it.
5. Labels
- A label is the name of the level, written where a reader sees it before the content: in the header or first line of a document, in the name of a file or a folder, or in the subject line of a message.
- A document, a file or a record at the Restricted level carries the label on the item itself.
- A document, a file or a record at the Confidential or Internal level carries the label on the item itself or on the folder, workspace or system that holds it.
- Public information needs no label.
- A message or a conversation takes the level of the information in it. A message that carries Restricted information has the label in its subject line or first line, and other messages need no label.
- A document, a file or a record that carries no label, and is held in no place that carries one, is unlabeled. Staff handle unlabeled information of a kind the table in section 4 lists at the level the table gives, and treat any other unlabeled information as Confidential until its information owner gives it a level.
- The person who creates information, or who receives it from outside [Company], labels it or puts it in a place that carries the right label.
- Staff never remove a label or replace it with another. Only the information owner changes a label, under section 7.
- Where a tool that [Company] uses can apply a label to a file or a message, the label uses the same four names.
6. Handling Information
The table below sets the rules for handling information at each level. A rule applies to information at that level wherever it is held and whatever form it takes, except that the rows on where it is kept and on encryption do not apply to paper copies, which the last row covers.
| Rule | Restricted | Confidential | Internal | Public |
|---|---|---|---|---|
| Label on a document, a file or a record | On the item itself | On the item or the place that holds it | On the item or the place that holds it | None |
| Access by staff | Only staff whose access the information owner has approved | Only staff who need it for their work | All staff, unless the information owner limits it | All staff |
| Where it is kept | Only in systems the information owner has approved for Restricted information | Only in systems [Company] has approved | Only in systems [Company] has approved | In any system [Company] has approved, and anywhere it has been published |
| Encryption | Required where it is kept and when it is sent | Required where it is kept and when it is sent | Required when it is sent outside [Company] | Not required |
| Sharing outside [Company] | Only with the information owner's approval and under a written agreement that protects it | Only where the work needs it and under a written agreement that protects it | Only where the work needs it | Allowed |
| AI tools | Only a tool [Company] has approved for Restricted information, and only with the information owner's approval | Only a tool [Company] has approved for Confidential information | Any tool [Company] has approved | Any tool [Company] has approved |
| Personal devices and removable media | Only on devices and media [Company] has approved, and only with the information owner's approval | Only on devices and media [Company] has approved | Only on devices and media [Company] has approved | Allowed |
| Paper copies | Only with the information owner's approval, locked away when not in use and shredded when no longer needed | Only where the work needs it, kept out of sight when not in use and shredded when no longer needed | Kept out of sight of visitors | Allowed |
Where a contract, or a marking given by whoever supplied the information, sets a stricter rule than the table, the stricter rule applies to that information. Where what is said aloud is Confidential or Restricted, staff make sure that only people allowed to have it can hear it.
The information owner may give an approval that the table requires for a kind of use or for a group of staff, and keeps a record of each approval it gives. Passwords, encryption keys, access tokens and other secrets that give access to systems are never entered into an AI tool.
Nothing in this policy stops [Company] giving information to the person it is about or to an authority where the law requires it. Nothing in it stops staff discussing their own pay and working conditions, or reporting a concern to an authority as the law allows.
7. Changing a Level
- Only the information owner lowers a level. A level is never lowered below the one the table in section 4 gives the kind of information, except when the information owner approves its release as Public.
- Releasing Restricted information as Public also needs the approval of the CTO.
- Staff who believe information has too low a level handle it at the higher level and tell its information owner, who decides within 10 working days.
- Each information owner reviews the levels of the information it is accountable for at least every 12 months, and when a law, a contract or the use of the information changes, and confirms its entries in the list that section 4 describes to the CTO.
- When a level changes, the information owner makes sure the label, the place the information is held and who can see it match the new level within 10 working days.
8. Information Received and Shared
- Staff who receive information from outside [Company] handle it at the level the table in section 4 gives its kind. Where the table does not list its kind, they treat it as Confidential until its information owner gives it a level, as section 5 requires for unlabeled information.
- Where the sender has marked the information, staff keep the sender's marking and label the information as section 5 requires.
- The way a sender classifies its own information never lowers the level this policy gives it.
- Before sharing Confidential or Restricted information outside [Company], the person sharing it tells the recipient its level and the rules the recipient must follow.
9. Training and Reporting
- The CTO makes sure staff are shown this policy, the four levels and the table in section 6 when they start work and at least every 12 months after that.
- Staff report to the CTO, as soon as they become aware of it, information that has been lost, sent to the wrong person or held where its level does not allow.
- Where Confidential or Restricted information may have reached someone who should not have it, staff also report it at once through [Company]'s incident reporting process.
10. Exceptions, Breaches and Review
An exception to this policy is approved in writing by the CTO, with the reason and any conditions recorded, and lasts no longer than 12 months. An exception for Restricted information also needs the approval of its information owner.
A breach of this policy may lead to disciplinary action up to dismissal, in line with [Company]'s disciplinary process and the employment law of the country where the person works; for contractors and other non-employees it may lead to the engagement ending. Nobody is penalized for making a report in good faith under section 9.
The CTO reviews this policy at least every 12 months and after any significant change to [Company]'s work, systems or obligations, and each change is approved by the CEO.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.