A.5.12 Organizational
Classification of information
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-16mostlyaligns with — Both controls establish security attributes on information that drive handling, protection, and access decisions throughout its lifecycle.
- RA-2mostlyaligns with — Both controls require organizations to evaluate the sensitivity and criticality of information to determine appropriate protection levels.
- AC-4partialaligns with — Both controls use classification attributes to enforce information flow restrictions between systems or organizations.
- CA-3partialaligns with — Both controls require agreements that define how classification levels are interpreted and handled when information is shared between organizations.
- MP-3partialaligns with — Both controls require marking of information with classification or sensitivity labels to communicate protection requirements.
- SC-16partialaligns with — Both controls require transmission of security attributes so that receiving systems can apply appropriate protections based on classification.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-05mostlyaligns with — Classification directly feeds asset prioritization by establishing the value, sensitivity, and criticality that determine protection levels and business impact.
- PR.AA-05mostlyaligns with — The classification scheme is explicitly required to align with the access-control policy so that entitlements and handling rules reflect the defined sensitivity levels.
- GV.OC-03partialaligns with — Legal, regulatory, and contractual confidentiality, integrity, and availability obligations are incorporated into the classification criteria and handling rules.
- GV.PO-01partialaligns with — A topic-specific classification policy is established and communicated, forming part of the broader cybersecurity risk-management policy framework.
- ID.AM-07partialaligns with — Classification results are maintained and updated throughout the information life cycle, ensuring metadata reflects current value and sensitivity.
- ID.RA-04partialaligns with — Classification levels are derived from the potential impact of compromise, directly supporting the identification and recording of impact and likelihood values.
Related OWASP ASVS 5.0 requirements (7)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.1.1mostlyaligns with — The ISO requirement to classify information according to confidentiality, integrity and availability needs directly supports the ASVS mandate to identify and classify all sensitive data processed by the application into protection levels.
- V14.1.2mostlyaligns with — Establishing a classification scheme with associated protective controls aligns with the ASVS requirement that each protection level must have documented protection requirements covering encryption, integrity, retention, logging and access controls.
- V13.1.4partialaligns with — The ISO directive that owners are accountable for classification and that the scheme must address business needs for sharing or restricting information aligns with the ASVS requirement to document critical secrets and their rotation schedule.
- V14.2.4partialaligns with — Defining handling rules based on classification levels provides the foundation for the ASVS requirement that controls around sensitive data must address encryption, integrity verification, retention, logging and access control.
Related weaknesses / CWE (33)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200mostlyprevents — By requiring owners to assign sensitivity labels and corresponding handling rules, the control ensures that information is not left unmarked and therefore reduces the chance that sensitive data will be exposed to unauthorized actors.
- CWE-213mostlyprevents — Classification directly addresses mismatched sensitivity views by defining what must be protected.
- CWE-1230partialmitigates — Classification helps identify metadata that may need protection, but does not directly limit its exposure.
- CWE-1323partialprevents — Classification identifies trace data as sensitive, guiding its protection.
- CWE-201partialmitigates — Classification identifies sensitive data so it is not inadvertently transmitted.
- CWE-202partialmitigates — Classification helps identify sensitive data that must be protected from inference attacks.
- CWE-212partialprevents — Classification identifies sensitive data that must be removed before storage or transfer.
- CWE-219partialmitigates — Classification identifies sensitive data so it can be placed outside the web root.
- CWE-284partialmitigates — The classification scheme is explicitly aligned with the access-control policy, so protective controls are applied consistently and the risk of improper access decisions is lowered.
- CWE-313partialprevents — Classification identifies sensitive data that must not be stored in cleartext.
- CWE-315partialprevents — Requires classification of sensitive information, indirectly driving protection measures for cookies.
- CWE-526partialmitigates — Classification drives decisions on what must be protected, indirectly discouraging cleartext storage of sensitive data.
- CWE-528partialmitigates — Classification helps identify core dumps as sensitive, but does not enforce storage or access restrictions.
- CWE-530partialmitigates — Classification helps identify which backups need stricter handling, but does not enforce storage location or access restrictions.
- CWE-540partialprevents — Classification helps identify source code containing sensitive data so it can be protected.
- CWE-552partialmitigates — Labeling information according to its sensitivity and specifying corresponding protection measures makes it less probable that files or directories containing sensitive content will be left accessible to external parties.
- CWE-612partialprevents — Classification helps identify what must be protected but does not enforce index access limits.
- CWE-732partialprevents — Classification results drive the assignment of permissions and handling procedures, decreasing the likelihood that critical resources receive incorrect or overly permissive permission settings.
- CWE-921partialmitigates — Classification identifies sensitive data that must not be stored without access controls.
- CWE-1301nonenone — Classification helps identify sensitive data that must be removed but does not address removal completeness.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — A consistent, organization-wide classification scheme reduces the chance that systems or data stores will be deployed with overly permissive or mismatched security settings because protection requirements are explicitly tied to each classification level.
- A04partialmitigates — When classification explicitly considers confidentiality and integrity needs, organizations are more likely to select and apply cryptographic controls commensurate with the sensitivity of the information, lowering the risk of weak or absent encryption.
- A01nonemitigates — By requiring owners to label information according to its sensitivity and by aligning those labels to access-control rules, the control ensures that data is only disclosed or modified by authorized parties, thereby limiting unauthorized access.
- A06noneprevents — Embedding classification into the design process forces architects and developers to consider the impact of compromise at the outset, leading to security requirements that are baked into the application rather than added later.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.