Skip to content

Classification Tier

Definition

A label assigned to an asset or data type indicating its sensitivity and the handling rules that apply. Common tiers are Public, Internal, Confidential, and Restricted (or Highly Confidential). Each tier maps to specific controls: encryption requirements, access restrictions, disposal procedures, and transmission rules.

Typical tiers
Public, Internal, Confidential, Restricted
Maps to
Encryption, access, disposal and transmission rules
Assigned to
Assets and data types
Purpose
Match handling controls to sensitivity

Common questions

Who typically assigns the classification tier to a given dataset?+

A designated data owner or custodian assigns the tier based on the data's sensitivity and regulatory exposure, and the assignment is periodically reviewed since a dataset's sensitivity can change as it is combined with other data or as regulations evolve.

Why does disposal procedure differ by tier?+

Higher tiers such as Restricted typically require verified destruction methods like cryptographic erasure or physical shredding with a certificate, while Public tier data can be discarded with standard deletion since its exposure carries little consequence.

What happens when data of mixed tiers is stored together?+

Standard practice is to classify the combined dataset at the level of its most sensitive component, since storing Restricted data alongside Public data in one location without applying the stricter controls would undermine the protection the tier system is meant to provide.

Related terms

Asset Inventory (Asset Register)
A structured record listing every information asset in scope, together with its owner, custodian, physical or logical location, classification level, criticality rating,...
Asset Owner
The person or role accountable for ensuring an asset is appropriately classified, protected, and reviewed. The owner is typically a business manager...
Information Asset
Anything that has value to the organisation by virtue of the information it contains or the information function it performs. Includes data,...
Threat
A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human...
Vulnerability
A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.