organisational Preventive Protect

A.5.12 Classification of Information

M365 Admin Path: Microsoft Purview compliance portal > Information protection

Evidence Source: Microsoft Purview

What is this control?

ISO 27001 control A.5.12 Classification of Information ensures the organisation identifies and protects information according to its sensitivity, value, and legal or contractual requirements. The control establishes a formal classification scheme defining protection baselines for different data types from General through Highly Confidential. Microsoft Purview Sensitivity Labels provide the technical infrastructure to assign, communicate, and enforce classification metadata across all information assets.

How to implement in Microsoft 365

Implement A.5.12 by defining and publishing the official classification scheme via Microsoft Purview Sensitivity Labels with minimum levels of General, Confidential variants, and Highly Confidential variants. Configure labels with associated protections including encryption, access restrictions, and information rights management. Designate asset owners for each classification level responsible for review and maintenance.

Establish bi-annual classification review schedules for sensitive and confidential data owners. Implement an ownership registry linking business data categories to designated owner roles. Configure DLP policies to detect and enforce handling rules based on classification labels.

What an auditor looks for

Auditors will verify sensitivity label configuration in Microsoft Purview showing all classification levels are defined. They will review the data classification dashboard showing live inventory of data by sensitivity label. Auditors will examine Content Explorer reports demonstrating data assets have sensitivity labels applied.

They will verify the asset ownership register with defined categories, assigned owners, and review schedule. Auditors will check that DLP policies are configured to enforce classification-based handling rules across all M365 workloads.

M365 capabilities that implement this control

Sensitivity Label Taxonomy Info Gov

Define and publish sensitivity label taxonomy with stakeholders

Manual Labeling Info Gov

Deploy manual sensitivity labeling to users

Label-Based Encryption Info Gov

Configure sensitivity labels with encryption protection

Client-Side Auto-Labeling Info Gov

Configure automatic labeling recommendations in Office clients

Service-Side Auto-Labeling Info Gov

Configure automatic labeling policies for SharePoint, OneDrive, Exchange

Trainable Classifiers Info Gov

Machine learning classifiers for content classification

AI Data Governance Info Gov

Sensitivity labels on AI-consumed data, DLP policies for AI-generated content, Copilot governance configuration