Skip to main content

CIA Classification

Rating information on confidentiality, integrity and availability to decide how strongly it must be protected.

CIA classification rates information, or the system that holds it, on three properties: confidentiality (who may see it), integrity (how much it matters that it is correct and complete) and availability (how long you can do without it). In Dutch the same method is called BIV-classificatie, after beschikbaarheid, integriteit and vertrouwelijkheid.

CIA rating levels

Each property gets its own rating, usually on three levels such as low, medium and high, or 1 to 3. The result is a profile rather than a single score: a public price list is low on confidentiality but high on integrity, while a payroll file is high on confidentiality and medium on availability. A classification policy defines what each level means, for example that high availability means a process may be down for no more than a few hours, so that two people rating the same asset reach the same answer.

What the rating drives

The rating decides which controls an asset needs. High confidentiality leads to encryption and strict access control, high integrity to change control and logging, high availability to redundancy and tested backups. In ISO 27001 this sits in the asset inventory and the risk assessment, and control 5.12 of ISO 27002, classification of information, asks for classification based on confidentiality, integrity, availability and the requirements of relevant interested parties.

Frequently asked questions

What is CIA classification?
CIA classification is the practice of rating information by its required Confidentiality, Integrity and Availability, to decide how strongly it must be protected. In Dutch it is known as BIV-classificatie.
Why classify information by CIA?
It ensures security controls are proportionate, so the most sensitive or critical information gets the strongest protection.
What do the letters in CIA and BIV stand for?
Confidentiality, Integrity and Availability (in Dutch: Beschikbaarheid, Integriteit, Vertrouwelijkheid).
What are the CIA rating levels?
Most organisations rate each of confidentiality, integrity and availability on three levels, such as low, medium and high. Each asset gets a rating per property, and the classification policy defines what each level means.