Information Classification Policy
Introduction
In order to preserve the appropriate confidentiality, integrity and availability of information assets, Arktek must make sure they are protected against unauthorised access, disclosure or modification. This is not just critical for assets covered by the Data Protection Act, and the primary and secondary data used for all business conducted across the Organisation by Arktek. Different types of information require different security measures depending upon their sensitivity.
Arktek’s information classification standards are designed to provide information owners with guidance on how to classify information assets properly and then use them accordingly.
This guidance - developed in accordance with the Security and Data Protection Policies - includes classification criteria and categories, as well as rules for the delegation of classification tasks.
This policy does not form part of any employee’s contract of employment and we may amend it at any time.
Responsibilities
Members of Staff or Contractors:
They are responsible for assessing and classifying the information they work with, and applying the appropriate controls. They must respect the security classification of any information as defined, and must report the inappropriate situation of information to the ISMS Manager as quickly as possible.
Information Owners:
Information Owners are responsible for assessing information and classifying its sensitivity. They should then apply the appropriate controls to protect that information. Information ownership can be delegated: see the Security Policy.
Data Processors:
Responsible for providing the mechanisms or instructions for protecting electronic information while it is resident on any Arktek owned or controlled system.
ISMS Manager:
Responsible for providing the instructions for the protection and preservation of records, physical or electronic. Responsible for advising and recommending information security standards on data classification.
Objectives
To fully comply with current regulations and legislation relating to protection of information and data.
Policy and Procedures
Information Classification Definitions
The following table provides a summary of the information classification levels that have been adopted by Arktek. These classification levels explicitly incorporate the Data Protection Act’s (DPA) definitions of Personal Data and Sensitive Personal Data, as laid out in the Data Protection Policy.
Confidential
‘Confidential’ information has significant value for Arktek, and unauthorised disclosure or dissemination could result in severe financial or reputational damage to Arktek, including fines from the Information Commissioner’s Office. Data that is defined by the Data Protection Act as Sensitive Personal Data falls into this category. Only those who explicitly need access must be granted it, and only to the least degree in order to do their work (the ‘need to know’ and ‘least privilege’ principles). When held outside Arktek, on mobile devices such as laptops, tablets or phones, or in transit, all documents of any type of classification are never stored on the local drive and access to such information can only be secured through: (i) accessing the desktop which is protected behind a secure logon process, and (ii) thereafter accessing the drives, which are encrypted for the stored information.
Restricted
‘Restricted’ information is subject to controls on access, such as only allowing valid logons from a small group of staff. ‘Restricted’ information must be held in such a manner that prevents unauthorised access i.e. on a system that requires a valid and appropriate user to log in before access is granted. Information defined as Personal Data by the Data Protection Act falls into this category. Disclosure or dissemination of this information is not intended, and may incur some negative publicity, but is unlikely to cause severe financial or reputational damage to Arktek. Note that large datasets of ‘Restricted’ information may become classified as Confidential, thereby requiring a higher level of access control.
Internal Use
‘Internal use’ information can be disclosed or disseminated by its owner to appropriate members of Arktek, consultants and contractors, as appropriate by information owners without any restrictions on content or time of publication.
Public
‘Public’ information can be disclosed or disseminated without any restrictions on content, audience or time of publication. Disclosure or dissemination of the information must not violate any applicable laws or regulations, such as privacy rules. Modification must be restricted to individuals who have been explicitly approved by information owners to modify that information, and who have successfully authenticated themselves to the appropriate computer system.
Designating information as ‘Confidential’ involves significant costs in terms of implementation, hardware and ongoing resources, and makes data less mobile. For this reason, information owners making classification decisions must balance the risk of damage that could result from unauthorised access to, or disclosure of, the information against the cost of additional hardware, software or services required to protect it.
- Examples of Security Level Definitions
- Confidential - Normally accessible only to specified and / or relevant members of staff
- DPA-defined Sensitive personal data: racial/ethnic origin political opinion religious beliefs trade union membership physical/mental health condition sexual life criminal record including when used as part of primary or secondary research data
- salary information
- individuals’ bank details
- draft research reports of controversial and / or financially significant subjects
- passwords
- large aggregates of DPA defined Personal Data including elements such as name, address, telephone number
- HR system data
- Arktek central and/or client data
- Interview transcripts, client databases or other research records involving individually identifiable sensitive subject to significant scrutiny in relation to appropriate exemptions/ public interest and legal considerations.
- Restricted - Normally accessible only to specified/relevant members of Arktek staff
- DPA-defined Personal Data (information that identifies living individuals) including:
home / work address age telephone number schools attended photographs including where used as part of primary or secondary research, contained in research databases, transcripts or other records
draft reports, papers and minutes systems
Subject to significant scrutiny in relation to appropriate exemptions/ public interest and legal considerations.
- Internal Use - Normally accessible only to members of staff, consultants and contractors
- Internal correspondence
- information held under license
- company policy and procedures
Subject to scrutiny in relation to appropriate exemptions/ public interest and legal considerations.
- Public - Accessible to all members of the public
- Annual accounts
- information available on the Arktek website or through Arktek publications.
Granularity of classification
The sets of information being classified should, in general, be large rather than small. Smaller units require more administrative effort, involve more decisions and add to complexity, thus decreasing the overall security.
Information Retention
There may be minimum or maximum timescales for which information must be kept. These may be mandated in a research or commercial contract. Other forms of information retention may be covered by environmental or financial regulations.
Position: Managing Director
This policy was last reviewed by Arktek Group Limited on 10 February 2024.