I used to think of info classification as a useless over-simplification. Information has unique properties which couldn't be reflected by association to predefined classes.
Sure enough - having info represented by classes is a simplification. But these days I see merit in the practice.
Classification fosters dialogue about the sensitivity of info. A process owner might not know his security requirements but I can get him started by asking: where is integrity more important - for info type x or type y?
(some of) my events
- 2018-10-03--05 Operativ informationssäkerhet (teaching course, Stockholm)
- 2018-09-05--07 Strategisk informationssäkerhet (teaching course, Stockholm)
- 2018-05-23--25 Teknisk informationssäkerhet (teaching course, Stockholm)
- 2018-05-17 Three Capabilities in a Crisis (guest lecturing at Mid Sweden University, Östersund)
- 2018-05-16 Info.säkerhet är inte "någon annans problem" (lunch seminar at Mid Sweden University, Östersund)