Skip to content
arrow_back
search
ISM-0393 policy ASD Information Security Manual (ISM)

Classify Databases Based on Data Sensitivity

Databases should be classified according to how sensitive the data they contain is.

record_voice_over

Plain language

This control is about sorting your databases based on how sensitive the information they hold is. It's important because if sensitive data is kept in databases that aren't properly guarded, it could lead to leaks of confidential information, causing harm to privacy, and even resulting in financial losses or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Databases and their contents are classified based on the sensitivity or classification of data that they contain.
policy ASD Information Security Manual (ISM) ISM-0393
priority_high

Why it matters

If databases are misclassified, controls may be misapplied, enabling unauthorised access and disclosure of higher-sensitivity records.

settings

Operational notes

Maintain a documented database classification register and reclassify when schemas, data sources or sensitivity change; verify labels match the highest data classification stored.

Mapping detail

Mapping

Direction

Controls