Information classification policy - Annex 1
Published: 31 August 2026Freedom of information class: How we manage our resources
Annex 1 provides further guidance for RoS' information classification policy
Table of contents
Information handling guidance
This guidance applies to single artefacts such as documents, or to collections of information and will assist colleagues to correctly classify information and to appropriately protect it based on its classification.
Understanding the classification of the information you are working with, and the implications of this, are essential to designing processes and systems that adequately meet the security requirements for that information. Controls in place for information should be appropriate to its classification.
Classification
RoS uses the UK Government Classification Policy. This means that all RoS information is classified as OFFICIAL.
The OFFICIAL classification covers a huge volume of information at many different levels of sensitivity, ranging from information that is already in the public domain to information that may be of interest to highly capable threat actors, and whose compromise could cause harm (albeit not significant or long-term harm) to the UK, its people or its interests.
Access
Those creating information are responsible for determining who needs to access it. Access to OFFICIAL information should always be no wider than is deemed necessary for business needs and be risk-based.
The need-to-know must be balanced with the need-to-share - information is only valuable if it is used by those who need it. The balance between these two principles must be considered carefully.
Protective marking
Protective marking of OFFICIAL information is not mandatory – see the section on Working with OFFICIAL and OFFICIAL SENSITIVE information for guidance on scenarios where protective marking should be considered.
Within the OFFICIAL classification, information or material whose compromise is likely to cause damage to the work or reputation of RoS and/or government will be classed as OFFICIAL – SENSITIVE and should be marked with the “- SENSITIVE” marking.
It is important to note that the classification of information does not affect our statutory obligations under data protection or freedom of information legislation. In cases where sensitive information is requested, there are exemptions within that legislation to protect the information.
When creating information artefacts, the potential classification of these should be taken into consideration. Specifically, inclusion of sensitive information should only be considered where this is necessary due to the inherent risk and cost associated with protecting and managing information of higher classifications.
For assistance with this guidance or for further information on information security, contact the Information Governance team.
Classification descriptions
Classification should be based on value or sensitivity of the information. This is reflected in the level of risk to RoS resulting from inappropriate sharing or exposure of the information in question.
OFFICIAL (unmarked internally) | OFFICIAL – SENSITIVE (consider marking) |
|---|---|
Information whose compromise would typically cause limited to no negative consequences for RoS, UK or Scottish Government, our partners or to an individual. This includes information that has been cleared for publication. It also includes routine operational, policy and service information that is not intended for public release, but that is unlikely to be of interest to threat actors. Aggregated data sets of OFFICIAL information may warrant additional controls. | Information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media due to its sensitivity or topical significance. A compromise could cause moderate, short-term damage to: HMG, the UK’s international reputation, the UK economy, HMG’s relations with its partners (including international partners) or moderate harm or distress to an individual or group of people. The implications of a compromise could be potentially significant but are not long standing and are unlikely to cause serious harm to HMG or the UK. |
Where a document or dataset contains data of differing classifications, the highest classification should be applied.
The classification of information can change over time, for example information that is commercially sensitive during contract negotiations may become less sensitive once the negotiations are complete.
Working with OFFICIAL and OFFICIAL - SENSITIVE information
OFFICIAL | OFFICIAL – SENSITIVE |
|---|---|
Verbal information | |
Information whose compromise would typically cause limited to no negative consequences for RoS, UK or Scottish Government, our partners or to an individual. This includes information that has been cleared for publication. It also includes routine operational, policy and service information that is not intended for public release, but that is unlikely to be of interest to threat actors. Aggregated data sets of OFFICIAL information may warrant additional controls. | Information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media due to its sensitivity or topical significance. A compromise could cause moderate, short-term damage to: HMG, the UK’s international reputation, the UK economy, HMG’s relations with its partners (including international partners) or moderate harm or distress to an individual or group of people. The implications of a compromise could be potentially significant but are not long standing and are unlikely to cause serious harm to HMG or the UK. |
Hard copy information | |
Storage and access
In the office:
Working remotely (including from home):
In public:
| Only print on corporate systems or devices that have been approved by your organisation and keep the number of copies strictly to what is required. In the office:
Working remotely (including from home):
In public:
|
TransportationMoving physical assets by hand:
Moving physical assets by courier/post:
| Moving physical assets by hand:
Moving physical assets by courier/post:
|
DestructionDo not dispose of information of any classification at home or in public bins. It should be retained securely at home before being taken into the office and placed in a confidential waste bin or bag. | |
Digital information | |
Storage
|
|
AccessIn the office: can be accessed in parts of the building which are accessible to the public. In public and when working remotely: can be accessed but be aware of whether you can be overlooked by unauthorised individuals, such as members of the public. | In the office: Avoid accessing in high-traffic areas, such as canteens or ‘drop in’ workspaces, and areas accessible to the public. In public and when working remotely: do not access where you can be overlooked. |
Sharing (via corporate channels)
|
|
