Information classification policy - Annex 1

Published: 31 August 2026
Freedom of information class: How we manage our resources

Annex 1 provides further guidance for RoS' information classification policy


Information handling guidance

This guidance applies to single artefacts such as documents, or to collections of information and will assist colleagues to correctly classify information and to appropriately protect it based on its classification.

Understanding the classification of the information you are working with, and the implications of this, are essential to designing processes and systems that adequately meet the security requirements for that information. Controls in place for information should be appropriate to its classification.

Classification

RoS uses the UK Government Classification Policy. This means that all RoS information is classified as OFFICIAL.

The OFFICIAL classification covers a huge volume of information at many different levels of sensitivity, ranging from information that is already in the public domain to information that may be of interest to highly capable threat actors, and whose compromise could cause harm (albeit not significant or long-term harm) to the UK, its people or its interests.

Access

Those creating information are responsible for determining who needs to access it. Access to OFFICIAL information should always be no wider than is deemed necessary for business needs and be risk-based.

The need-to-know must be balanced with the need-to-share - information is only valuable if it is used by those who need it. The balance between these two principles must be considered carefully.

Protective marking

Protective marking of OFFICIAL information is not mandatory – see the section on Working with OFFICIAL and OFFICIAL SENSITIVE information for guidance on scenarios where protective marking should be considered.

Within the OFFICIAL classification, information or material whose compromise is likely to cause damage to the work or reputation of RoS and/or government will be classed as OFFICIAL – SENSITIVE and should be marked with the “- SENSITIVE” marking.

It is important to note that the classification of information does not affect our statutory obligations under data protection or freedom of information legislation. In cases where sensitive information is requested, there are exemptions within that legislation to protect the information.

When creating information artefacts, the potential classification of these should be taken into consideration. Specifically, inclusion of sensitive information should only be considered where this is necessary due to the inherent risk and cost associated with protecting and managing information of higher classifications.

For assistance with this guidance or for further information on information security, contact the Information Governance team.

Classification descriptions

Classification should be based on value or sensitivity of the information. This is reflected in the level of risk to RoS resulting from inappropriate sharing or exposure of the information in question.

OFFICIAL (unmarked internally)

OFFICIAL – SENSITIVE (consider marking)

Information whose compromise would typically cause limited to no negative consequences for RoS, UK or Scottish Government, our partners or to an individual.

This includes information that has been cleared for publication. It also includes routine operational, policy and service information that is not intended for public release, but that is unlikely to be of interest to threat actors.

Aggregated data sets of OFFICIAL information may warrant additional controls.

Information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media due to its sensitivity or topical significance.

A compromise could cause moderate, short-term damage to: HMG, the UK’s international reputation, the UK economy, HMG’s relations with its partners (including international partners) or moderate harm or distress to an individual or group of people.

The implications of a compromise could be potentially significant but are not long standing and are unlikely to cause serious harm to HMG or the UK.

Where a document or dataset contains data of differing classifications, the highest classification should be applied.

The classification of information can change over time, for example information that is commercially sensitive during contract negotiations may become less sensitive once the negotiations are complete.

Working with OFFICIAL and OFFICIAL - SENSITIVE information

OFFICIAL

OFFICIAL – SENSITIVE

Verbal information

Information whose compromise would typically cause limited to no negative consequences for RoS, UK or Scottish Government, our partners or to an individual.

This includes information that has been cleared for publication. It also includes routine operational, policy and service information that is not intended for public release, but that is unlikely to be of interest to threat actors.

Aggregated data sets of OFFICIAL information may warrant additional controls.

Information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media due to its sensitivity or topical significance.

A compromise could cause moderate, short-term damage to: HMG, the UK’s international reputation, the UK economy, HMG’s relations with its partners (including international partners) or moderate harm or distress to an individual or group of people.

The implications of a compromise could be potentially significant but are not long standing and are unlikely to cause serious harm to HMG or the UK.

Hard copy information

Storage and access


  • Only print on corporate systems or devices that have been approved by your organisation and keep the number of copies to a minimum.
  • Exercise particular care when storing or accessing names and contact details.
  • Avoid taking hard copy documents out of the office unless there is a clear business need

In the office:

  • Keep your desk clear of hard copy information not in use.
  • Store in an opaque folder or container when not in use.

Working remotely (including from home):

  • Store in a discreet, opaque container.
  • Keep out of sight when not in use.
  • Can be accessed in shared spaces, but be aware of whether you can be overlooked

In public:

  • Store in an opaque folder, bag, or container which can be secured to prevent accidental loss.
  • Can be accessed but be aware of whether you can be overlooked by unauthorised individuals, such as members of the public.

Only print on corporate systems or devices that have been approved by your organisation and keep the number of copies strictly to what is required.

In the office:

  • Keep your desk clear of hard copy information not in use.
  • Store in an opaque folder or container when not in use, and under lock and key when unattended.
  • Use office furniture/physical security equipment that can be securely locked.
  • Avoid accessing in high-traffic areas, such as canteens or ‘drop in’ workspaces.

Working remotely (including from home):

  • Store securely (in a discreet, opaque container and or/lock and key).
  • Keep out of sight when not in use.
  • Do not access where you can be overlooked.

In public:

  • Store in an opaque folder, bag or container, which can be securely fastened to prevent accidental loss.
  • Do not access where you can be overlooked, for example in a cafĂ© or on public transport.

Transportation


Moving physical assets by hand:

  • Use a sealed, opaque cover.

Moving physical assets by courier/post:

  • Include return address.
  • Never mark classification on envelope.
  • Use a reputable commercial courier.

Moving physical assets by hand:

  • Use a sealed, opaque cover.

Moving physical assets by courier/post:

  • Include return address.
  • Never mark classification on envelope.
  • Use a recorded mail service or reputable commercial courier.
  • Seek authorisation from the relevant Information Asset Owner before sending overseas.

Destruction


Do not dispose of information of any classification at home or in public bins.

It should be retained securely at home before being taken into the office and placed in a confidential waste bin or bag.

Digital information

Storage


  • Only save information in RoS systems.
  • Where possible, mark information with “OFFICIAL” in the header and footer.
  • Minimise multiple copies on local systems as far as practically possible (e.g. a team should use a single shared copy rather than saving multiple copies in offline folders on their device).
  • Only save to a folder if you are confident that all those with access to that folder have need-to-know for the information.
  • Mark all information with “OFFICIAL-SENSITIVE” in the header and footer.

Access


In the office: can be accessed in parts of the building which are accessible to the public.

In public and when working remotely: can be accessed but be aware of whether you can be overlooked by unauthorised individuals, such as members of the public.

In the office:

Avoid accessing in high-traffic areas, such as canteens or ‘drop in’ workspaces, and areas accessible to the public.

In public and when working remotely: do not access where you can be overlooked.

Sharing (via corporate channels)


  • Can be shared beyond the original distribution list.
  • Include any additional handling instructions.
  • When sharing outside of RoS, consider protectively marking the information (and if being sent via email, also the email itself)
  • Information can be shared with individuals outside of your organisation on a strict need-to-know and need-to-share basis.
  • Include any additional handling instructions.
  • Only share it beyond the original distribution list where necessary for business purposes and keep the original sender cc’d on any onward distribution. Blind carbon copy (bcc) should not be used when using this marking.
  • Only distribute it to named individuals, or shared mailboxes where you know that all the recipients have a need-to-know.