There are several terms in cybersecurity that are often confused. Information classification, TLP protocol, security categorization, or access control are often used almost synonymously in presentations, internal policies, and marketing materials. They are not. It’s like someone claiming that a car license plate, a driver’s license, and a traffic sign are the same thing because they all relate to transportation in some way.
The result of this confusion is an environment where no one knows whether to mark a document as confidential, add TLP:AMBER to it, or put it in a restricted folder. Yet each of these measures addresses a completely different issue. If we confuse them, the result is chaos and confusion that leads to a false sense of security. This is just as dangerous as ignoring the rules.
Imagine a situation where you receive information about a new critical vulnerability. Before you start sharing or storing it, you should answer four simple questions.
1) How sensitive is this information?
2) Who can we share it with?
3) Who can access it?
4) What are the consequences if it is compromised?
Each of these questions is addressed by a different standard or methodology. Without an understanding of these rules, any attempt to classify data will end in the aforementioned chaos.
The Traffic Light Protocol (TLP), managed by FIRST, was created as a simple way to manage information sharing between organizations. Its purpose is not to determine the sensitivity of information, but to establish rules for its further dissemination. TLP does not say how important or classified the information is. It only says who can share it further. Any part of the standard is an indication of what the TLP protocol is intended for. Nowhere is it mentioned whether the information is secret, confidential or public. TLP simply does not determine the sensitivity of information.
In TLP 2.0, there are five levels:
TLP:CLEAR – information can be shared publicly.
TLP:GREEN – can be shared within the community.
TLP:AMBER – only within the recipient's organization.
TLP:AMBER+STRICT – only to specific recipients.
TLP:RED – only to participants in the original communication.
If we obtain information about a new critical vulnerability, it may contain publicly known information and still be marked as TLP:RED. The manufacturer simply does not want to allow the dissemination of this information outside the security team. The same information can be marked as TLP:CLEAR a few days later, even though its content has not changed at all. TLP therefore answers only one question: Who can I forward the information to?
Information classification addresses its sensitivity. The organization tries to determine how serious the consequences of unauthorized disclosure, change or loss of the information would be. That is why most organizations use their own classification scheme. The most common levels are Public, Internal, Confidential and Restricted. Some companies add Secret or Highly Confidential, while others only use three levels. In the private sector, it is often possible to come across a document marked as "Confidential". In contrast, the state administration uses legally defined levels of secrecy. Both solutions can be correct, although they look different.
Neither ISO/IEC 27001 nor ISO/IEC 27002 prescribe specific class names. They only require that the organization establish a classification, use it consistently, and that it corresponds to the actual risks. This is an important difference from TLP. ISO says that a classification should exist, but does not specify its form.
There is another difference. Government administrations usually have classification properties clearly defined by law. A private company cannot therefore give its internal documents a label such as "SECRET", thus suggesting or claiming that they are of a state level of secrecy. Such a label could be misleading, especially if the documents are shared outside the company or with state institutions. Therefore, the classification should be clearly defined and differentiated. On the other hand, it is not generally forbidden to use similar terminology, if it is clearly stated that it is a corporate system.
One of the most common mistakes is the claim that FIPS 199 represents a document classification system. The American standard FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems evaluates the impact of a security incident on an information system or type of information. It assesses three basic security properties. The first is confidentiality, the second is integrity, and the third is availability. This is the well-known CIA security triad. Each of these properties is given a level of Low, Moderate, or High. The result is not a label on a document, but a security categorization of the system.
If we imagine, for example, a hospital information system, the loss ofAvailability can mean a threat to the lives of patients. In this case, availability will be rated High. Confidentiality of personal data, on the other hand, can be Moderate and integrity of records again High. This combination ultimately determines what security measures must be implemented. FIPS 199 therefore answers the question: How serious will the impacts of a security incident be?
FIPS 199 itself is a relatively brief document. Practical use is described only in NIST SP 800-60, which shows how to categorize individual types of information. The next document following the document determining impacts is FIPS 200. This sets out minimum security requirements for federal information systems. The last document is NIST SP 800-53. Tent contains a catalog of security measures that should correspond to the resulting security category.
Thus, FIPS 199 determines the impact of a data breach, NIST SP 800-60 the severity, and NIST SP 800-53 the method of resolution.
FIPS 199 therefore determines the security impact category (impact level) based on confidentiality, integrity, and availability. NIST SP 800-60 helps determine this category for specific types of information and information systems. NIST SP 800-53 defines the security and protection measures (controls) that should be implemented to reduce risk. FIPS 200 fulfills the role of translating the determined impact level into minimum security requirements for federal information systems.
Public administration and security agencies do not use the same classification levels as commercial companies. Legislation mandates uniform labeling of classified information. For this reason, commercial organizations must implement clearly distinguishable levels of data classification. The European Union uses four levels of EU Classified Information. NATO uses its own classification scheme. Individual member states then have national classification systems that are mapped to each other. These classification levels have legal significance. They are not just recommendations or internal methodologies; incorrect data evaluation has serious consequences. And this is exactly why private organizations must avoid uniform labeling.
Let's imagine a safe full of documents marked "Secret". The label on a document does not mean that anyone with a security clearance can open all the documents. This is what access control is for. Access control determines who can read, change or delete a document. In other words, it answers the question: Who is allowed in? This is what access control addresses. There are several different methods here, hidden under the acronyms DAC, MAC, RBAC, ABAC, and others.
Let's imagine a document containing a security incident response plan. The organization classifies it as Confidential. At the same time, it marks it TLP:AMBER because it does not want it to be passed outside the organization. Only members of the security team will gain access to the document through RBAC. If the organization uses MAC, the user's security level will also be verified. If ABAC is used, the system will also check the device, location, or other attributes. Each mechanism solves a different problem. None of them replaces the others. Knowing these mechanisms and the impact of their action is an integral part of understanding the entire issue of information security management in the IT sector.
The most common mistakes in this area are caused by misunderstanding.
Mistake 1: that TLP represents a document classification. It does not.
Mistake 2: FIPS 199 labels documents as confidential or secret. In reality, it assesses the impact of a security incident on information systems and information types.
Mistake 3: Classification automatically determines access permissions. In reality, classification only describes the sensitivity of information. Permissions are addressed by the access control model.
Mistake 4: The organization believes that by implementing classification labels, it has solved information security. This is like a hospital deciding that once a patient has been tagged, the doctor is no longer needed. The label itself does not protect anything. True security is created by a combination of correct classification, appropriate access control, information sharing controls, and strict adherence to security rules.
I would like to appologize, this time the list of references will be much longer. It would be possible to write a times longer article about this topic.
1. Introductory Provisions
1.1. These General Terms and Conditions are, unless otherwise agreed in writing in the contract, an integral part of all contracts relating to training organised or provided by the trainer, Jan Dušátko, IČ 434 797 66, DIČ 7208253041, with location Pod Harfou 938/58, Praha 9 (next as a „lector“).2. Creation of a contract by signing up for a course
2.1. Application means unilateral action of the client addressed to the trainer through a data box with identification euxesuf, e-mailu with address register@cryptosession.cz or register@cryptosession.info, internet pages cryptosession.cz, cryptosession.info or contact phone +420 602 427 840.3. Termination of the contract by cancellation of the application
3.1. The application may be cancelled by the ordering party via e-mail or via a data mailbox.4. Price and payment terms
4.1. By sending the application, the ordering party accepts the contract price (hereinafter referred to as the participation fee) indicated for the course.5. Training conditions
5.1. The trainer is obliged to inform the client 14 days in advance of the location and time of the training, including the start and end dates of the daily programme.6. Complaints
6.1. If the participant is grossly dissatisfied with the course, the trainer is informed of this information.7. Copyright of the provided materials
7.1. The training materials provided by the trainer in the course of the training meet the characteristics of a copyrighted work in accordance with Czech Act No 121/2000 Coll.8. Liability
8.1. The trainer does not assume responsibility for any shortcomings in the services of any third party that he uses in the training.9. Validity of the Terms
9.1 These General Terms and Conditions shall be valid and effective from 1 October 2024.Consent to the collection and processing of personal data
According to Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as "the Regulation"), the processor xxx (hereinafter referred to as "the Controller") processes personal data. Individual personal data that are part of the processing during specific activities at this web presentation and in the course of trade are also broken down.Information about the records of access to the web presentation
This website does not collect any cookies. The site does not use any analytical scripts of third parties (social networks, cloud providers). For these reasons, an option is also offered for displaying the map in the form of a link, where the primary source is OpenStreet and alternatives then the frequently used Maps of Seznam, a.s., or Google Maps of Google LLC Inc. The use of any of these sources is entirely at the discretion of the users of this site. The administrator is not responsible for the collection of data carried out by these companies, does not provide them with data about users and does not cooperate on the collection of data.Information about contacting the operator of the site
The form for contacting the operator of the site (administrator) contains the following personal data: name, surname, e-mail. These data are intended only for this communication, corresponding to the address of the user and are kept for the time necessary to fulfil the purpose, up to a maximum of one year, unless the user determines otherwise.Information about the order form
In case of an interest in the order form, the form contains more data, i.e. name, surname, e-mail and contact details for the organisation. These data are intended only for this communication, corresponding to the address of the user and are kept for one year, unless the user determines otherwise. In the event that a business relationship is concluded on the basis of this order, only the information required by Czech law on the basis of business relations (company name and address, bank account number, type of course and its price) will continue to be kept by the administrator.Information about the course completion document
Within the course, a course completion document is issued by the processor. This document contains the following data: student's name and surname, the name and date of the course completion and the employer's name. The information is subsequently used for the creation of a linear hash tree (non-modifiable record). This database contains only information about the provided names and company names, which may or may not correspond to reality and is maintained by the processor for possible re-issuance or verification of the document's issuance.Rights of the personal data subject
The customer or visitor of this website has the possibility to request information about the processing of personal data, the right to request access to personal data, or the right to request the correction or deletion of any data held about him. In the case of deletion, this requirement cannot be fulfilled only if it is not data strictly necessary in the course of business. The customer or visitor of this website also has the right to obtain explanations regarding the processing of his personal data if he finds out or believes that the processing is carried out in violation of the protection of his private and personal life or in violation of applicable legislation, and the right to request removal of the resulting situation and to ensure the correction.