Page 270

The University of SydneyPage 17Dividing Objects/Information–Assign sensitivity level for each object–Classification–Top Secret (TS)–Secret (S)–Confidential (C )–Unclassified (UC)–Finer classification can be done following “need-to-know” principle.–E.g.Research and Human Resources files are “Confidential”, but HR does not need to know research outcomes of the organization.–Sensitivity of objects can be represented as;–(Classification level, [“need-to-know” category])–E.g. (Confidential, [Research]), and (Confidential, [Financial])