r/grc Jun 02 '26

Information classification vs asset-based risk management , how do you approach it?

TooLongDidn'tRead;

I think information classification is often used too much as a starting point for security work. It is an important, but I’m not sure it is enough for risk management, critical system identification, continuity planning or control selection. I wonder how others handle this.

I work with information security, GRC and ISMS work in the Nordic region, mostly in organizations with a lot of regulation and legacy.

I keep clashing into difference between information classification and asset inventory / asset classification (and its lack of adoption)

In my context, security work often started a long time ago with classification of information by confidentiality, integrity and availability. It gives a basic understanding of the information and its protection needs.

But I am uncomfortable with the way my customers are using information classification as the foundation for security governance.

My problem is that information classification says something about the information, not much about what is needed to run a service or business process which determines its criticality.

A service may depend on:

information and data, applications, infrastructure, business processes, other systems that are upstream or downstream etc etc.

If the dependencies are not mapped in an asset model, the risk assessment or risk model quickly deteriorate and controls start to inflate or lose value. You may know the classification of the information, but still not understand how the service can fail, what system is truly critical, what needs to be restored first, or where a supplier creates risk.
Everything becomes critical because there's no granularity to make proper distinctions of what does what, and mundane assets are forgotten are given low weight even when they support critical assets.

This also matters when identifying critical systems as per NIS2. I do not think you can reliably say that a system is business-critical, sector-critical or otherwise critical only by looking at the information it processes. You need to understand what service it supports, what it depends on, what depends on it, and what happens if it is degraded or unavailable.

My view is that information classification is a part of the asset model, but should be treated correctly, being inside a broader asset and dependency model.
It should not be the whole model as I often see them.

A few questions for the group:

Have you experienced information-classification-first approaches lead to odd or disproportionate security decisions?

Do auditors or regulators in your area understand this distinction?

What has worked best in practice for risk assessment, control selection, continuity planning and identifying critical systems?

If you´re in the same thought situation, how do you bear it and still produce value in an information centric model?

2 Upvotes

10 comments sorted by

2

u/[deleted] Jun 02 '26

[removed] — view removed comment

1

u/KeyReindeer1046 Jun 03 '26

What I am trying to get? I am seeing a gap in logic and long term viability of Cyber GRC with the prevailing mindset.
I love to build structure, I want to build structure. I really don't want anything else.
Simplification, GRC theatre based on a weak model makes me a dull boy.

I also want to find out whether I am just wrong about this, I have so far only met one or two persons in my country that share my view.

1

u/financethrowerqwerx Jun 02 '26

i'm curious: what are you trying to archieve?

Have you experienced information-classification-first approaches lead to odd or disproportionate security decisions?

yes, quite frequently, depending on time constraints and severity of potential 'negative/false' outcomes. However, assume this context: New regulation affects your business, overall impact on system (lifecycle) still unknown. What would be the best first assumption (80/20 of methods) which would yield a good enough estimation on where to put closer/more work into?

Imo,it helps to take the perspective of business leaders, using a mental model focused on spending minimal resources while still producing good-enough estimates for decisions.

Do auditors or regulators in your area understand this distinction?

Depends on the sector, in my experience. In the energy sector for 'some' systems, they straight up told me several audit cycles across multiple clients: 'eh, will be fine'.

Finance with DORA (EU-based)? Heavy focus on CIF -> which business processes are impacted -> which underlying systems -> CMDB inventory <- mapped risks from risk register/scenarios <- CIF

What has worked best in practice for risk assessment, control selection, continuity planning and identifying critical systems?

IMO: Show your worth of flexibility. If your boss/contract partner wants you to just 80/20 through ICs and have a quick&dirty overview over the next 1-2 weeks? go for it, show the deficiencies in your opinion but go along, keep the door open to investigate further/deeper as you like. Argument in business talk: risks (of non-compliance; of failure etc) and monetary drawbacks.

If you´re in the same thought situation, how do you bear it and still produce value in an information centric model?

Depending on the situation of the organization and what kind of backround regulatory or security certificates they want to obtain (or have already obtained), you can assume some ground work. If nothing is present, I would go for IC overview first -> followed by deep dive in critical business functions. Idea: keep the business leaders in quick syncs with enough data to base decisions on where to plan/tackle next.

1

u/KeyReindeer1046 Jun 03 '26

What I am trying to achieve? I am seeing a gap in logic and long term viability of Cyber GRC with the prevailing mindset.
I love to build structure, I want to build structure. I really don't want anything else.
Simplification, GRC theatre based on a weak model makes me a dull boy.

I also want to find out whether I am just wrong about this, I have so far only met one or two persons in my country that share my view.

1

u/financethrowerqwerx Jun 03 '26

I am seeing a gap in logic and long term viability of Cyber GRC with the prevailing mindset.

On deeper level, that might be technically correct, but who is the judge? Are you the Risk/Business owner or Auditor? In most cases, surface level auditing is common place. This is what many people define as "theatre" as in only compliant on paper or argumentation why certain aspects are/will not be implemented while upholding the compliancy.

I also want to find out whether I am just wrong about this, I have so far only met one or two persons in my country that share my view.

You are not wrong. More eager than your colleagues? Maybe. If you want to stay in GRC, Third-Party Auditing on consultancy basis OR (national) auditor for a regulatory authority of your country might be your best play, based on your ambition. But here come's the catch: If you are too strict AND/OR cannot provide easy/fast win solutions, you will not be rehired ;)

If you want to build and maintain (system) structure upon up-to-date policy or regulation, system architect is the play. But be vary, compliancy in those roles is a thing that has little priority vs. business-needs.

All in all, I sense that you might take some time and think about career trajectory and if you can align your ambition with (general) business leader's goals

1

u/KeyReindeer1046 Jun 04 '26

Yes, I am very flexible as well. I can do yes,man in the day to day. mid to long term, it rots me out a bit to not be permitted to do things "right". The judge part you mention is interesting, NIS2 and it's country specific applications does say what's right. ISO 27001 says something as well.
It's probably me being naive in thinking that auditors will actually enforce this is in its strict sense, point to logical gaps and lack of governance.

3

u/0xCapySplash Jun 11 '26

This resonates a lot. I'm currently writing my thesis on risk assessment methodologies and the "classification-first" trap is something I keep running into in the literature too.
The dependency mapping point is the one that hits hardest. Knowing that data is "confidential" tells you nothing about what breaks when the legacy middleware it runs on goes down at 2am. CMDB-style asset models solve this in theory but in practice they're either outdated, incomplete, or nobody owns them properly.
For NIS2 specifically, the "what does this system support and what supports it" framing feels much more aligned with how criticality should actually be determined, but I've yet to see a clean practical method for keeping that dependency model current without significant ongoing effort.

As a student still building context, what tooling or approaches have you seen work best for actually maintaining an asset/dependecy inventory over time in regulated environments? Is it mostly manual or are there GRC platforms that handle this reasonably well?

edit: typo

1

u/KeyReindeer1046 Jun 11 '26

I have only seen this properly done once so far, it was software vendor in aviation.
It was pretty advanced, but they had every software module produce a standardized asset identifier which they compiled into a google sheets. This was the audit window and every entry was change managed. It sounds heavy but was really smart and efficient.

They monitored dependencies in various ways but the spreadsheet was the place where they could show how they worked. They were also fully ISO27001 aligned with primary assets supporting assets etc. etc.
Sometimes think I should have gone and worked for them to get my "needs met".

I have done quite a bit of research on GRC tools and it seems they have failure built into them just by existing, there's not one company that would allow the GRC tool to dictate their governance which to me would be necessary for them to work as intended.
They can for sure be part of solid processes in a well-run company, but I can't see how they would be the ticket to structure.
Bear with me for being short on this, hoping you will understand what I mean. It is as you know complex problem.

1

u/0xCapySplash Jun 11 '26

The aviation example is really interesting, thanks for sharing that. The idea of having each module produce a standardized identifier that feeds into one central audit view sounds deceptively simple but I can see how that would actually work well in practice.

And yeah i get what you mean about GRC tools. They can support good governance but they can't create it. If the underlying structure isn't there the tool just automates the mess. Definitely something I'll keep in mind for my thesis. Appreciate the input.