Sensitivity describes how much harm, obligation or control is associated with disclosure, misuse, alteration, loss or inappropriate access.
Public announcements, internal plans, student records, financial details, trade secrets, safety-critical instructions and regulated personal information all differ in sensitivity. The classification should determine handling, access, sharing, storage, retention and review rather than exist as a decorative label.
Quick answer: how should sensitivity be categorised?
- Disclosure harm: what happens if unauthorised people see it?
- Integrity harm: what happens if it is altered?
- Availability harm: what happens if it is lost or unavailable?
- Privacy: does it concern identifiable people?
- Legal or contractual duty: is protection required?
- Operational importance: does misuse disrupt essential function?
- Audience: public, internal, restricted, need-to-know?
- Handling: what storage, transfer and disposal controls apply?
- Retention: how long should the sensitive state persist?
- Review: when can the classification be lowered or raised?
This article complements How to Categorise Access and How to Categorise Labels. Sensitivity describes the protection need; access and labels operationalise that need.
Sensitivity is not secrecy
Information can be sensitive because of privacy, safety, reputation, contract or operational importance even when it is not secret in the national-security sense.
Sensitivity is not importance
A highly important public policy can be non-confidential, while a minor internal record can still be sensitive because it contains personal data.
Public sensitivity means disclosure is broadly acceptable
Public does not mean inaccurate, ownerless or free from integrity controls. It means broad disclosure is permitted.
Internal sensitivity limits routine distribution
Internal material may be intended for staff or members but not the general public. The risk is usually moderate and contextual.
Confidential sensitivity requires controlled sharing
Unauthorised disclosure can create meaningful legal, financial, privacy, competitive or reputational harm.
Restricted sensitivity narrows access further
Need-to-know access, stronger authentication, encryption, export limits and detailed audit may apply where consequences are severe.
Critical sensitivity concerns severe operational or safety consequence
Some information or control states deserve the highest protection because misuse can cause major disruption, safety harm, irreversible loss or systemic compromise.
Regulated sensitivity comes from external obligation
Privacy law, health rules, financial regulation, contractual confidentiality and other regimes can impose handling requirements independent of an organisation’s preferred label names.
Confidentiality, integrity and availability sensitivity can differ
A public timetable may have low disclosure sensitivity but high integrity sensitivity if unauthorised changes would mislead thousands of users.
Personal sensitivity depends on identifiability and consequence
Names, contact details, educational records, health data, financial records and credentials can require different protection based on context and harm.
Aggregated data can change sensitivity
Combining many low-sensitivity records can create sensitive patterns, and aggregation can sometimes reduce sensitivity if individuals can no longer be identified.
Derived information inherits and can amplify sensitivity
An inference, profile or model output can reveal more than any one source field. Classification should consider what the derived result exposes.
Sensitivity should control access
Higher sensitivity generally justifies narrower audiences, stronger authentication, more explicit permissions and shorter standing access.
Sensitivity should control handling
Storage, encryption, printing, copying, transfer, export and disposal rules should become stricter as potential harm rises.
Sensitivity should control logging
High-sensitivity access often deserves stronger evidence of who accessed, changed or exported the resource.
Sensitivity should control retention
Keeping sensitive material forever can increase exposure. Retention should follow legal, operational and evidential needs rather than habit.
Sensitivity labels should be self-descriptive
Labels should make relative protection clear enough that users can distinguish levels without memorising arbitrary codes.
Too many levels reduce consistency
A complex hierarchy can create disagreement and misclassification. Use enough levels to change handling decisions, not to create administrative theatre.
Under-classification creates exposure
If sensitive material is labelled too low, access and handling controls may be insufficient.
Over-classification creates friction
If everything is restricted, collaboration, search and retrieval degrade and users may begin bypassing the system.
Sensitivity can change over time
Embargoed results can become public, commercial plans can lose value, and personal or legal restrictions can persist longer. Effective dates and review triggers matter.
Context can raise or lower sensitivity
The same field can be harmless in one context and sensitive in another when combined with location, identity, vulnerability or operational timing.
Sensitivity conflicts need higher authority
If one source marks a record public and another marks it restricted, preserve the governing authority and resolve the conflict rather than averaging labels.
AI systems can propagate sensitive content
Classification should follow data into prompts, retrieval stores, generated outputs and logs rather than assuming sensitivity disappears when information changes format.
A practical sensitivity record
- sensitivity ID;
- resource or information class;
- sensitivity level;
- confidentiality, integrity and availability impacts;
- privacy status;
- legal or contractual basis;
- allowed audience;
- handling requirements;
- access requirements;
- retention and disposal rules;
- owner and authority;
- effective and review dates;
- downgrade or escalation rules;
- version.
The deeper idea
Sensitivity is a translation layer between potential harm and practical handling. It should change what people and systems do.
To categorise sensitivity well is to know what harm could follow disclosure, alteration or loss, what obligations apply, who may access the material and which controls change as the level changes.
Final answer
Categorise sensitivity by disclosure, integrity and availability harm, privacy, legal duty, operational impact, audience, handling, access, retention and review. Use levels such as public, internal, confidential, restricted, critical and regulated only when each level drives materially different controls.
