Skip to main content
NexusGroup Employee Portal

Knowledge base · Records & systems

Classifying information correctly

The four classification levels and how to handle information at each one.

3 min read · Updated 22 June 20XX · For All staff

Classifying information tells you how careful to be with it. Nexus Group uses four levels — from freely shareable to tightly controlled.

The four levels

LevelWhat it meansHow to handle it
PublicApproved to share outside Nexus.No restrictions — just use the approved version.
InternalFor staff generally; not for outsiders.Share within Nexus on a work-need basis; don’t post publicly.
ConfidentialLimited to those who need it; includes personal information.Need-to-know access; store securely; follow the Privacy Policy.
RestrictedSensitive or financial; tightly controlled.Strict access; never copy off approved systems; report any exposure.

How to classify something

Ask: who could be harmed, and how badly, if this got out or was wrong?

  • Personal details (staff or customer) → at least Confidential.
  • Financial records, payroll → Restricted.
  • Internal reports and working documents → Internal.
  • Published policies, brochures, templates → Public.

If you’re unsure, treat it as the higher level until you can check.

Handling tips

  • Label or note the classification where you can.
  • Match how you store and share it to its level (see Information Security).
  • Don’t downgrade something to make sharing easier — check with the owner first.

Where information lives

Each asset has an owner and a system — see the information asset register and the business systems register.