How to use the Government’s Industry Data Classification Framework (IDCF) to bolster your data security
If your business holds customer or employee information, a data breach isn’t a hypothetical – it’s an escalating threat....
In our Workforce Pulse survey of 510 Aussie businesses, we found that 37 per cent named a data breach involving employee or customer information as one of their biggest workforce worries.
This worry grows with your business – you don’t just have more data to process, but more employees who need to know exactly what kind of data they’re handling.
When there’s no standardised classification for data, it’s easy for private data to be passed between systems without anybody noticing. Just because one employee knows data is private doesn’t guarantee that everyone’s on the same page. When data isn’t clearly classified, a data breach becomes a real possibility.
Data breaches are increasingly common – the Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in 2025 alone.
That’s why the Australian Government has launched the Industry Data Classification Framework (IDCF) so your organisation can learn how to:
The IDCF includes three core strategies which are specifically designed to fit businesses of all shapes and sizes.
Think of them as one big journey, not isolated activities, where each strategy naturally leads to the next.
The first step is a risk assessment: the framework provides tools, questionnaires and impact ratings to give businesses a standardised approach to assessing data risk. It shows where you can go wrong, how serious the harm could be, and the type of protection your data needs.
Once you know the risk, you’re ready for Data Security Levels (DSLs). These are basically labels which tell people how they should store and share data.
Based on your risk assessment, you’ll receive a DSL range from zero – requiring minimal protection – to 5+, which requires the strongest standard of information security.
Once your levels are set, you can take the optional step of adding a marker – extra information to clearly show what kind of data is being handled and how it should be treated.
For example, a document might be classified as:
DSL-3, Confidential
The DSL-3 part tells us what level of protection is required. The confidential marker signals that handling obligations apply — for example, written agreements that limit who can access the data.
While the framework provides practical guidance for managing data according to risk, organisations might then look to demonstrate the effectiveness of their information security practices to customers, regulators and other stakeholders.
The best way to do this is through ISO/IEC 27001 certification. Chris Kondic, Citation Certification’s Executive General Manager, highlights that “ISO/IEC 27001 certification provides independent assurance that an organisation’s information security management system (ISMS) has been assessed against an internationally recognised standard.”
Achieving certification means your business has implemented a structured, audited ISMS that demonstrably protects sensitive data, client records, and critical systems. It’s widely regarded as the gold standard for information security and is applicable to organisations of all sizes and industries globally.
Workforce Pulse survey respondents cited ISO 27001 as the most common “next” certification businesses intend to pursue. 35 per cent of those without it – more than any other standard – identified it as the logical next step in their certification strategy.
For an ISO/IEC 27001-certified organisation, the IDCF can help address a common weakness by providing a more defensible, risk-based approach to data classification. The IDCF and ISO 27001 work hand in hand; IDCF helps organisations understand and classify their data risks, while ISO/IEC 27001 provides the structured, independently assessed framework for managing those risks and protecting information.
Learn how to turn data security into a measurable business gain through the ISO 27001 framework, or set up an obligation-free call to discuss how certification can build confidence in your business.