Sensitivity

A measure of the harm that would follow if information were disclosed to people not authorised to see it: the main property that classification labels record.

Sensitivity is a measure of the harm that would follow if information reached people who should not have it. It is the property most classification schemes are built on: a label such as confidential or secret records a judgement about sensitivity, made by the data owner, and the handling requirements follow from that label. FIPS 199 approaches the same idea through potential impact, rating the effect of a loss of confidentiality, integrity or availability as low, moderate or high.

Sensitivity is commonly confused with criticality. Sensitivity asks how much damage exposure would cause; criticality asks how much the organisation depends on the information or system to keep operating. A published price list can be low in sensitivity yet high in criticality for an online shop, while an archived legal file can be the reverse. Sensitivity drives confidentiality controls, access decisions and security clearance requirements; criticality drives availability controls and recovery priority. Sensitivity can fall over time, which is why declassification exists.

Exam relevance: a scenario is likely to describe information and ask what should decide its classification or which kind of control it needs. Candidates are expected to separate sensitivity (harm from disclosure) from criticality (dependence for operations), and to remember that the business owner, not the IT team, makes the judgement.