Canberra Hands Industry Data Classification Scheme

Australian organisations now have a common vocabulary for describing how sensitive their data is. The same scheme sets out what protection each category warrants, and how that expectation travels when data is shared.

The Industry Data Classification Framework was released on 2 September by the Department of Home Affairs, developed in partnership with CSIRO. Adoption is voluntary.

The framework is a key deliverable of the 2023-2030 Australian Cyber Security Strategy. It is the final version of work previously known as the Voluntary Data Classification Framework.

Home Affairs describes it as a practical tool with four uses. Organisations can understand the value of their data, identify and manage data risks, apply appropriate protections, and share data securely.

The department says the framework aligns with existing standards. It draws on extensive research and consultation with industry across Australia.

The scheme is pitched at organisations of all sizes, from small and medium enterprises through to large organisations. Home Affairs says it is designed to be flexible and easy to adopt.

That applies whether an organisation is just starting its data security journey or already has mature data handling practices in place.

The breadth is deliberate. Where two organisations exchanging data classify it the same way, the handling expectation attached to a dataset travels with it.

At the centre of the framework are Data Security Levels, running from DSL 0 to DSL 5+. DSL 0 covers data requiring minimal protection. DSL 5+ carries the strongest information security requirements.

Organisations work through a risk assessment first, using tools, questionnaires and impact ratings to establish where exposure sits. Each category of data is then assigned a level, which determines how it must be stored and shared.

Optional markers can be added alongside the level. A dataset labelled DSL-3, Confidential signals both the protection standard and an access restriction.

The framework and its supporting resources are published at idcf.gov.au.

Adoption becomes the next phase of work

This release is not the end of the department's involvement. Under Horizon 2 of the Strategy, covering 2026 to 2028, Home Affairs says it will work closely with industry to support adoption of the framework.

It has also committed to ensuring the framework continues to meet the needs of Australian organisations as the cyber threat landscape changes.

Greta Doherty is First Assistant Secretary, Counter Foreign Interference, Cyber and Technology at the Department of Home Affairs. She framed the release around data value rather than data protection alone.

"The IDCF is an important outcome from the 2023-2030 Australian Cyber Security Strategy that will help Australian organisations understand the value of the data they hold," Doherty said.

"We know that data is an important source of growth for the Australian economy. It helps organisations make better decisions and improve their products and services."

"The IDCF will help Australian industry strengthen their data governance practices, share data with confidence and unlock new opportunities for innovation and collaboration."

Adoption carries no legal obligation and the framework creates no new compliance requirement. It aligns with existing standards rather than displacing them.

Nor does it alter obligations under the Privacy Act 1988, the Security of Critical Infrastructure Act 2018 or sector-specific regulation. Organisations subject to those regimes still assess their data against those rules.

The sequence within the framework is deliberate. Classification precedes control selection, so the level assigned to a dataset determines the handling rules rather than the other way round.

That also places the work ahead of certification rather than in competition with it. Classification establishes what needs protecting before controls are chosen or a standard such as ISO 27001 is pursued.