Skip to content
GitHubLinkedIn

Information Classification Policy

This policy defines information classification levels and the minimum handling rules for each level.

OwnerInformation Security Officer
Contactinfra@lef.tec.br
Version1.1
Last updated2025-03-26
Review cadenceAnnual (or after policy/legal changes)

To establish a consistent and risk-based approach to classify and protect information handled by LEF, ensuring that information is appropriately safeguarded according to its sensitivity and value.

This policy applies to all LEF employees, contractors, systems, and third parties who access or process LEF information.

LEF adopts the following information classification levels:

  • Public: Information that can be shared freely without risk to LEF.
    Example: published marketing materials, job postings.

  • Internal: Information intended for internal use only. Unauthorized disclosure may cause minimal or moderate impact.
    Example: internal procedures, team communications.

  • Confidential: Information whose unauthorized disclosure could negatively impact LEF’s operations, competitive advantage, or client relationships.
    Example: contracts, internal financial reports, customer data.
    All confidential projects are covered by NDAs.

  • All employees are responsible for identifying and handling information in accordance with its classification.
  • The Information Security Officer is responsible for maintaining this policy and supporting its implementation.

Each classification level requires different handling measures:

ClassificationAccess ControlStorage & TransmissionSharing & Disclosure
PublicUnrestrictedNo special requirementsFreely shareable
InternalLEF personnel onlyStored in Microsoft 365 (Teams, OneDrive, SharePoint); encrypted in transitOnly with other LEF personnel
ConfidentialRole-based, need-to-knowStored in Microsoft 365 and/or EVEO Private Cloud; encrypted in transitBased on project assignment and covered by NDA

Outbound email includes a default bilingual disclaimer (EN/PT) managed in Microsoft 365. This adds legal protection but does not replace careful handling of sensitive information. See Microsoft 365 for the current footer.

This policy is reviewed annually or whenever legal, regulatory, or operational changes require it.

Questions about classification or handling of specific information should be directed to: infra@lef.tec.br

  • Exceptions (sharing/storage beyond the default rules):
  • Awareness/communication of classification expectations: