Asset classification helps organisations implement an effective risk management strategy. It also helps them prioritise security resources, reduce IT costs, and stay in compliance with legal regulations. The most common classification scheme is: *restricted, confidential, internal-only, and public*. - **Restricted** is the highest level. This category is reserved for incredibly sensitive assets, like need-to-know information. - **Confidential** refers to assets whose disclosure may lead to a significant negative impact on an organization. - **Internal-only** describes assets that are available to employees and business partners. - **Public** is the lowest level of classification. These assets have no negative consequences to the organization if they’re released.