Data Security Levels (DSLs) are the core of the Industry Data Classification Framework (IDCF). A DSL label tells people how to store and share data. A low DSL means the data needs minimal protection. The lowest DSL is 0. A high DSL means the data needs stronger protection. DSL-5+ is the highest.
A DSL label must be applied to data for it to be considered classified under the IDCF.
For more information, go to
Module 4: Data Security Levels module in the IDCF.
Protecting data with DSLs
DSLs help reduce the chance of an adverse event and its consequences by ensuring data is stored and shared in systems that have the right level of protection.
A DSL reflects:
- the likelihood of an adverse event
- the organisation’s risk tolerance
- how big the impact would be if the data was compromised.

Choosing the right DSLs
Organisations choose a DSL by looking at the value of the data and the likelihood of an adverse event, as well as how serious an event’s impact could be. This process is called a
risk assessment.
The IDCF does not tell you exactly which security controls to use. Your organisation decides the DSL after assessing risk. You can then choose the tools and systems that work best for your business, provided they meet or exceed the level of protection required for that DSL.
Organisations can choose the right DSL by looking at:
- the level of risk or possible harm linked to the data – what could happen if an adverse event occurred
- their risk tolerance – how careful they want to be with this type of data (a higher DSL means stronger protection)
- the balance between risk and the cost or effort of protection – choosing a level that is proportionate and practical.
Although the IDCF provides guidance, your organisation can use its own processes or policies, or seek specialised advice, when assigning DSLs
Protecting data at the right level
Once data has a DSL label, it should be stored and used on systems that meet or exceed the level of protection required. As technology and risks change, the protection controls needed to meet a DSL may also change.
If a system claims to meet a certain DSL, the system owner should be able to show that it truly provides that level of protection. The organisation that owns the data is responsible for checking this, especially when sharing data with another organisation. This assurance is often provided through a security statement or included in a data-sharing agreement and organisations should adhere to the code of conduct.
Using DSLs when sharing data
DSL protection always applies when data is stored, used, or moved. When data is transferred between systems, the devices or systems used for the transfer must also have protection that matches the DSL.