Markers help you share extra information about your data. They sit next to a Data Security Level (DSL) label and add more information about the data, such as how the data should be handled or who can access it.
Using markers is optional. Organisations can decide which markers to use, when to use them and if more than one marker should be applied. Most organisations use them only when they want to communicate something specific. Markers do not change the DSL - they add handling or sharing details on top of it.
Markers can be used to show things like whether:
- the data needs careful handling
- the data includes private or sensitive information
- access should be limited to certain people.
Markers can also be used to signal rules for sharing or retention, such as time-limited or ‘internal only’ access. Markers support day-to-day work by giving quick directions about how data should be treated.
Organisations can also agree to use them when sharing data, so everyone applies the same handling rules.
For example, an email may be classified as:
DSL-3, Confidential
DSL-3 is the label which communicates the protection required based on the risks. ‘Confidential’ is the marker. In the IDCF, this marker signifies that there may be obligations in place (such as a written agreement) to limit access to the data. Markers like ‘Confidential’ guide how data is shared, but the DSL still sets the protection level systems must meet.
Types of markers
The three types of markers in the IDCF give you flexibility while ensuring organisations take a consistent approach. The types of markers are:
- integrated markers – these markers are built into the IDCF. They cover common handling needs such as who can see the data.
- adopted markers – these markers come from another organisation or standard and are used in the IDCF. An example is the
Traffic Light Protocol (TLP). The TLP uses colours to show how widely information can be shared.
- user-defined markers – these are created by an organisation to suit its own needs. They can be used within the organisation or agreed on when sharing data with another organisation. User-defined markers should be clearly documented so others can interpret them correctly.
For more information, go to
Module 5: Markers module in the IDCF.