Rewritten — 2026-07-28 (UTC). As published on 2026-05-18 this article argued that OFFICIAL:Sensitive was a marking and not a classification, and that an OFFICIAL-rated system was by default suitable for it. PSPF Release 2026 says the opposite on both counts. A correction note went up on 2026-07-26; the body below has now been re-authored against the current Guidelines at the same URL. It also repairs a second error the correction note did not catch — Legal Privilege, Legislative Secrecy and Personal Privacy are information management markers, not security caveats.
OFFICIAL: Sensitive is a security classification. It is the lowest rung of the classified ladder, not the top of the unclassified one — and reading it the other way leads to the wrong storage, handling, and assessment decisions.
PSPF Release 2026 Guidelines §9.2 is unambiguous: “The Australian Government uses four security classifications: OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET.” The same paragraph disposes of the rest of the vocabulary — “OFFICIAL and UNOFFICIAL are not security classifications and are not mandatory markings.” So the line that matters does not fall between PROTECTED and everything below it. It falls between OFFICIAL and OFFICIAL: Sensitive, and the colon is where it falls.
The mechanism underneath is the Business Impact Level. A classification is applied only where the compromise of the information would cause impact that is “low to medium, or above”. OFFICIAL: Sensitive sits at BIL 2 — limited damage to an individual, organisation or government — with PROTECTED one step above it at BIL 3 and OFFICIAL one step below at BIL 1. The gap between OFFICIAL and OFFICIAL: Sensitive is a whole impact level, assessed by the originator, and only the originator can change it.
The practical consequences sit in three places.
Handling. Because it is a classification, the §9.3 minimum protections and handling requirements apply, and PSPF Requirement 0061 mandates that the information is clearly marked. Where a text marking is impractical, colour-based marking is mandatory and yellow is the recommended cell colour for OFFICIAL: Sensitive. Entity-specific markings are not recognised by the policy at all.
System scope. The device rules are the clearest illustration of the change. Mobile devices the entity has neither issued nor authorised “must not be authorised to access, process, store or communicate government OFFICIAL: Sensitive or above information” — the boundary is drawn at OFFICIAL: Sensitive, not at PROTECTED. Treat an OFFICIAL environment as automatically fit for OFFICIAL: Sensitive and you have skipped a control boundary the framework draws explicitly. Where an assessment is in scope, the question to answer is whether the environment was assessed for classified information, not whether it was assessed at all.
Aggregation. Aggregation is not a footnote in Release 2026; it is a named sub-impact category in the Business Impact Level tool, at every level. A significant aggregated holding that would cause limited damage on compromise sits at OFFICIAL: Sensitive on that basis alone. A collection of individually routine records can therefore reach a classification its members never held — the assessment is of the holding, not the record.
One more distinction worth getting right, because the two are routinely conflated. Legal Privilege, Legislative Secrecy and Personal Privacy are information management markers: optional, drawn from the National Archives metadata standard, and — in the words of §9.4 — “not protective markers or security classifications”. Security caveats are a different construct entirely (§9.5): four categories, each governed by a controlling authority, imposing handling requirements beyond the classification, and they must only ever appear alongside one. A marker signals a non-security restriction on use. A caveat adds protection. Neither is a classification.
The takeaway survives its own correction: read the marking string in full. The colon is doing work — it just is not the work this article originally described. It is the point at which information becomes security classified.
Published by TrustedZone news automation on 2026-05-18 AEST. Director rollback.