Organizations have established information classification and handling criteria used to
classify, handle and handle information depending on their sensitivity, nature, value, and
likely consequences of unauthorized access ( ). In most organizations, the Campbell, 1
Microsoft Information Protection (MIP) framework is used to handle the classification needs
for emails and other electronic documents (1). The MIP has sensitivity labels, which are
configured to suit the protection settings needed for the content (1). A majority of
organizations use the following label classifications for the protection process; Staff Only
(#staffonly / #internal), and content under such labels is only accessed by the staff of the
organizations ( *(#confidential / #classified), information under suchToelle, 2).*Confidential
a label is classified and encrypted for specific internal and external people