Information security category | Categorisation of information and information systems based on the information security impact on safety risk analysis. Information service providers and consumers apply the performance-based information security requirements based on the category. | NONE | None. | BASIC | Information security categories shall be reviewed every (2) years based on the latest risk analysis. | INTERMEDIATE | Information security categories shall be reviewed annually based on the latest risk analysis. | ADVANCED | Information security categories shall be reviewed monthly based on the latest risk analysis. |