What is “Restricted distribution” and how can you ensure the security and certification of Information Systems?

  • Defence
  • Cyber
  • Cybersecurity

© Ercom et Adobe stock

  • Type Insight
  • Published

With data being shared digitally to an ever increasing extent, governments and institutions have introduced classification policies to safeguard sensitive information. What do these classifications entail, and what must organisations put in place to ensure they comply? Read on for full details.

In a context of increasing digitalisation and the exchange of documents between private and public entities, as well as French and foreign partners, the French Interministerial General Instruction No. 1300 on the protection of national defence secrets introduces a new classification framework for government information, together with defined rules governing its protection and handling. This directive identifies two categories of non-public information:

  • classified information protected under criminal law;
  • protected information falling under the Restricted designation, which is not subject to specific legal protection.

The Restricted designation is intended to protect non-public information that does not fall within the scope of national defence and security classification. Unauthorised access to, dissemination of, or misappropriation of information protected by this designation:

  • would be detrimental to public safety, the reputation of institutions, or the privacy of their representatives;
  • is likely to contribute to an increase in the risks of terrorism, the proliferation of conventional weapons technologies, or weapons of mass destruction, as defined under the directive on the Protection of the Nation’s Scientific and Technical Potential (PPST);
  • would undermine the political, military, diplomatic, scientific, economic, or industrial strategies of the French State.

The principal purpose of the Restricted designation is to remind users of their duty of discretion, as well as the disciplinary or administrative sanctions to which they may be exposed in the event of a breach.

France is not the only country to operate a classification policy designed to protect sensitive information. The Restricted designation has equivalents within the security frameworks of the European Union (EU Restricted) and NATO (NATO Restricted). Their purpose is to safeguard the interests and information relating to the political, military, diplomatic, scientific, economic, and industrial strategies of these international organisations against the risks of disclosure or unauthorised access.

Finally, additional protective designations exist to restrict access by foreign individuals and organisations, even where they are otherwise authorised. This is the purpose of the “Special France” or “Special France and [countries] Eyes Only” designation used in multinational programmes.

What is the regulatory framework for CIOs and CISOs who must ensure the security of restricted information?

Organisations processing Restricted information must comply with the requirements of Interministerial Instruction No. 901/SGDSN/ANSSI (II 901), relating to sensitive or Restricted information systems. This instruction defines the security measures and rules governing the implementation of an approved Restricted information system.

The requirements of II 901 apply to:

  • state administrations and public or private entities processing sensitive information;
  • organisations subject to the directive on the Protection of the Nation’s Scientific and Technical Potential (PPST);
  • entities possessing knowledge or expertise that could potentially be used for terrorist purposes or for the proliferation of weapons of mass destruction or their delivery systems.

These requirements structure the protection of Restricted information processed by an organisation in order to ensure business continuity, protect its reputation, prevent data breaches, and secure both personnel and assets.

These measures are also based on existing technical standards and the recommendations issued by the French National Cybersecurity Agency (ANSSI). ANSSI has published a guide entitled Recommendations for the Architecture of Sensitive or Restricted Information Systems to support the implementation of II 901 measures in the design of the information system (IS) architecture hosting Restricted information.

The primary objective of this guide is to provide technical recommendations for the architecture of sensitive and Restricted information systems. Certain technical aspects, however, are not covered, including physical and environmental security, security relating to IT developments, Voice over IP telephony, and information system access control. CISOs and CIOs must therefore ensure that such measures are implemented in accordance with recognised best practice and state-of-the-art security standards.

When establishing a Restricted Information System, organisations must implement a formal security accreditation procedure. This procedure identifies the scope of the information system processing Restricted information, together with the components necessary for its operation and protection, including filtering, detection, alerting, and backup capabilities. Risks relating to these components must then be identified and managed accordingly.

The accreditation process also includes verification of compliance with the regulatory requirements applicable to Restricted systems. The combination of risk management and compliance assessment results in an accreditation decision taken by the representative of the organisation operating the system. This decision formalises the acceptance of residual risk at the highest level of the organisation.

The IS architecture and all interconnections must be accredited and periodically reassessed as part of a process of continuous improvement and ongoing adaptation to evolving threats. II 901 further specifies that interconnections involving a Restricted IS must be subject to separate accreditation.

How can organisations ensure the security and accreditation of their Restricted IS?

To protect and accredit an information system, the following prerequisites should be implemented:

  • use trusted products and service providers holding ANSSI security approval;
  • implement end-to-end encryption for all sensitive information;
  • segregate information within the IS either physically (dedicated equipment) or logically (VPNs, VLANs, etc.);
  • classify and label information so that users, administrators, and operators are aware of the required level of protection;
  • apply the RESTRICTED DISTRIBUTION marking to office documents where appropriate;
  • enable strong primary and secondary authentication mechanisms;
  • rigorously manage the allocation of access rights and permissions;
  • protect application servers, workstations, and interconnection systems against malicious code;
  • limit the use of peripherals and removable media.

Today, both public and private organisations face growing requirements for mobility, collaborative working, and the secure sharing of sensitive information. Providing secure access to and exchange of such information with external partners therefore requires solutions capable of delivering a high level of security.

How to ensure the security and certification of your Restricted IS?

© Ercom

In order to protect and certify your IS, the following are prerequisites:

  • Use trusted products and service providers with ANSSI security approval.
  • Use end-to-end encryption for your information.
  • Segregate your information within the IS either physically (dedicated equipment)or logically (VPN, VLAN...).
  • Tag the information so that users, administrators, operators... are made aware of the level of protection of the information they handle.
  • For office documents, it is necessary to stamp them with the RESTRICTED DISTRIBUTION designation.
  • Enable strong initial and secondary authentication.
  • Rigorously manage the allocation of permissions.Protect against malicious code on application servers, workstations and means of interconnection.Limit the number of peripherals and removable media.

    Today, both public and private organisations have increased needs for mobility, collaborative work and sharing sensitive information, all in a secure manner. Accessing and sharing this information with external partners require solutions capable of ensuring strong security.

Related articles

  • Defence

How to stop the use of unsecured attachments without hampering your teams’ productivity

Insight
  • Defence

Remote access: Which VPN can balance security and user experience?

Insight
  • Europe

The Five Cybersecurity Questions Every Critical Organisation Should Be Asking in 2026

Insight
  • Defence

Data protection: How can you comply with ANSSI’s recommendations?

Insight
  • Defence

Supply chain: How can we build an environment of trust?

Insight
  • Defence

Why is encryption your best defence against targeted attacks?

Insight
  • Defence

Hosting Your Data in France or Overseas: What Difference Does It Make?

Insight
  • Defence

Crisis communication: How does the Executive Committee communicate when the main network is compromised?

Insight
  • Defence

What are ANSSI's recommendations regarding mobile phones?

Insight