Access control mechanisms usually control accesses between objects and subjects in a computing system. Objects in a computing environment are ranked according to a security class hierarchy to facilitate the operation of access control mechanisms. At present the process of allocating a security class to an object is solely based on human judgment. The objective of the framework as proposed in this paper is not to eliminate human judgment, but rather to assist the process oi allocating security classes to objects. Concepts borrowed from classical information theory, such as entropy, are applied in the process of allocating security classes to objects, resulting in a so-called mechanical component of a security class for an object.