Texas A&M Transportation Institute · TTI Code policy · Unapproved draft

Data Classification

Which kinds of data may be kept in a TTI Code repository, and which may not. Every category and limit below is placeholder text — nothing on this page has been reviewed or approved yet, so it cannot be used to decide where data belongs.

⚠ DRAFT — placeholder text, not yet reviewed or approved by TTI Information Security. The approved classification level for this instance and the category definitions must be confirmed against the authoritative Texas A&M University System standard before publication. Values still awaiting a decision are marked like this.

Approved level

The highest classification of data TTI Code is approved to store.

Ceiling for this instance

Not set

TTI Information Security has not yet set the level this instance is approved to hold, so no level is approved today.

To be filled in by TTI Information Security — e.g. “Controlled”, but NOT “Confidential / CUI”.

Data above the approved level must not be placed here without explicit approval from TTI Information Security, together with any compensating controls it requires.

Categories

Draft rows only. They must be mapped to the exact categories and references in the authoritative Texas A&M University System data-classification standard — TTI Information Security to confirm.

CategoryExamplesAllowed here?
Public Open-source code, public docs, published research artifacts Yes
Controlled / Internal Internal tooling, unpublished research code, operational configuration (no passwords or keys) Per approved level
Confidential / Regulated Controlled unclassified information (CUI); export-controlled work (ITAR/EAR); personal, student or health records (PII, FERPA, HIPAA); sponsor-restricted material Approval required

Your responsibilities

Automated classification (planned)

TTI Code will integrate automated data tagging and classification (Microsoft Purview and TTI's own data platform) so that repository content is scanned and labelled when it is pushed, and findings are reported to TTI Information Security. Until that is in place, classifying what you store is your responsibility, as set out above.