Texas A&M Transportation Institute · TTI Code policy · Unapproved draft
Data Classification
Which kinds of data may be kept in a TTI Code repository, and which may not. Every category and limit below is placeholder text — nothing on this page has been reviewed or approved yet, so it cannot be used to decide where data belongs.
Approved level
The highest classification of data TTI Code is approved to store.
Ceiling for this instance
TTI Information Security has not yet set the level this instance is approved to hold, so no level is approved today.
Data above the approved level must not be placed here without explicit approval from TTI Information Security, together with any compensating controls it requires.
Categories
Draft rows only. They must be mapped to the exact categories and references in the authoritative Texas A&M University System data-classification standard — TTI Information Security to confirm.
| Category | Examples | Allowed here? |
|---|---|---|
| Public | Open-source code, public docs, published research artifacts | Yes |
| Controlled / Internal | Internal tooling, unpublished research code, operational configuration (no passwords or keys) | Per approved level |
| Confidential / Regulated | Controlled unclassified information (CUI); export-controlled work (ITAR/EAR); personal, student or health records (PII, FERPA, HIPAA); sponsor-restricted material | Approval required |
Your responsibilities
- Classify what you store. When you are unsure, treat it as the higher category and ask TTI Information Security.
- Use private or internal repository visibility for any non-public data. Never make a repository public without first confirming it holds only Public data.
- Keep passwords, keys and tokens out of repositories entirely — put them in the secrets store instead — whatever the classification of the rest of the repository.
Automated classification (planned)
TTI Code will integrate automated data tagging and classification (Microsoft Purview and TTI's own data platform) so that repository content is scanned and labelled when it is pushed, and findings are reported to TTI Information Security. Until that is in place, classifying what you store is your responsibility, as set out above.