Data Classification
TTI Code · code.tti.tamu.edu
⚠ DRAFT — placeholder text, not yet reviewed or approved by TTI Information Security. The approved classification level for this instance and the category definitions must be confirmed against the authoritative TAMUS/TTI standard before publication.
Approved level for this instance
TTI Code is approved to store data classified up to and including: [SET BY TTI ISO — e.g., "Controlled" but NOT "Confidential/CUI"]. Data above this level must not be placed here without explicit ISO approval and any required compensating controls.
Categories (align to the authoritative TAMUS standard)
| Category | Examples | Allowed here? |
| Public | Open-source code, public docs, published research artifacts | Yes |
| Controlled / Internal | Internal tooling, unpublished research code, operational config (no secrets) | [per approved level] |
| Confidential / Regulated | CUI, export-controlled (ITAR/EAR), PII/FERPA/HIPAA, sponsor-restricted | [ISO approval required] |
Map these rows to the exact TAMUS data-classification standard categories and references. [ISO to confirm.]
Your responsibilities
- Classify what you store; when unsure, treat it as the higher category and ask [TTI ISO].
- Use private or internal repository visibility for any non-public data; never make a repo public without confirming it contains only Public data.
- Keep secrets out of repositories entirely (use the secrets store), regardless of classification.
Automated classification (planned)
TTI Code will integrate automated data-tagging and classification (Microsoft Purview / the TTI landscape data platform) so repository content is scanned and labeled on push, and findings are reported to ISO. Until that lands, classification is the user's responsibility per this page.
Version: DRAFT · Last updated: [date] · Owner: [TTI ISO]