Zero Trust Engineering — Classification and sensitivity taxonomy
securityv1/01 Views
/02 About
Data and information protection engineering reference for classification and sensitivity taxonomy, including policy, logical interfaces, recovery and assurance.
Purpose: Classification and sensitivity taxonomy. Domain: Data and information protection. Family: lifecycle. Scenario trigger: Classify newly created or discovered information. Input assurance: Content signals, business sensitivity and legal obligations. Evaluation: Map information to governed classifications and confidence. Governing policy: Classification precedence, override and review policy. Resource-side obligation: Apply authoritative handling class to information object. Protected concern: Enterprise records and content classification service. Logical interface: Object class confidence source labels obligations and time. Evidence: Classification rationale label version and owner decision. Failure: Misclassification or unsupported sensitivity override. Required recovery: Require owner review and restrict disclosure pending classification. Architectural invariant: A lower-trust system may not downgrade authoritative classification Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.
Curated · other · unspecified · Published by Lattix · 29 elements · 34 relationships · validated on publish
/03 Contents
- Capability
- Data and information protection, Classification and sensitivity taxonomy
- Role
- Data and information protection owner
- Business Actor
- Lifecycle or resource administrator
- Activity
- Classify newly created or discovered information, Verify: Content signals, business sensitivity and legal obligations, Assess: Map information to governed classifications and confidence, Execute: Apply authoritative handling class to information object, Exception: Misclassification or unsupported sensitivity override, Recover: Require owner review and restrict disclosure pending classification
- Application Component
- Content signals, business sensitivity and legal obligations, Map information to governed classifications and confidence, Apply authoritative handling class to information object
- Application
- Enterprise records and content classification service
- Policy
- Classification precedence, override and review policy
- API
- Classification and sensitivity taxonomy logical interface
- Message/Event Schema
- Object class confidence source labels obligations and time
- Data Store
- Classification rationale label version and owner decision
- Control
- Classification and sensitivity taxonomy enforcement assurance
- Risk
- Misclassification or unsupported sensitivity override risk
- Requirement
- A lower-trust system may not downgrade authoritative classification
- Measure
- Classification and sensitivity taxonomy assurance completeness
- Trust Boundary
- Classification and sensitivity taxonomy authority boundary
- State
- Transition verified, Lifecycle transition rejected, Baseline state established, Change pending independent validation, Transition suspended, Lifecycle transition closed