Agent skill

Classification Policy

by Hack23 in Hack23/cia

Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad

Apache-2.0Auto-check passedLegal & Compliance

Install Classification Policy

skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia classification-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/classification-policy .claude/skills/classification-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
classification-policy
GitHub stars
239
Token cost
~7.4k tokens
SKILL.md length
1,449 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad

  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Purpose, When to Use This Skill, 4-Tier Classification Model and Classification Decision Tree, plus 7 more sections
  • Calls psql; reaches github.com

What it does

Classification Policy is an agent skill from Hack23/cia. Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad

Its SKILL.md is about 7.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/classification-policy”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • psql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • img.shields.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Classification Policy loads about 7.4k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,449 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 1,449 words, ~7,387 tokens.

Download SKILL.mdSave it as .claude/skills/classification-policy/SKILL.md (or your agent's skills folder).
name
classification-policy
description
Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad
license
Apache-2.0

Data Classification Policy Skill

Purpose

This skill provides systematic guidance for implementing risk-based data and asset classification within the CIA platform, ensuring proper protection controls align with information sensitivity, business impact, and regulatory requirements per ISO 27001 A.5.12, A.5.13, and A.8.10.

When to Use This Skill

Apply this skill when:

  • ✅ Designing data models with sensitive information (personal data, political records)
  • ✅ Implementing access controls for classified information
  • ✅ Defining encryption requirements for data at rest and in transit
  • ✅ Creating data handling procedures (storage, transmission, disposal)
  • ✅ Conducting privacy impact assessments (GDPR compliance)
  • ✅ Establishing retention and disposal policies
  • ✅ Labeling data assets in documentation or code
  • ✅ Configuring security controls for different sensitivity levels

Do NOT skip for:

  • ❌ "Internal-only" systems (still require classification)
  • ❌ Development/test data (may contain production data copies)
  • ❌ Temporary data stores (still subject to classification)
  • ❌ Public APIs (may expose classified data)

4-Tier Classification Model

Classification Levels Overview
mermaid
graph TD
    subgraph Classification["🏷️ Classification Tiers"]
        RESTRICTED["🔴 RESTRICTED<br/>Extreme Confidentiality<br/>National Security Level"]
        CONFIDENTIAL["🟠 CONFIDENTIAL<br/>High Confidentiality<br/>Business Sensitive"]
        INTERNAL["🟡 INTERNAL<br/>Moderate Confidentiality<br/>Company Use Only"]
        PUBLIC["🟢 PUBLIC<br/>No Confidentiality<br/>Publicly Accessible"]
    end
    
    subgraph CIA["🛡️ CIA Triad Mapping"]
        CONF["🔒 Confidentiality<br/>Data Secrecy"]
        INT["✅ Integrity<br/>Data Accuracy"]
        AVAIL["⏱️ Availability<br/>Data Access"]
    end
    
    subgraph Controls["🔐 Security Controls"]
        ENCRYPTION["🔐 Encryption Requirements"]
        ACCESS["🚪 Access Controls"]
        AUDIT["📊 Audit Logging"]
        RETENTION["📅 Retention Policy"]
    end
    
    RESTRICTED --> CONF
    RESTRICTED --> INT
    RESTRICTED --> AVAIL
    
    CONFIDENTIAL --> CONF
    CONFIDENTIAL --> INT
    CONFIDENTIAL --> AVAIL
    
    INTERNAL --> INT
    INTERNAL --> AVAIL
    
    PUBLIC --> AVAIL
    
    CONF --> ENCRYPTION
    CONF --> ACCESS
    INT --> AUDIT
    AVAIL --> RETENTION
    
    style Classification fill:#1565C0
    style CIA fill:#4CAF50
    style Controls fill:#FF9800
🔴 RESTRICTED - Extreme Confidentiality

Definition: Information requiring maximum protection due to severe business, legal, or regulatory consequences if disclosed.

CIA Triad Mapping:

  • Confidentiality: Image: Extreme - Unauthorized disclosure causes catastrophic damage
  • Integrity: Image: Critical - Data tampering creates legal liability
  • Availability: Image: High - Authorized access required for compliance

Examples in CIA Platform:

  • Encryption keys and cryptographic secrets
  • Database credentials and connection strings
  • OAuth tokens and API keys
  • Personal Identity Numbers (Swedish personnummer)
  • Authentication credentials and password hashes

Mandatory Security Controls:

Control TypeRequirementImplementation
Encryption at RestAES-256 or strongerAWS KMS, encrypted EBS volumes
Encryption in TransitTLS 1.3 minimumHTTPS only, HSTS enabled
Access ControlZero-trust, MFA requiredRBAC, least privilege principle
Audit LoggingAll access logged with retentionCloudWatch Logs, 1-year retention
LabelingExplicit marking requiredCode comments, doc headers
RetentionMinimum required, immediate disposalAutomated purging after expiry

Java Implementation Example:

java
/**
 * CLASSIFICATION: RESTRICTED
 * Contains database credentials - never log or expose
 * 
 * @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/CLASSIFICATION.md">Classification Policy</a>
 * @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/Cryptography_Policy.md">Cryptography Policy</a>
 */
@Configuration
public class DatabaseConfig {
    
    // RESTRICTED: Database password from encrypted secrets manager
    @Value("${spring.datasource.password}")
    private String databasePassword;
    
    @Bean
    public DataSource dataSource() {
        HikariConfig config = new HikariConfig();
        config.setJdbcUrl(System.getenv("DB_URL"));
        config.setUsername(System.getenv("DB_USERNAME"));
        
        // NEVER log or print RESTRICTED data
        config.setPassword(databasePassword);
        
        // Enable connection encryption (TLS 1.3)
        config.addDataSourceProperty("ssl", "true");
        config.addDataSourceProperty("sslmode", "verify-full");
        
        return new HikariDataSource(config);
    }
    
    @Override
    public String toString() {
        return "DatabaseConfig{password=***REDACTED***}";
    }
}

Handling Requirements:

  • ❌ NEVER store in source code or version control
  • ❌ NEVER log to application logs or console
  • ❌ NEVER transmit over unencrypted channels
  • ❌ NEVER store in plaintext configuration files
  • ✅ Store in AWS Secrets Manager or Parameter Store
  • ✅ Inject via environment variables at runtime
  • ✅ Rotate regularly (minimum quarterly)
  • ✅ Immediate revocation when compromised
🟠 CONFIDENTIAL - High Confidentiality

Definition: Business-sensitive information with significant financial, operational, or competitive impact if disclosed.

CIA Triad Mapping:

  • Confidentiality: Image: Very High - Disclosure causes major business harm
  • Integrity: Image: High - Unauthorized modification creates business risk
  • Availability: Image: High - Business continuity depends on access

Examples in CIA Platform:

  • Political party financial records (detailed budget data)
  • Ministerial expense reports (before public release)
  • Internal security vulnerability assessments
  • Business strategy and competitive analysis
  • System architecture diagrams with security details

Mandatory Security Controls:

Control TypeRequirementImplementation
Encryption at RestAES-256 recommendedDatabase encryption, encrypted backups
Encryption in TransitTLS 1.2 minimumHTTPS, secure API calls
Access ControlRBAC with quarterly reviewsSpring Security, user roles
Audit LoggingAccess events loggedApplication logs, 90-day retention
LabelingClassification marking recommendedDocument headers, metadata
RetentionBusiness-driven retention7 years for financial data

Java Implementation Example:

java
/**
 * CLASSIFICATION: CONFIDENTIAL
 * Contains business-sensitive political party financial data
 * 
 * Access restricted to authenticated users with PARTY_ANALYST role
 * All access logged per ISO 27001 A.8.15
 */
@Entity
@Table(name = "party_financial_record")
public class PartyFinancialRecord {
    
    @Id
    @GeneratedValue(strategy = GenerationType.IDENTITY)
    private Long id;
    
    @Column(name = "party_id", nullable = false)
    private String partyId;
    
    // CONFIDENTIAL: Detailed budget breakdown
    @Column(name = "budget_json", columnDefinition = "jsonb")
    @Convert(converter = JsonConverter.class)
    private Map<String, BigDecimal> detailedBudget;
    
    @Column(name = "fiscal_year")
    private Integer fiscalYear;
    
    @CreatedDate
    @Column(name = "created_at", nullable = false)
    private LocalDateTime createdAt;
    
    @CreatedBy
    @Column(name = "created_by")
    private String createdBy;
}

@Service
public class PartyFinancialService {
    
    private final AuditLogger auditLogger;
    
    @PreAuthorize("hasRole('PARTY_ANALYST') or hasRole('ADMIN')")
    @Audited(message = "Access to CONFIDENTIAL party financial data")
    public PartyFinancialRecord getFinancialRecord(Long recordId, String userId) {
        // Log access to CONFIDENTIAL data
        auditLogger.logDataAccess(
            "CONFIDENTIAL", 
            "party_financial_record", 
            recordId, 
            userId
        );
        
        return financialRepository.findById(recordId)
            .orElseThrow(() -> new ResourceNotFoundException("Record not found"));
    }
}

Handling Requirements:

  • ❌ NEVER share with unauthorized external parties
  • ❌ NEVER store on unencrypted removable media
  • ❌ NEVER transmit via unencrypted email
  • ✅ Encrypt before email transmission (if required)
  • ✅ Access requires authentication and authorization
  • ✅ Mark documents with "CONFIDENTIAL" header
  • ✅ Securely dispose when no longer needed
🟡 INTERNAL - Moderate Confidentiality

Definition: Information intended for internal use only, with moderate business impact if disclosed externally.

CIA Triad Mapping:

Examples in CIA Platform:

  • Internal project planning documents
  • System performance metrics and analytics
  • Employee directory and contact information
  • Internal training materials
  • Aggregated usage statistics (anonymized)

Security Controls:

Control TypeRequirementImplementation
Encryption at RestRecommended for sensitive subsetsDatabase encryption optional
Encryption in TransitTLS 1.2 for external accessHTTPS for web interfaces
Access ControlAuthentication requiredStandard user accounts
Audit LoggingSignificant events loggedBasic application logs
LabelingClassification marking optionalFile metadata preferred
RetentionStandard business retention3 years typical

Java Implementation Example:

java
/**
 * CLASSIFICATION: INTERNAL
 * System performance metrics for internal monitoring
 * 
 * Access requires authentication
 */
@Entity
@Table(name = "system_metrics")
public class SystemMetrics {
    
    @Id
    @GeneratedValue(strategy = GenerationType.IDENTITY)
    private Long id;
    
    @Column(name = "metric_name")
    private String metricName;
    
    @Column(name = "metric_value")
    private Double metricValue;
    
    @Column(name = "timestamp")
    private LocalDateTime timestamp;
    
    @Column(name = "server_id")
    private String serverId;
}

@RestController
@RequestMapping("/api/internal/metrics")
public class MetricsController {
    
    // INTERNAL: Requires authenticated user
    @GetMapping
    @PreAuthorize("isAuthenticated()")
    public ResponseEntity<List<SystemMetrics>> getMetrics(
            @RequestParam LocalDateTime startTime,
            @RequestParam LocalDateTime endTime) {
        
        List<SystemMetrics> metrics = metricsService.findByTimeRange(startTime, endTime);
        return ResponseEntity.ok(metrics);
    }
}

Handling Requirements:

  • ❌ NEVER publish to public websites or repositories
  • ❌ NEVER share with external parties without approval
  • ✅ Share with authenticated internal users
  • ✅ Use standard email for internal distribution
  • ✅ Standard backup and retention procedures
  • ✅ Dispose using normal deletion procedures
🟢 PUBLIC - No Confidentiality

Definition: Information approved for public disclosure with no confidentiality requirements.

CIA Triad Mapping:

Examples in CIA Platform:

  • Public API documentation
  • Open-source code repositories (GitHub public repos)
  • Published voting records (already public from Riksdagen)
  • Press releases and marketing materials
  • Public data visualizations and dashboards

Security Controls:

Control TypeRequirementImplementation
Encryption at RestNot requiredStandard storage
Encryption in TransitRecommended for integrityHTTPS for web content
Access ControlNone requiredPublic access allowed
Audit LoggingOptionalBasic web server logs
LabelingClassification marking optionalMetadata optional
RetentionIndefinite or business needStandard retention

Java Implementation Example:

java
/**
 * CLASSIFICATION: PUBLIC
 * Published voting records from Swedish Riksdagen
 * 
 * Data already public via Riksdagen API
 * No access restrictions required
 */
@Entity
@Table(name = "voting_record")
public class VotingRecord {
    
    @Id
    private String votingId;
    
    @Column(name = "politician_id")
    private String politicianId;
    
    @Column(name = "vote")
    @Enumerated(EnumType.STRING)
    private VoteType voteType; // YES, NO, ABSTAIN, ABSENT
    
    @Column(name = "voting_date")
    private LocalDate votingDate;
    
    @Column(name = "document_id")
    private String documentId;
}

@RestController
@RequestMapping("/api/public/voting-records")
public class VotingRecordController {
    
    // PUBLIC: No authentication required
    @GetMapping
    public ResponseEntity<List<VotingRecord>> getVotingRecords(
            @RequestParam(required = false) String politicianId,
            @RequestParam(required = false) LocalDate startDate,
            @RequestParam(required = false) LocalDate endDate) {
        
        List<VotingRecord> records = votingService.findPublicRecords(
            politicianId, startDate, endDate
        );
        
        return ResponseEntity.ok(records);
    }
}

Handling Requirements:

  • ✅ Can be published to public websites
  • ✅ Can be shared via any medium
  • ✅ No special disposal requirements
  • ⚠️ Verify data is truly public before classifying
  • ⚠️ Ensure no embedded RESTRICTED/CONFIDENTIAL data

Classification Decision Tree

Use this decision tree to classify information:

mermaid
graph TD
    START["🏷️ Start Classification"] --> Q1{"Contains credentials,<br/>encryption keys,<br/>or PII?"}
    
    Q1 -->|Yes| RESTRICTED["🔴 RESTRICTED"]
    Q1 -->|No| Q2{Business-sensitive or<br/>competitive advantage<br/>if disclosed?}
    
    Q2 -->|Yes| Q3{Significant financial<br/>or legal impact<br/>if disclosed?}
    Q2 -->|No| Q4{Already publicly<br/>available or<br/>approved for release?}
    
    Q3 -->|Yes| CONFIDENTIAL["🟠 CONFIDENTIAL"]
    Q3 -->|No| INTERNAL["🟡 INTERNAL"]
    
    Q4 -->|Yes| PUBLIC["🟢 PUBLIC"]
    Q4 -->|No| INTERNAL
    
    RESTRICTED --> R_CONTROLS["🔐 Maximum Security:<br/>• AES-256 encryption<br/>• MFA required<br/>• Never log<br/>• Immediate disposal"]
    
    CONFIDENTIAL --> C_CONTROLS["🛡️ High Security:<br/>• Encryption recommended<br/>• RBAC enforced<br/>• Access logging<br/>• Quarterly reviews"]
    
    INTERNAL --> I_CONTROLS["🚪 Standard Security:<br/>• Authentication required<br/>• Internal use only<br/>• Standard retention<br/>• Basic logging"]
    
    PUBLIC --> P_CONTROLS["🌐 Public Access:<br/>• No restrictions<br/>• Integrity focus<br/>• High availability<br/>• Public distribution OK"]
    
    style RESTRICTED fill:#D32F2F
    style CONFIDENTIAL fill:#FF9800
    style INTERNAL fill:#FDD835
    style PUBLIC fill:#4CAF50
    style START fill:#1565C0

Labeling Requirements

Code-Level Labeling

JavaDoc Comments:

java
/**
 * CLASSIFICATION: RESTRICTED
 * 
 * Contains authentication tokens and encrypted credentials.
 * 
 * Security Requirements:
 * - Never log token values
 * - Rotate tokens every 90 days
 * - Immediate revocation on compromise
 * 
 * @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/CLASSIFICATION.md">Classification Policy</a>
 * @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/Secrets_Management_Policy.md">Secrets Management</a>
 */
public class AuthenticationToken {
    // Implementation
}

SQL Table Comments:

sql
-- CLASSIFICATION: CONFIDENTIAL
-- Party financial data with business-sensitive budget details
-- Access requires PARTY_ANALYST role
COMMENT ON TABLE party_financial_record IS 
'CLASSIFICATION: CONFIDENTIAL - Party financial data requiring access control';

COMMENT ON COLUMN party_financial_record.budget_json IS 
'Detailed budget breakdown - business sensitive';
Document-Level Labeling

Markdown Header:

markdown
---
title: Security Vulnerability Assessment
classification: CONFIDENTIAL
date: 2025-02-10
author: Security Team
retention: 7 years
---

# CONFIDENTIAL: Security Vulnerability Assessment

**Classification**: CONFIDENTIAL  
**Audience**: Internal Security Team Only  
**Distribution**: Do not forward externally

Configuration Files:

yaml
# CLASSIFICATION: INTERNAL
# Application configuration - internal use only
spring:
  application:
    name: citizen-intelligence-agency
  # ... configuration

GDPR and Privacy Classification

Show full SKILL.md (602 more words)Show less
Special Category Personal Data (Art. 9 GDPR)

Definition: Sensitive personal data requiring explicit consent and enhanced protection.

Examples:

  • Political opinions and party membership (Art. 9.1.a GDPR)
  • Trade union membership
  • Health data
  • Biometric data for identification
  • Genetic data

Classification Mapping:

GDPR CategoryClassificationRationale
Political opinionsCONFIDENTIAL minimumBusiness-sensitive + GDPR Art. 9
Health dataRESTRICTEDSpecial category + high risk
Biometric dataRESTRICTEDUnique identifier + irreversible

CIA Platform Handling:

java
/**
 * CLASSIFICATION: CONFIDENTIAL
 * GDPR: Special Category Personal Data (Art. 9.1.a - Political Opinions)
 * 
 * Political party membership requires:
 * - Explicit consent (GDPR Art. 9.2.a)
 * - Legal basis documentation
 * - Enhanced security controls
 * - Privacy by design
 */
@Entity
@Table(name = "politician_party_membership")
public class PoliticianPartyMembership {
    
    @Id
    private String membershipId;
    
    @Column(name = "politician_id", nullable = false)
    private String politicianId;
    
    // GDPR Art. 9 - Political opinion (special category)
    @Column(name = "party_id", nullable = false)
    private String partyId;
    
    @Column(name = "membership_start")
    private LocalDate membershipStart;
    
    @Column(name = "membership_end")
    private LocalDate membershipEnd;
    
    // GDPR compliance: Track consent basis
    @Column(name = "legal_basis")
    @Enumerated(EnumType.STRING)
    private GdprLegalBasis legalBasis; // PUBLIC_OFFICIAL, LEGITIMATE_INTEREST
    
    @Column(name = "data_source")
    private String dataSource; // "Riksdagen Public API"
}
Personal Data Classification
Data TypeGDPR ClassificationPlatform ClassificationSecurity Controls
Direct Identifiers (name, SSN)Personal DataRESTRICTEDEncryption + MFA
Political OpinionsSpecial CategoryCONFIDENTIALEnhanced access controls
Contact Information (email, phone)Personal DataCONFIDENTIALAccess logging
IP AddressesPersonal DataINTERNALStandard security
Aggregated AnalyticsAnonymizedPUBLICEnsure irreversible anonymization

ISO 27001 Control Mapping

A.5.12 - Classification of Information

Control Objective: Ensure appropriate level of protection based on importance to organization.

Implementation in CIA Platform:

  • ✅ Four-tier classification model defined (RESTRICTED, CONFIDENTIAL, INTERNAL, PUBLIC)
  • ✅ Classification criteria documented in this skill
  • ✅ Labeling procedures for code, data, and documents
  • ✅ CIA triad mapping to security controls
  • ✅ GDPR privacy level integration

Verification:

bash
# Search for classification labels in codebase
grep -r "CLASSIFICATION:" --include="*.java" --include="*.sql" citizen-intelligence-agency/

# Verify database column comments include classification
psql -d cia_database -c "\
SELECT table_name, column_name, col_description(attrelid, attnum) \
FROM information_schema.columns \
JOIN pg_class ON relname = table_name \
JOIN pg_attribute ON attrelid = pg_class.oid AND attname = column_name \
WHERE table_schema = 'public' \
AND col_description(attrelid, attnum) LIKE '%CLASSIFICATION%';"
A.5.13 - Labelling of Information

Control Objective: Ensure information assets receive appropriate level of protection.

Implementation:

  • ✅ Labeling standards for code comments, database tables, documents
  • ✅ Automated labeling enforcement via code review
  • ✅ Metadata tagging in version control systems
A.8.10 - Information Deletion

Control Objective: Information deleted when no longer required.

Retention by Classification:

java
/**
 * Automated data retention enforcement
 */
@Component
@Scheduled(cron = "0 0 2 * * *") // Daily at 2 AM
public class DataRetentionEnforcer {
    
    private final AuditLogger auditLogger;
    
    public void enforceRetention() {
        // RESTRICTED: Immediate disposal after expiry
        deleteExpiredRestrictedData();
        
        // CONFIDENTIAL: 7-year retention (financial data)
        deleteExpiredConfidentialData(Period.ofYears(7));
        
        // INTERNAL: 3-year retention (operational data)
        deleteExpiredInternalData(Period.ofYears(3));
        
        // PUBLIC: Indefinite retention (no automatic deletion)
    }
    
    private void deleteExpiredRestrictedData() {
        List<RestrictedData> expired = restrictedRepo.findExpired(LocalDateTime.now());
        
        for (RestrictedData data : expired) {
            // Secure deletion with audit trail
            auditLogger.logDataDeletion("RESTRICTED", data.getId(), "RETENTION_EXPIRED");
            restrictedRepo.secureDelete(data);
        }
    }
}

NIST Cybersecurity Framework Mapping

PR.DS-2: Data-in-transit is protected

  • ✅ TLS 1.3 for RESTRICTED data
  • ✅ TLS 1.2 minimum for CONFIDENTIAL data
  • ✅ HTTPS recommended for INTERNAL/PUBLIC data

PR.DS-5: Protections against data leaks are implemented

  • ✅ Access controls per classification level
  • ✅ Audit logging for RESTRICTED/CONFIDENTIAL access
  • ✅ Data loss prevention through classification awareness

CIS Controls Mapping

CIS Control 3: Data Protection

  • 3.3: Configure data access control lists
    • ✅ RBAC implementation per classification
  • 3.11: Encrypt sensitive data at rest
    • ✅ AES-256 for RESTRICTED
    • ✅ Database encryption for CONFIDENTIAL
  • 3.12: Segment data processing and storage
    • ✅ Separate storage for different classification levels

Practical Implementation Checklist

For New Data Models
  • Identify sensitivity level using decision tree
  • Assign classification tier (RESTRICTED/CONFIDENTIAL/INTERNAL/PUBLIC)
  • Document CIA triad requirements
  • Add classification labels to code/schema
  • Implement required security controls
  • Define retention and disposal procedures
  • Conduct GDPR privacy assessment if applicable
  • Document legal basis for personal data processing
  • Configure access controls per classification
  • Enable audit logging for RESTRICTED/CONFIDENTIAL data
For Existing Systems
  • Inventory all data assets
  • Classify each asset using decision tree
  • Add classification labels to existing code
  • Verify current controls match classification requirements
  • Identify and remediate control gaps
  • Update documentation with classification markings
  • Conduct classification review (annual minimum)

Common Classification Mistakes

❌ Mistake 1: Over-Classification

Problem: Classifying all data as RESTRICTED/CONFIDENTIAL unnecessarily
Impact: Excessive security overhead, reduced operational efficiency
Solution: Use decision tree, classify based on actual business impact

❌ Mistake 2: Under-Classification

Problem: Classifying sensitive data as PUBLIC/INTERNAL
Impact: Inadequate protection, compliance violations, data breaches
Solution: When uncertain, classify higher and review with security team

❌ Mistake 3: No Classification

Problem: Leaving data unclassified
Impact: No clear security controls, inconsistent protection
Solution: Mandate classification for all new data models via PR reviews

❌ Mistake 4: Inconsistent Labeling

Problem: Same data classified differently across systems
Impact: Confusion, control gaps, audit findings
Solution: Centralized classification authority, regular reviews

AWS Implementation Examples

S3 Bucket Classification
yaml
# CloudFormation template for classified S3 bucket
Resources:
  ConfidentialDataBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: cia-confidential-party-data
      BucketEncryption:
        ServerSideEncryptionConfiguration:
          - ServerSideEncryptionByDefault:
              SSEAlgorithm: aws:kms
              KMSMasterKeyID: !Ref DataEncryptionKey
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true
      VersioningConfiguration:
        Status: Enabled
      LifecycleConfiguration:
        Rules:
          - Id: CONFIDENTIAL-7year-retention
            Status: Enabled
            ExpirationInDays: 2555 # 7 years
            NoncurrentVersionExpirationInDays: 30
      Tags:
        - Key: Classification
          Value: CONFIDENTIAL
        - Key: DataOwner
          Value: PartyAnalysisTeam
        - Key: GDPRCategory
          Value: BusinessSensitive
RDS Database Classification
yaml
  ConfidentialDatabase:
    Type: AWS::RDS::DBInstance
    Properties:
      DBInstanceIdentifier: cia-confidential-db
      Engine: postgres
      EngineVersion: "18.3"
      DBInstanceClass: db.t3.medium
      StorageEncrypted: true
      KmsKeyId: !Ref DataEncryptionKey
      BackupRetentionPeriod: 30
      EnableCloudwatchLogsExports:
        - postgresql
      DeletionProtection: true
      Tags:
        - Key: Classification
          Value: CONFIDENTIAL
        - Key: DataType
          Value: PoliticalFinancialRecords
        - Key: RetentionYears
          Value: "7"

References

  • ISO 27001:2022 - A.5.12 Classification of Information
  • ISO 27001:2022 - A.5.13 Labelling of Information
  • ISO 27001:2022 - A.8.10 Information Deletion
  • GDPR Article 9 - Processing of Special Categories of Personal Data
  • NIST SP 800-60 - Guide for Mapping Types of Information
  • CIS Controls v8 - Control 3: Data Protection

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/classification-policy of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Classification Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Classification Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Classification Policy this skillHack23/cia239—~7.4kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin183—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    939 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    939 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    183 GitHub stars~6.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Classification Policy

What does Classification Policy do?

Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad. Classification Policy is an agent skill from Hack23/cia.

When should I use Classification Policy?

Classification Policy fits situations like: tasks that involve SOC 2 and security compliance.

How do I install Classification Policy in Claude Code?

Run `npx skills add Hack23/cia --skill classification-policy -a claude-code`. Or copy the skill folder (.github/skills/classification-policy in Hack23/cia) into .claude/skills/classification-policy in your project. Claude Code loads it when a task matches its description.

How do I install Classification Policy in Codex?

Run `npx skills add Hack23/cia --skill classification-policy -a codex`. Or copy the skill folder (.github/skills/classification-policy in Hack23/cia) into .agents/skills/classification-policy in your project. Codex loads it when a task matches its description.

Can I use Classification Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill classification-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/classification-policy, .gemini/skills/classification-policy, .github/skills/classification-policy and .opencode/skills/classification-policy in your project.

What does Classification Policy need to run?

Going by SKILL.md and its folder, Classification Policy needs the command-line tools its instructions call (psql).

Does Classification Policy access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: img.shields.io. This is read from the text; nothing was executed.

Is Classification Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Classification Policy use?

Classification Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Classification Policy use?

About 7.4k tokens (SKILL.md is roughly 30k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Classification Policy?

Skills that share tags, products or a category with Classification Policy: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 183 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Classification Policy?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.