Data classification
dataPolicy: classification: confidential inputs: - name: customer_data classification: personal outputs: - name: report classification: internal restrictions: externalTransfer: deny- Classes from least to most restrictive:
public,internal,confidential/personal,restricted/sensitive,secret. - Executions whose inputs rank above
dataPolicy.classificationare rejected. - Declassifying an output is recorded in the
artifact.createdevent. - The classes are an organizational vocabulary. Mapping them to legal definitions is up to the organization.
Normative text: Data classification.