Skip to content

Data classification

Source: Storage & Data Standards, sys_kb_id=fdc09a4d93548f908037f8bd1dba10ed.


Level Contains
Public [TBD: not defined in the standard]
Internal [TBD: not defined in the standard]
Confidential [TBD: not defined in the standard]
Restricted PII and HIPAA data
  1. Classification must be documented.
  2. Classification must be tagged on storage resources where possible.

The phrase “where possible” acknowledges that some resource types do not support tags. Where tags are supported, the tag is required.

Classification Requirement
Restricted Private endpoints. Key Vault managed keys where required.
Confidential Private endpoints. Key Vault managed keys where required.
Internal The baseline encryption, identity and backup rules.
Public The baseline encryption, identity and backup rules.

The baseline rules (encryption at rest, TLS 1.2+, backup, IaC) apply at every level. Classification adds private endpoints and managed keys at the top two levels; it does not remove anything at the bottom two.

The standard requires a classification tag but does not fix the key name. [TBD: the tag key is not specified.]

The validator accepts data_classification, dataClassification or classification, and requires the value to be one of Public, Internal, Confidential, Restricted.

tags = {
data_classification = "Restricted"
}

The Azure Environment Standards govern where classified data may live:

Environment Customer data
Sandbox No customer data
Dev No customer data
Test None, or de-identified
Stage Yes (controlled)
Production Yes

Source of truth: plugins/patterson-engineering/skills/storage-data-standards/references/classification.md in the patterson-corp repository.