Data Classification Matrix
Define your data levels and the handling rules that follow from each one.
Published · v1.0.0 · 2026-08-01
Exercise
Sort realistic records into classification levels and defend the handling rules that follow.
Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team
Hint: Ask what happens if it leaks, not how secret it feels.
Hint: Contract clause, privacy law, card scheme, or health rule.
Hint: Name real systems you use.
Hint: Sharing rules are where classification earns its keep.
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.
NIST · Revision 3
SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems(opens in a new tab)Link last confirmed 2026-02-01
NIST
Privacy Framework(opens in a new tab)Link last confirmed 2026-02-01
National Archives (ISOO)
Controlled Unclassified Information (CUI) Registry(opens in a new tab)Link last confirmed 2026-02-01
Complete every section, acknowledge, and pass the knowledge check.
This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.
Version v1.0.0 · Document owner: ComplianceAnvil Content Team
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Matched on shared frameworks, topics, and program packs.
Define your data levels and the handling rules that follow from each one.
Published · v1.0.0 · 2026-08-01
Draft one System Security Plan section end to end, using the narrative pattern assessors expect.
Published · v1.0.0 · 2026-08-01
Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.
Published · v1.0.0 · 2026-08-01
Practice separating CUI from FCI and from ordinary business information.
Published · v1.0.0 · 2026-08-01
The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.
Published · v1.0.0 · 2026-08-01
Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.
Published · v1.0.0 · 2026-08-01
Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.