Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intended audience
Managers and program owners
Difficulty
Intermediate
Estimated time
15 minutes
Access
Free
NIST SP 800-171
ISO 27001
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Assign a classification level (Public, Internal, Confidential, or Regulated) to realistic business records.
  • Identify the specific rule, contract clause, or law that makes a given record 'Regulated' rather than simply sensitive.
  • Match each classification level to an approved storage location within the organization's real systems.
  • Write enforceable sharing rules tied to each classification level.
  • Distinguish classification decisions based on impact of disclosure rather than a subjective sense of secrecy.

Records to classify

  • Marketing brochure PDF.
  • Employee payroll register.
  • Customer contract with pricing.
  • Engineering drawing supplied by a federal prime.
  • Internal meeting notes.
  • Résumés from a recent hiring round.

Key takeaways

  • Classification should be judged by the consequence of disclosure, not by how sensitive a record feels intuitively.
  • A record is only 'Regulated' when a specific law, contract clause, or standard applies to it, and that source should always be named.
  • Each classification level needs a defined, approved storage location so employees know exactly where data belongs.
  • Sharing rules are where classification becomes operationally meaningful; a label with no sharing rule accomplishes little.
  • Data classification frameworks are most effective when they map directly onto real systems the organization already uses.

Practice workspace

  1. Hint: Ask what happens if it leaks, not how secret it feels.

  2. Hint: Contract clause, privacy law, card scheme, or health rule.

  3. Hint: Name real systems you use.

  4. Hint: Sharing rules are where classification earns its keep.

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 1
Knowledge check

80% required to pass. Answers are graded on our servers.

1. An engineering drawing supplied by a federal prime contractor is most likely which classification level?

2. What should determine a record's classification level?

3. For a record marked 'Regulated,' what must accompany the classification decision?

4. Why does each classification level need an approved storage location?

5. Why are sharing rules considered the point where classification 'earns its keep'?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Matched on shared frameworks, topics, and program packs.

Template

Data Classification Matrix

Define your data levels and the handling rules that follow from each one.

Intermediate
30 min
Premium
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Beginner
20 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Template

Information Security Policy

The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.

Intermediate
45 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Internal Audit Preparation Checklist

Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.

Intermediate
35 min
Free
SOC 2
ISO 27001

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.