> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/security-vetting-and-technical-assurance-playbook/classification-data-and-privacy/government-security-classifications.md).

# Government Security Classifications

### Purpose

This page defines how government information classifications are handled in projects.

### Classification Tiers

HMG information is managed using three main classification tiers:

| Tier       | Meaning for projects                                                                                |
| ---------- | --------------------------------------------------------------------------------------------------- |
| OFFICIAL   | Routine government business, public services and operations. Requires baseline protective controls. |
| SECRET     | Sensitive information that needs stronger protection because compromise could cause serious damage. |
| TOP SECRET | The most sensitive information requiring the highest levels of protection.                          |

OFFICIAL information may also carry handling caveats such as OFFICIAL-SENSITIVE where additional handling discipline is required.

### Project Rules

* classify information at creation or receipt;
* apply customer marking and handling instructions;
* store information only in approved locations;
* grant access based on need-to-know, role, attributes and approval;
* prevent movement into unapproved collaboration tools, repositories or AI systems;
* apply encryption and audit logging appropriate to the classification;
* retain, archive, return or securely dispose of information according to the contract and data owner instructions.

### Handling Matrix

| Handling area     | Required decision                                                                              |
| ----------------- | ---------------------------------------------------------------------------------------------- |
| Storage           | Approved system, classification boundary, geographic restrictions and backup model.            |
| Transmission      | Approved channel, encryption requirement and recipient validation.                             |
| Collaboration     | Approved workspace, membership control and external sharing restrictions.                      |
| Printing          | Whether printing is permitted, how outputs are protected and disposal method.                  |
| AI and automation | Whether data may be processed by AI tools, where prompts/logs are stored and who approves use. |
| Disposal          | Retention period, secure deletion method and evidence required.                                |

### Quality Gate

No project should process customer or government information until classification, handling, storage, sharing, retention and disposal controls are documented and approved.
