Skip to main content

Data Classification Policy

Purpose

This policy defines the classification of information managed by the Skpr hosting platform, ensuring data is appropriately protected according to its sensitivity and impact level. It aligns with Australian government classification standards for agencies and regulated industries.

Scope

This policy applies to:

  • All digital assets across AWS environments
  • Infrastructure as Code (e.g. Terraform state files and modules)
  • Internal documentation
  • Client data

Classification Levels

The Skpr hosting platform

LevelDescriptionTypical ImpactExamples
OFFICIALNon-sensitive information with low or negligible confidentiality impactMinor business or reputational impact if disclosedGeneral website content, public knowledge base articles
OFFICIAL: SensitiveMedium confidentiality impact. Requires controlled accessLimited operational disruption, reputational damageInternal system designs, infrastructure docs, non-prod credentials
PROTECTEDHigh confidentiality impact. Must comply with ACSC ISMSignificant harm to individuals, clients, or operationsCustomer data, Terraform secrets, production configurations

Controls by Classification

ClassificationStorageAccess ControlTransmissionDestruction
OFFICIALStandard AWS servicesRole-based IAMTLS-encrypted channelsNormal deletion policies
OFFICIAL: SensitiveEncrypted (AES-256), IAM, audit loggingMFA, access logging, mandatory taggingTLS 1.2+ with endpoint validationS3 Object Lock
PROTECTEDEncrypted storage (AWS KMS), loggingFine-grained IAM, audit trailsEncrypted + monitored transmissionISM-compliant sanitisation or key revocation

Roles & Responsibilities

  • Skpr platform team - Oversees implementation and compliance with this policy.
  • PreviousNext Operations Lead - Responsible for the enforcement and auditing of this policy.

Review & Updates

This policy will be reviewed annually or upon significant changes to infrastructure or regulatory requirements.