Hunter Storm Information Classification
Information classification is the process of identifying and labeling information according to characteristics such as sensitivity, confidentiality, handling requirements, legal or regulatory obligations, and potential impact.
This approach follows established information-security and information-governance practice rather than creating a proprietary vocabulary where established terminology already exists.
NIST’s current work describes data classification as discovering, identifying, and labeling sensitive data, including unstructured information. ISO’s current information-classification standards use the broader concept of information classification, marking and handling (ICMH).
Classification is a Property of Information
Data classification answers:
How should this information be treated?
It does not answer:
- What record is this?
- What happened?
- What corpus does it belong to?
- Who created it?
- Who is responsible for it?
- What external system references it?
Those questions are handled by other metadata.
Use Established Terminology
Where an established classification vocabulary is appropriate to the information being classified, that terminology is used rather than creating a Hunter Storm-specific substitute.
Depending on the information and governing requirements, established classifications may include terms such as:
- Public
- Internal
- Confidential
- Restricted
- Controlled Unclassified Information (CUI)
- Unclassified
- Confidential
- Secret
- Top Secret
These terms do not constitute one universal ladder. The same word may have materially different definitions in different classification regimes.
Classification, Marking, and Handling
Classification establishes the applicable sensitivity or protection category.
Marking makes that classification visible to people and systems.
Handling requirements establish what may be done with the information.
These functions should remain distinguishable even when implemented together.
Corollary Classifications
A classification may have one or more corollaries in other established information-classification systems.
A corollary is provided to help people from another professional, governmental, legal, technical, or organizational environment understand the approximate position or function of a classification within their own conceptual framework.
A corollary is not a conversion.
For example, an information item classified as “Confidential” in one organizational scheme cannot automatically be treated as U.S. national-security Confidential information. Under Executive Order 13526, U.S. national-security classification is a specific government classification system with three levels: Confidential, Secret, and Top Secret, and those terms have defined national-security meanings.
Similarly, CUI is not simply another level on the Confidential → Secret → Top Secret ladder. CUI is a separate controlled-information regime for information requiring safeguarding or dissemination controls but excluded from national-security classified information.
Corollary Relationship Types
Where useful, external classifications may be identified as:
- Equivalent — substantially the same defined concept
- Near-equivalent — substantial overlap but material differences remain
- Broader — the external classification encompasses the Hunter Storm classification
- Narrower — the external classification represents a subset
- Analogous — similar purpose or sensitivity concept, but not equivalent
- Related — relevant to the same information-handling problem without a direct correspondence
- No direct corollary — no responsible comparison has been identified
Classification Corollary Matrix
| Information Classification / Handling Concept | Corporate / Information-Governance Context | U.S. National-Security Context | CUI / Federal Controlled-information Context | Relationship |
|---|---|---|---|---|
| Public | Public / approved for public disclosure | Unclassified may be public, but is not synonymous with public | Generally outside CUI | Contextual, not equivalent |
| Internal | Internal / internal-use information | May remain Unclassified | May or may not be controlled | Contextual |
| Confidential | Confidential information | Confidential has a specific national-security meaning | May involve protected information, but CUI is not a national-security classification | Similar word; not automatically equivalent |
| Restricted | Restricted / limited-access information | No direct national-security classification equivalent | May overlap conceptually with controlled information | Analogous |
| Highly Restricted | Specially controlled / need-to-know information | May resemble the handling concept associated with higher-sensitivity information | May require enhanced controls depending on governing authority | Analogous, not equivalent |
This matrix is an orientation aid. The authoritative definition is always the definition belonging to the classification system under which the information is actually governed.
Governing Principle
Use established classifications where established classifications exist. Do not manufacture equivalence where none exists.
Hunter Storm Records Management System Core Architectural Resources
- About Hunter Storm Numbering Classification System (HSCNS)
- Classification Taxonomy and Government Crosswalk
- Corpus Scale and Technical Continuity Governance Standard | Ecosystem Standard
- Hunter Storm Classification System (HSCS)
- Hunter Storm Classification Numbering System (HSCNS)
- Hunter Storm Classification Numbering System (HSCNS) Cross-Reference and External Numbering
- Information Classification
- Information Classification Taxonomy
- Information Security Governance
- Document Governance
- Ecosystem Publication and Identifier Standard
- Hunter Storm Records Management System (HSRMS)
- Version Governance Standard | Ecosystem Standard
Discover More from Hunter Storm
- Confidential Contact, Consultation, or Engagement Request Form
- Hunter Storm | CV and Competency-Mapped Professional Portfolio Novel Framework
- Hunter Storm Official Site
- Information Security Governance
- StormWatch | Lessons from the CISA ChatGPT Incident
