Skip to content

Commit

Permalink
Classification: corrections
Browse files Browse the repository at this point in the history
  • Loading branch information
semancik committed Mar 21, 2024
1 parent e28eea4 commit 8563344
Showing 1 changed file with 8 additions and 1 deletion.
9 changes: 8 additions & 1 deletion docs/roles-policies/classification/index.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ compliance:
description: 'Example demonstrating use of policy rules to enforce classification requirements'
'5.14':
description: 'Description of an idea for limiting access to internal information using classification scheme'
'5.16':
description: 'Management of user clearances'
---
= Information Classification and Clearances
:page-toc: top
Expand Down Expand Up @@ -301,7 +303,12 @@ E.g. certify access to category III systems every 6 months, certify access to ca
// TODO: create an example for this, after 4.9 when new certification settles in.
// TODO: Refer from ISO 27001 5.13

* As classifications (labels) and clearances are assigned to relevant objects using ordinary feature:assignment[assignments], feature:access-certification[access certification] features can be used to regularly re-certify the classifications and clearances. Furthermore, the feature:schema-activation[activation mechanisms] of the assignment can be used to assign clearances for a limited time period.
* As clearances are assigned to users using ordinary feature:assignment[assignments], feature:access-certification[access certification] features can be used to regularly re-certify the clearances. Furthermore, the feature:schema-activation[activation mechanisms] of the assignment can be used to assign clearances for a limited time period.
// TODO: create an example for this, after 4.9 when new certification settles in.
// TODO: Refer from ISO 27001 5.6

// TODO * As classifications (labels) are assigned to relevant objects using ordinary feature:assignment[assignments], feature:access-certification[access certification] features can be used to regularly re-certify the classifications.
// TODO: we need ability to replace assignment in certification, not just removal of assignment
// TODO: create an example for this, after 4.9 when new certification settles in.
// TODO: Refer from ISO 27001 5.12

Expand Down

0 comments on commit 8563344

Please sign in to comment.