Data Classification and National Markings

Analog Informatics Corporation (AIC) kits mark records with a classification and enforce who may read or change them. CMMC needs three markings: Unclassified, Federal Contract Information (FCI), and Controlled Unclassified Information (CUI). The kits go further. One marking catalog holds US government, allied, national, and corporate markings, ranked by sensitivity.

Three document tiers of different navy and teal tones separated by controlled access boundaries
Data Classification and National Markings

The classification features are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits.

Short Answers

Does the kit support markings above CMMC?

Yes. The catalog includes US government markings from UNCLASSIFIED to TOP SECRET / SCI, NATO markings, and national markings for several countries. Each family can be turned on or off.

Which national standards are in the catalog?

United States (Executive Order 13526 and 32 CFR Part 2001 levels), NATO, United Kingdom, Canada, Australia, European Union, Germany, and France. Organizations can add their own corporate markings.

Does the kit enforce the markings?

Yes. Each person gets a top clearance. Mandatory access control (MACL) can be off, warn, or enforce. In enforce mode, a person cannot read a record marked above their clearance.

Can a marking be lowered?

Only through a formal release. The release needs a justification, and every release is recorded in an append-only audit trail.

Do markings reach the SIEM?

Yes. The marking can be added to audit log entries, Windows Event Log entries, and syslog events sent to a Security Information and Event Management (SIEM) system.

Marking Families

Family Example Markings
CMMC Unclassified, FCI, CUI, CUI Specified
US government UNCLASSIFIED, CONFIDENTIAL, SECRET, TOP SECRET, TOP SECRET / SCI
NATO NATO UNCLASSIFIED, NATO RESTRICTED, NATO CONFIDENTIAL, NATO SECRET, COSMIC TOP SECRET
United Kingdom OFFICIAL, OFFICIAL-SENSITIVE, SECRET, TOP SECRET
Canada Protected A, Protected B, Protected C, CONFIDENTIAL, SECRET, TOP SECRET
Australia UNOFFICIAL, OFFICIAL, OFFICIAL:Sensitive, PROTECTED, SECRET
European Union RESTREINT UE / EU RESTRICTED, CONFIDENTIEL UE, SECRET UE, TRES SECRET UE
Germany VS-NUR FUR DEN DIENSTGEBRAUCH (VS-NfD), VS-VERTRAULICH, GEHEIM, STRENG GEHEIM
France DIFFUSION RESTREINTE, CONFIDENTIEL DEFENSE, SECRET DEFENSE, TRES SECRET DEFENSE
Corporate Public, Internal, Company Confidential, Trade Secret, and custom markings

The organization decides which families apply to its contracts. The organization's security officer and its government customer decide how classified information must be handled.

How Enforcement Works

  1. Pick a mode. Commercial mode leaves markings blank. CMMC mode shows Unclassified, FCI, and CUI. NIST SP 800-53 mode turns on the government families you choose.
  2. Give each person a clearance. A clearance is the highest marking a person may read. Groups can carry a clearance too.
  3. Mark records. People, groups, systems, shared files, and reports carry a marking. New records get the default marking.
  4. Enforce. The kit follows the rules of the Bell-LaPadula model. A person may not read up. A person may write up. Lowering a marking needs a formal release.
  5. Record everything. Marking changes, releases, and denied reads are audited under NIST SP 800-53 AU-2, AU-3, AU-9, and AC-16.

Screenshots

Choose a classification mode, and carry markings into audit logs and SIEM events.
One marking catalog ranks CMMC, US government, and NATO markings by sensitivity.
National markings for the United Kingdom, Canada, Australia, and more are built into the catalog.
Preview any access decision, and lower a marking only through an audited formal release.
Mandatory access control policies apply marking defaults for a framework in one step.
The document sharing vault stores and shares FCI and CUI with classification markings.

Scope

The kit labels and enforces markings on its own records, shared files, and reports. It is not a cross-domain solution and not an accredited classified network. Classified networks are accredited by the government customer.

Related Controls

Framework Controls
NIST SP 800-53 AC-3, AC-16, AU-2, AU-3, AU-9, MP-3
NIST SP 800-171 3.1.3, 3.8.4
CMMC AC.L2-3.1.3, MP.L2-3.8.4
ISO/IEC 27001 Annex A 5.12, 5.13

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.