# Data Security Delivery Pack

Skill: `securing-data`

[Word report](report.en.docx) · [Excel register](register.en.xlsx)

## Record details

| ID | Field | Project value |
| --- | --- | --- |
| `artifact_id` | Artifact ID | |
| `project` | Project | |
| `skill` | Skill | |
| `version` | Version | |
| `date` | Date | |
| `status` | Status | |
| `author` | Author | |
| `owner` | Owner | |
| `approver` | Approver | |
| `purpose` | Purpose | |
| `business_outcome` | Business outcome | |
| `scope` | Scope and exclusions | |
| `source_inputs` | Inputs and sources | |
| `assumptions` | Assumptions and constraints | |
| `decisions` | Decisions | |
| `rationale` | Rationale | |
| `risks` | Risks | |
| `exceptions` | Exceptions | |
| `open_items` | Open items | |
| `due_date` | Due date | |
| `acceptance_criteria` | Acceptance criteria | |
| `evidence_location` | Evidence location | |
| `reviewer_decision` | Reviewer decision | |
| `next_gate` | Next stage gate | |

## Domain analysis and decisions

### Security scope and responsibility (`scope`)

Define assets, processing chain, vendors, and shared-responsibility boundaries.

> Enter project evidence, conclusion, and owner.


### Data and risk classification (`classification`)

Classify data and handling requirements by use, sensitivity, and potential harm.

> Enter project evidence, conclusion, and owner.


### Threats and exposure (`threats`)

Record threat paths, exposure, existing controls, and residual risk.

> Enter project evidence, conclusion, and owner.


### Identity and access design (`access_design`)

Define least privilege, revocation, and denied paths by subject, data, and action.

> Enter project evidence, conclusion, and owner.


### Controls and negative tests (`control_tests`)

Cover encryption, masking, non-production data, export, audit, and unauthorized-access tests.

> Enter project evidence, conclusion, and owner.


### Monitoring incidents and response (`incident`)

Set logging, alerts, incident severity, escalation, and review evidence.

> Enter project evidence, conclusion, and owner.


### Exceptions and residual risk (`residual_risk`)

State exception approval, compensating controls, expiry, and review.

> Enter project evidence, conclusion, and owner.


### Gates and acceptance (`acceptance_evidence`)

List control-test, role-approval, and operations-handoff evidence.

> Enter project evidence, conclusion, and owner.


## Working registers

### Access Matrix (`access`)

Record subject-data-action permissions and denials.

| Subject (`subject`) | Data scope (`data`) | Action (`action`) | Decision (`decision`) | Owner (`owner`) | Approver (`approver`) | Evidence (`evidence`) |
| --- | --- | --- | --- | --- | --- | --- |
|   |   |   |   |   |   |   |

### Control Tests (`control_tests`)

Track control effectiveness and remaining exceptions.

| Control (`control`) | Test (`test`) | Test result (`test_result`) | Exception (`exception`) | Owner (`owner`) | Evidence (`evidence`) | Review date (`review_date`) |
| --- | --- | --- | --- | --- | --- | --- |
|   |   |   |   |   |   |   |
