Skip to content
SALARAProof Space

PROOF SPACE

Experience Organizational Intelligence

See how SALARA turns a policy document into activated Organizational Intelligence, then ask a question and Replay the evidence behind the answer.

  • Policy document source
  • Activated intelligence only
  • Deterministic Runtime
  • Replayable evidence

What you are doing

  1. Choose a documentStart from an activated policy source.
  2. Inspect the contentReview the governed statements SALARA compiled.
  3. Ask a questionReceive a deterministic answer and open Replay.

Policy document experiences

Choose a document

Each available document is backed by activated Organizational Intelligence.

Document content

What SALARA activated

These approved statements are the content Runtime can use. Answers stay inside this activated boundary.

Information Security · Activated document

Data Classification and Handling Standard

31 approved statements · DOC-SEC-0005 · SRC-6E538DE827A73F0439799AD79070
  1. - Export-controlled technical data requires an export determination before storage.

    ASSERT-1A70DB26514B0B175AA05D4834D2FD99 · v1
  2. - This standard is reviewed each January by the CISO.

    ASSERT-21C9995A563AADC0D342E9F2FE009158 · v1
  3. - An unmarked deliverable may not leave a Compass One system boundary.

    ASSERT-2536D8D31E98EE88E3F2DEC27D1FCA94 · v1
  4. - Compass One prohibits storage of export-controlled technical data in shared drives.

    ASSERT-2D24D8B1AE3BCFB72EB3ED97CB95CB15 · v1
  5. - A covered defense information incident requires Government reporting within seventy two hours.

    ASSERT-3DDA2EB9C68AC6078C955D285523C908 · v1
  6. - External sharing of commercial information requires data owner approval.

    ASSERT-4987E2F685AC43EE41526B8684E32201 · v1
  7. - A non-disclosure agreement must exist before any external sharing of proprietary information.

    ASSERT-4B26B58164B62B941E1C5F6069778511 · v1
  8. - Every information asset must carry one of seven Compass One information classes.

    ASSERT-55A9BF474619AE2D17883694EB7C87DA · v1
  9. - Every report must follow the incident reporting procedure in DOC-SEC-0002.

    ASSERT-5937B802C55DC77ECAC6EE0A993DE66F · v1
  10. - Transmission of controlled unclassified information requires an approved encrypted channel.

    ASSERT-6BEC15C8852C4BC3C1F87B68AA544F09 · v1
  11. - A contract instruction overrides this standard whenever the contract is stricter.

    ASSERT-6CE521344337D502879C400804256FF0 · v1
  12. - Compass One prohibits storage of controlled unclassified information in chat platforms.

    ASSERT-6E1462E38F79B981C06809060C59CFE0 · v1
  13. - The marking must cite the contract clause that imposes the control.

    ASSERT-7019A23F71B73794B33B7DA2B82588F9 · v1
  14. - Controlled unclassified information must reside in an approved enclave.

    ASSERT-7403477E8FAD5D7625A341CF69AB1757 · v1
  15. - Marking is applied by the document author at creation.

    ASSERT-7A90AFB21D8324252AC793FF6ECFE66F · v1
  16. - A suspected disclosure of controlled unclassified information must be reported within one hour.

    ASSERT-93A7EF042F3C8D5635CA1C125F50A951 · v1
  17. - Covered defense information must reside in a program approved enclave.

    ASSERT-A27DDFD546E9140D6A873CA4DA501A28 · v1
  18. - The owning department owns the classification of internal proprietary information.

    ASSERT-A299A30431865F94C956C3A552BD27CF · v1
  19. - Compass One retains federal contract information for the full contract retention period.

    ASSERT-AA788408CB56930E02F2AED849CDF989 · v1
  20. - Physical media holding controlled unclassified information must be shredded by approved means.

    ASSERT-AD4A415D1D0B9F0573BE4FE38E03246D · v1
  21. - A named access list is required for every controlled unclassified information repository.

    ASSERT-B7A97286B4BF74F38E41838E4AF82E64 · v1
  22. - Unmarked information is treated as internal proprietary information by default.

    ASSERT-B8F2F436774AD1B977DB070A96ED8882 · v1
  23. - The Compliance function owns the classification of controlled unclassified information.

    ASSERT-BEC9C5C6AFC7A04B7A66A3950B112AB8 · v1
  24. - Personal email accounts are prohibited for every Compass One information asset.

    ASSERT-BFF725D5D3703AECCB1B695C7BE68A26 · v1
  25. - Access to program-scoped information is granted by program boundary rather than job title.

    ASSERT-C79E206B7D054CC8D526AA5B7F82B7E8 · v1
  26. - Disposal of controlled unclassified information requires a recorded certificate of destruction.

    ASSERT-C7A297E8C35745985004E4A67006685B · v1
  27. - Internal proprietary information may reside in the standard document repository.

    ASSERT-CE0EC19389DDB7BFF9EBC58DBB53FBAD · v1
  28. - Every document containing controlled unclassified information must carry a visible marking.

    ASSERT-DAD7FDAF220DE0F3C861CB629A2FE3B2 · v1
  29. - The CISO owns this standard.

    ASSERT-DEBF8C8BB3C9A8D2F04A671F75A7C59C · v1
  30. - Contract-delivered federal material is treated as federal contract information by default.

    ASSERT-F47534367768226E75D8B49CEE47BA98 · v1
  31. - This standard applies to all employees, contractors, and temporary workers.

    ASSERT-FBEDAAA9129B76A4D86EC0D907FC4CBB · v1

From the activated intelligence

Suggested questions

These examples are derived deterministically from approved Assertions in the active compiled artifact.

Activated-OI question

What does the policy say about - Export-controlled technical data requires an export determination before storage?

Ask this question
Activated-OI question

What does the policy say about - This standard is reviewed each January by the CISO?

Ask this question
Activated-OI question

What does the policy say about - An unmarked deliverable may not leave a Compass One system boundary?

Ask this question
Activated-OI question

What does the policy say about - Compass One prohibits storage of export-controlled technical data in shared drives?

Ask this question
Activated-OI question

What does the policy say about - A covered defense information incident requires Government reporting within seventy two hours?

Ask this question
Activated-OI question

What does the policy say about - External sharing of commercial information requires data owner approval?

Ask this question

One discipline, four ways to explore

Learn. Understand. Experience. Explore.

Handbook
Learn the discipline.
Guide
Understand the concepts.
Proof Space
Experience Organizational Intelligence.
Research Library
Explore the supporting evidence.