Determine the data classification, security impact level, and TX-RAMP scoping for an IT product or information resource — in one guided workflow.
This guided tool covers three TAMU IT security assessments in a single workflow:
Data Classification, Impact Level, and
TX-RAMP
scoping. You can run all three or just the ones you need. Answer each question and the next
will appear automatically. A report can be downloaded when you finish.
Nothing you enter is saved or transmitted. Every answer stays in your browser and is lost when you close or refresh this page.
Cloud Service Determination
Two determinations, in order: whether this is a cloud computing service at all, and if so, which service model delivers it.
Part 1 — Is it a cloud computing service?
TX-RAMP Program Manual Section 5.1.1 lists five essential characteristics, drawn from NIST SP 800-145. A cloud computing service exhibits all five.
Answer the five questions above to see whether this is a cloud computing service.
Part 2 — Which service model?
Section 5.1.2. The model turns on how much of the stack your unit manages.
Answer the questions above to see which service model applies.
Data Classification
Answer these questions in plain terms and we'll tick the matching boxes above for you.
Answer the questions above to see which frameworks may apply.
Answer these questions and we'll determine which special controls apply.
Answer the questions above to see which controls apply.
Impact Assessment
Effect of unavailability or compromise
For each item below, indicate what would happen if this resource were unavailable or compromised. The impact level is set by the most severe outcome that applies, following the TAC §202.5 impact designation criteria.
TX-RAMP Scoping
Possible exemption from TX-RAMP certification
Is the confidential information negligible?
TAMU defines negligible confidential data as University-Confidential data that, if its confidentiality, integrity, or availability were compromised, would have no adverse effect on university assets, university operations, or any individual — and that contains no regulated data, personally identifiable information (PII), or human-subject data. All four questions below must be answered "No" to qualify.
Answer the four questions above to see whether this data qualifies as negligible.
Assessment Complete
Cloud Service
—
Data Classification
—
Impact Level
—
TX-RAMP
—
Cloud Service Determination
Data Classification
Impact Level
TX-RAMP Determination
Enter Your Name
Your name is recorded in the footer of the report and is required to download it.
Please enter your name to download the report.
About this tool
This combined assessment integrates the TAMU
Data Classification Calculator (based on the TAMU Data Classification Policy),
the Impact Calculator (based on TAC §202.5 impact designation criteria), and the
TX-RAMP Scoping Calculator (implementing the scoping decision tree from DIR's
TX-RAMP Scoping Tool
and the TX-RAMP Program Manual v4.0, February 2026).
Individual calculators are also available for standalone use.
For questions, contact TAMU IT Security & Risk.