| Sensitive-data and flow assessment | Sources, fields, classifications, users, purposes, environments, transfers, and control gaps. | Defines where protection is required and where alternative controls may be sufficient. |
| Masking and tokenization policy | Use-case criteria, approved methods, ownership, exceptions, review cycles, and evidence. | Creates a consistent control basis across teams and platforms. |
| Rule and transformation catalogue | Field-level methods, domains, deterministic logic, dependencies, and test conditions. | Supports implementation, repeatability, troubleshooting, and change management. |
| Target architecture and integration design | Control placement, token services, vaults, key management, identity, logging, and resilience. | Clarifies technical dependencies, security boundaries, and operating responsibilities. |
| Validation and acceptance pack | Privacy, utility, integrity, performance, compatibility, recovery, and exception test evidence. | Supports accountable approval before rollout or production use. |
| Operating model and runbook | Roles, support, monitoring, release, incident, access, reconciliation, and review procedures. | Enables sustainable operation after implementation. |