Answer: I'm assuming that by data classification you mean information classification. Considering that, the template that covers information classification is the "Information Classification Policy", which is located in folder 08 Annex A ==A.8 Asset management
2 - And in addition - vulnerability ,management process? Can't find these docs in the package.
Answer: The vulnerability management is not a mandatory document according to ISO 27001, nor is it a document commonly adopted by organizations (most of them rely on outsourced services for this purpose), so it is not included in the toolkit, to avoid unnecessary effort to manage the ISMS. If you understand that this document is important to your organization, you can schedule a meeting with one of our experts so he can help you to develop such document.