Skip navigation

Classification

Data classification, in the context of information security, is the classification of data based on its level of sensitivity and the impact to the University should that data be disclosed, altered or destroyed without authorization. The classification of data helps determine what baseline security controls are appropriate for safeguarding that data.  All institutional data should be classified into one of three sensitivity levels, or classifications:

A. 

Restricted Data

 

Data should be classified as Restricted when the unauthorized disclosure, alteration or destruction of that data could cause a significant level of risk to the University or its affiliates. Examples of Restricted data include data protected by state or federal privacy regulations and data protected by confidentiality agreements.  The highest level of security controls should be applied to Restricted data.

Restricted Data includes but is not limited to:

  • First name or first initial, and last name in combination with one or more of the following:
    • Social security number
    • Driver's license number
    • State identification number
    • Financial account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account
    • Medical information
    • Health insurance information

PCI Data is defined by the Payment Card Industry Security Council as: 

  • A Credit Card number (primary account number or PAN) and one or more of the following:
  • Cardholder Name
  • Service Code
  • Expiration Date

B. 

Private Data

 

Data should be classified as Private when the unauthorized disclosure, alteration or destruction of that data could result in a moderate level of risk to the University or its affiliates. By default, all Institutional Data that is not explicitly classified as Restricted or Public data should be treated as Private data.  A reasonable level of security controls should be applied to Private data.

C. 

Public Data

 

Data should be classified as Public when the unauthorized disclosure, alteration or destruction of that data would results in little or no risk to the University and its affiliates. Examples of Public data include press releases, course information and research publications.  While little or no controls are required to protect the confidentiality of Public data, some level of control is required to prevent unauthorized modification or destruction of Public data.


Classification of data should be performed by an appropriate Data Steward. Data Stewards are senior-level employees of the University who oversee the lifecycle of one or more sets of Institutional Data. See Information Security Roles and Responsibilities for more information on the Data Steward role and associated responsibilities.

Your Next Step is Within Reach.

With over 135 years of excellence and 70,000 alumni, we provide an extraordinary education that’s within your reach.