DRAFT: Data Classification Standard

Tags Standard

Purpose

This standard establishes the University's data classification model and the minimum requirements for handling, protecting, storing, transmitting, retaining, sharing, and disposing of University data.

Data classification provides a consistent framework for applying appropriate security, privacy, operational, legal, contractual, and regulatory controls throughout the data lifecycle.

Data classification is independent of workload classification. Data classification identifies the sensitivity of data. Workload classification determines the governance and control baseline applicable to the systems that process that data.

Scope

This standard applies to:

  • University information assets
  • Applications
  • Databases
  • Data platforms
  • File storage systems
  • Cloud services
  • Software-as-a-Service solutions
  • Integration platforms
  • Paper records containing University data
  • Third-party systems processing University data

Data Classification Categories

The University recognizes four data classifications:

  1. Public
  2. Sensitive/Internal
  3. Highly Sensitive
  4. Restricted

Public Data

Definition

Information approved for public disclosure that may be freely distributed without adverse impact to the University, its students, employees, partners, or operations.

Examples

  • Published websites
  • Public reports
  • Marketing materials
  • Public research publications
  • Published institutional information

Protection Requirements

  • Protection against unauthorized modification
  • Protection against accidental destruction
  • Appropriate backup and recovery measures

Sensitive/Internal Data

Definition

Information intended for internal University use that is not approved for public disclosure but would generally cause limited risk if improperly disclosed.

Examples

  • Internal communications
  • Operational documentation
  • Internal procedures
  • Administrative records
  • Non-public business information

Protection Requirements

  • Authenticated access
  • Protection from unauthorized disclosure
  • Appropriate access controls
  • Protection during transmission
  • Retention and disposal according to approved processes

Highly Sensitive Data

Definition

Information that could result in significant institutional, legal, financial, operational, or reputational impact if improperly disclosed, modified, destroyed, or unavailable.

Examples

  • Protected personnel information
  • Confidential financial information
  • Sensitive institutional records
  • Confidential business information
  • Other information designated as Highly Sensitive by policy or governance processes

Protection Requirements

  • Strong authentication controls
  • Role-based authorization
  • Least privilege access
  • Monitoring and auditability
  • Data protection controls
  • Encryption when stored or transmitted where supported
  • Documented ownership and stewardship

Restricted Data

Definition

Information subject to legal, regulatory, contractual, research, export-control, licensing, or institutional requirements that impose specific restrictions on access, handling, transmission, retention, disclosure, storage, or disposal.

Examples

  • Protected Health Information (PHI)
  • Controlled Unclassified Information (CUI)
  • Criminal Justice Information (CJI)
  • Export-controlled information
  • Contractually restricted information
  • Other data designated as Restricted through policy, contract, or regulation

Protection Requirements

  • Compliance with applicable legal and regulatory requirements
  • Enhanced access controls
  • Enhanced monitoring and auditability
  • Data protection controls
  • Approved retention and disposal processes
  • Documented ownership and stewardship
  • Formal governance oversight where required

Data Ownership and Stewardship

All University data shall have identified ownership and stewardship responsibilities.

Data owners are responsible for:

  • Approving access
  • Determining appropriate use
  • Supporting classification decisions
  • Reviewing classification when business requirements change

Data stewards are responsible for:

  • Data governance activities
  • Data quality activities
  • Lifecycle management activities
  • Protection requirement implementation support

Classification Requirements

Data shall be classified according to applicable legal, regulatory, contractual, research, institutional, and business requirements.

When multiple classifications could apply, the highest applicable classification shall be used.

Data derived from classified data shall inherit the required protections of the originating data unless formally reviewed and reclassified.

Data Protection Requirements

Data protection requirements shall be determined according to the assigned classification and applicable policies, standards, regulations, and contractual obligations.

Protection controls may include:

  • Authentication
  • Authorization
  • Encryption
  • Monitoring
  • Audit logging
  • Backup and recovery
  • Retention management
  • Secure disposal

Retention and Disposal

Data shall be retained and disposed of according to applicable University policies, regulatory obligations, contractual obligations, and records management requirements.

Data that is no longer required shall be disposed of using approved disposal processes appropriate for the assigned classification.

Classification Review

Data classifications shall be reviewed when:

  • New data is introduced
  • Business requirements change
  • Regulatory requirements change
  • Contractual obligations change
  • Institutional requirements change
  • The nature of the data materially changes

Exceptions

Exceptions to this standard require documented approval through the approved exception process.