Information Classification and Protection Policy
Overview
The Information Classification and Protection Policy (ICPP) defines how University information is classified and how it is to be protected.
1.0 Purpose
Students, faculty, staff, and alumni trust that the University protects their personal information as it exists in any medium — electronic, as well as all forms of paper records. This policy is designed to help each member of the University community do his or her part to fulfill that trust by classifying and protecting University data.
2.0 Applicability
All University faculty, staff, and students shall comply with this policy and any management controls derived from it, as they acquire, communicate, transmit, process, or store information on behalf of the University. The University shall also require that third parties handle University information in accordance with applicable laws and regulations and accept liability for violation of those laws and regulations for any University information that they acquire, communicate, transmit, process, or store on behalf of the University.
3.0 Policy
Managers in the schools and divisions shall periodically inventory all information their offices acquire, communicate, transmit, process, or store and assign it to one of the information classifications defined in this policy. The managers shall then apply and document the appropriate controls for each set of records (e.g., forms, electronic documents, databases, etc.) based on the highest classification of data contained in those records (see currently supported controls in Schedule C and classification/documentation examples in Schedule D).
University information is contained in physical or electronic records. Physical records (which include all forms of paper records and documents) contain information directly readable by humans. Electronic records contain information that requires an electronic device to read the information. Managers shall inventory information regardless of record type.
4.0 Classifications
Information shall be classified in one of the following categories:
Public Data
Public information or data is University information that:
- Is made available to the public.
- Is not classified as RESTRICTED or Confidential.
Confidential Data
Confidential information or data is University information that:
- Is used primarily to conduct official University business with limited internal distribution.
- Contains proprietary information or pertains to student records that are covered by the Family Educational Rights and Privacy Act (FERPA). See Schedule A for further information.
RESTRICTED Data
RESTRICTED information or data is University information that:
- Includes authentication secrets (passwords, private keys). See Schedule A for further examples.
- Makes the University liable for costs or damages due to unauthorized disclosure under laws, government regulations, or contract.
- Pertains to information protected by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). See Schedule A for further information.
Known confidential and restricted data fields are contained within Schedule A.
5.0 Controls
The appropriate control shall be applied to every process used to handle information, according to the classification of that information. The controls include: Acquisition, Access, Network Transmission, Data Processing, Communication, Storage, and Retention/Disposal/Transfer.
6.0 Improper Disclosure or Loss
All faculty, staff, and students shall immediately report inappropriate disclosure or suspected loss of Confidential or Restricted information to their supervisor or IT Tech Central. The supervisor or IT Tech Central shall inform the Information Security Office promptly when loss or improper disclosure of records containing Confidential or Restricted information is suspected or confirmed.
The responsible division head or dean will sign any legally mandated information breach notification letters for information lost or disclosed by their employees.
7.0 Assistance
The Information Security Office shall maintain a matrix of applicable controls by process and information type for use by managers and technical advisors. This matrix shall be considered Schedule B of this policy. A list of recommended technical procedures for implementing encryption and access controls will be maintained by Information Technology and published by the Information Security Office, considered Schedule C of this policy.
For consulting on the classification and control of electronic information, contact the Information Security Office. Information on the classification and control of physical records is available from Risk Management.
8.0 Enforcement
Failure to comply with this policy may result in discipline, suspension, dismissal, and/or legal action.
Revision History
| Action | Dates |
|---|---|
| UMC Approved | 8/2008 |
| Schedule Updates |
12/2012, 07/2015, 11/2018. |
See Also
← Back to Security Policies and Standards.