Data Classification
Applicability & Scope
This procedure applies to all data stored, processed, or transmitted on any information resources where university business occurs. This includes:
- Local physical servers and databases.
- Cloud-hosted repositories (e.g., Office 365, Google Workspace, AWS, Azure).
- Departmental or individual endpoint devices (laptops, workstations, mobile devices).
- Third-party, vendor-managed, or external contract-operated platforms.
Classification Level Matrix
| Classification Level | Policy Reference | Sensitivity & Impact | Examples |
|---|---|---|---|
| Public | DC-3 | Low Sensitivity: Openly available. Loss of confidentiality has zero negative impact. Focus is solely on availability and preventing unauthorized modifications. | Public course catalogs, marketing websites, public directory details, press releases. |
| University-Internal | DC-4 | Moderate Sensitivity: Accessible to eligible employees for business functions. Not publicly broadcasted, but may be releasable under public records requests (e.g., open records laws) after appropriate legal review. | Internal memos, departmental budgets, technical configuration drafts, non-sensitive internal emails. |
| University-Confidential | DC-5 | High Sensitivity: Access restricted by legal, ethical, or contractual constraints. Unauthorized exposure causes significant operational, reputational, or academic harm. | FERPA-protected student records, proprietary research details, personnel files, unreleased financial statements. |
| Critical | DC-6 | Extreme Sensitivity: Unauthorized disclosure likely leads to criminal/civil penalties, significant financial liability, or severe institutional damage. Strictly restricted access. | Social Security Numbers (SSNs), HIPAA-protected patient health records, Credit Card data (PCI-DSS), Export Controlled technology (ITAR). |
Ownership and Responsibility
The Information Resource Owner (usually a section or program leader, principal investigator, or system administrator) is responsible for each data store or system. They are ultimately responsible for making sure their data is classified and protected accordingly.
Use the Data Classification Tool to determine the level of data you have.
Application of Controls
Based on the data level defined in the Policy Reference section above each data type has an Implementation section in the policy. The Information Resource Owner is responsbible for applying the controls as defined.
Technology Services - PVFA, maintains PVFA Operated Services Data Classifications as part of the CLEAR process. The CLEAR status of each service is documented in our internal Service Information pages.