Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The State University of New York at Fredonia ("Fredonia") is committed to the confidentiality, integrity, and availability of information important to the University’s mission. All University data must be classified into one of three categories described in this policy and protected using the appropriate security measures consistent with the minimum standards for the classification category as described in related information/data security policies.

 


POLICY

Fredonia has classified its physical and electronic data into three risk-based categories for the purpose of determining who is allowed to access the information and what security precautions must be taken to protect it. This policy facilitates applying the appropriate security controls to university data, and assists data owners in determining the level of security required to protect data on the systems for which they are responsible.

...

Data Risk Classification Category

Category 2 - Private

Minimum Security Standard

 800-53 Moderate

Risk from Disclosure

Moderate

Definition

  • Includesuniversity data not identified as Category 3 Data, but includes data protected by state and federal regulations. This includes FERPA-protected student records and electronic records that are specifically exempted from disclosure by the New York State FOIL
  • Private data must be protected to ensure that it is not inadvertently or unnecessarily disclosed in a FOIL request. FOIL excludes data that if disclosed would constitute an unwarranted invasion of personal privacy.
  • The NIST Special Publication 800-171. Protecting Controlled Unclassified. Information in Non-federal Information Systems and Organizations maps to the Category 2 - Private data risk classification.

Examples

  • FERPA-protected data
  • Gramm-Leach Bliley data
  • Final course grades, exam questions or answers
  • HR employment data
  • Law enforcement investigation data, judicial proceedings data includes student disciplinary or judicial action information
  • Public Safety information
  • IT infrastructure data
  • Collective bargaining negotiation data, contract negotiation data
  • Trade secret data
  • Protected data related to research
  • University intellectual property
  • University proprietary data
  • Data protected by external non-disclosure agreements 
  • Inter- or intra-agency data which are not: statistical or factual tabulations; instructions to staff that affect the public; final agency policy or determination
  • External audit data
  • University person number (e.g. Fredonia ID "FID", PDIM)
  • Performance Programs and Evaluations
  • Travel Authorizations and Reimbursement Forms
  • Brass Key Forms and Inventories
  • Search Committee Documents
  • Licensed software
  • Certain nonpublic Intellectual Property

...

This policy applies to all members of the university community, as well as to 3rd parties who handle university data. 


CONTACT INFORMATION

Office of Information Technology Services and Finance and Administration, Maytum Hall, Fredonia, NY, 14063.

...