51°µÍø

Appendix A: Data classifications

51°µÍø data

51°µÍø data is any data related to 51°µÍø (51°µÍø) operations that is

  1. Stored on 51°µÍø information technology systems
  2. Physically recorded and stored on 51°µÍø premises
  3. Maintained by 51°µÍø faculty, staff, or students
  4. Related to institutional processes on or off campus

Critical versus non-critical

51°µÍø Data is either critical or non-critical:

Non-critical data is information considered public and non-confidential in nature. Non-critical data is not subject to protection or data handling procedures.

Critical data is information considered valuable to some degree to 51°µÍø. Classification of critical data varies based on the context and use case with respect to the value of the information, the degree of protection required, and the degree of damage that unauthorized disclosure would cause. Critical information is not releasable on demand without due process.

Some examples of critical data are:

  • Personally Identifiable Information (PII)
  • Financial account numbers
  • Passwords
  • Information that may have a derogative impact on 51°µÍø, staff or students of 51°µÍø
  • Internal communications that may have a derogative impact on 51°µÍø operations if sent to someone without a need to know
  • Health-related information
  • Any information deemed confidential, restricted or academically sensitive

Critical data classifications

The following are the most common terms and classifications of critical data in use at 51°µÍø:

Personally identifiable information (PII)

A commonly used security industry term that describes any data that could potentially identify a specific individual. PII is any information that can be used to distinguish one person from another and can be used for de-anonymizing anonymous data. PII may be a single unit of data (e.g. a social security number) or may result from the combining of related pieces of information (e.g. a user name and password).

GLBA covered information

51°µÍø is required to protect covered customer data in accordance with the Gramm Leach Bliley Act (GLBA). GLBA defines covered customer information as any record containing nonpublic personal information or personally identifiable financial information about a customer of 51°µÍø – whether in paper, electronic, or other form – that is handled or maintained by or on behalf of 51°µÍø or its affiliates.

GLBA nonpublic personal information

Nonpublic personal information is GLBA’s terminology for customer data covered by the regulation. It includes:

  • Any list, description, or other grouping of consumers (and publicly available information pertaining to them) that is derived using any personally identifiable financial information that is not publicly available
  • Any information a student or other third party provides in order to obtain a financial service from 51°µÍø
  • Any information about a student or other third party resulting from any transaction with 51°µÍø involving a financial service
  • Any information otherwise obtained about a student or other third party in connection with providing a financial service to that person

Examples of nonpublic personal information include (but are not limited to):

  • Social Security number
  • Credit card number
  • Account numbers
  • Account balances
  • Any financial transactions
  • Tax return information
  • Driver’s license number
  • Date or location of birth

Examples of services or activities that 51°µÍø may offer, which result in the creation of nonpublic personal information, could include (but are not limited to):

  • Student (or other) loans, including receiving application information and the making or servicing of such loans
  • Credit counseling services
  • Collection of delinquent loans and accounts
  • Check cashing services
  • Obtaining information from a consumer report
Protected data

Information considered valuable to 51°µÍø but not requiring confidentiality controls. Unclassified information may have additional departmental controls on the handling, collection, processing, and/or distribution. Examples of this would include destruction or storage dates/instructions, rare historical documents, copyrighted materials, and special instructions such as conditional access provisions.

Academic data

A classification of critical information controlled for academic purposes to maintain academic freedom. This does not include student personal identification.

Academic data deals with faculty lesson and testing content. This includes but is not restricted to test banks, quizzes, sequential lesson material, answer keys, or research conducted by faculty affiliated with 51°µÍø or research conducted on the premises with other institutions. It also can include information regarding academic thesis research by faculty.

Academic information disclosure can degrade the integrity of grades, the reputation of 51°µÍø, the student body, and faculty as a whole. It can also cause enormous financial losses and penalties due to the illicit exploitation of research.

Internal data

A classification of critical information considered medium to high risk, because the exposure of this information can cause serious harm to 51°µÍø. Information in this category is largely proprietary and operational in nature. This includes information about 51°µÍø-related activities. Examples include detailed information about some information technology infrastructure, 51°µÍø buildings, security procedures, activities or events, information about future 51°µÍø development plans, and grant information.

Confidential data

A classification of critical information considered high risk, either because the exposure of this information can cause tremendous harm to an individual or 51°µÍø or because the information is specifically protected under law or contract (e.g. HIPAA, FERPA, GLBA, PCI, and ORS 646.600 Oregon’s Identity Theft Protection Act). This includes information that can be linked, directly or indirectly, to individual people. Social security numbers, credit card numbers, financial information, personally identifiable medical information, personal addresses, and personally identifiable academic information fall into this category.

Data in these categories will require varying security measures appropriate to the degree to which the loss or corruption of the data would impair the business functions of the 51°µÍø, result in financial loss, or violate law, policy or 51°µÍø contracts.

Controlled sensitive data

An encompassing definition used in 51°µÍøâ€™s Information Security policies that references all confidential and private information governed by those policies. This includes data classified as PII, regulated data (PHI, HIPAA, FERPA, GLBA, etc.), protected, academic, internal or confidential data. In simple terms, any critical personal or sensitive information for which 51°µÍø is liable if publicly disclosed.