Educause Security Discussion mailing list archives

Re: Data Classification: Legal criteria


From: David Kovarik <david-kovarik () NORTHWESTERN EDU>
Date: Tue, 18 Mar 2008 13:50:28 -0500

Here's what we've defined...

http://www.it.northwestern.edu/policies/dataaccess.html


Dave Kovarik, ISS/C
Northwestern University
Office: (847) 467-5930

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Basgen, Brian
Sent: Tuesday, March 18, 2008 1:04 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Data Classification: Legal criteria

 We are in the process of developing a data classification policy with three
types: public, internal, and confidential.

 The criteria or logic behind classifying confidential data is fairly
easy: FERPA, GLBA, PCI, etc, requires the confidentiality of certain data
types. Yet, I am not clear on the best external criteria to use for
classification of internal data. Peer institutions, "best practices" is one
thought, but I'm wondering what other objective criteria people have
employed for the justification of making certain kinds of data internal as
opposed to public. Let me know, thanks.

~~~~~~~~~~~~~~~~~~
Brian Basgen
Information Security
Pima Community College



Current thread: