Background:
In accordance with the binding requirements of federal laws, state laws, and CSU policies that govern how private and confidential data are collected, managed and protected, Humboldt State University recognizes its affirmative and continuing obligation to provide appropriate administrative, technical and physical safeguards to protect such university information assets.
Unauthorized use, access, disclosure, or acquisition of private or confidential information could result in severe damage to HSU, its students, employees or customers. Financial loss, damage to HSU’s reputation and legal action could result.
Security precautions and procedures for protecting private and confidential data are necessary.
Data Classification Standards:
The CSU Information Security Advisory Committee and information security staff from the Chancellor’s Office have defined data classification standards as follows (see Appendix A):
Policy:
Neither Level 1 Confidential data nor Level 2 Private data shall be stored on university–owned personal computers (desktop or laptop), other electronic storage media (e.g., cd, dvd, or flash drive) or other electronic devices (e.g., PDAs, smart phones) without the express written approval of the President or his designee. Approval shall only be granted in order to accomplish specific tasks identified as absolutely necessary to conducting the business of the University. The data shall be removed when the business reason no longer exists.
This policy applies to:
Managers for work groups with the same protected data storage requirements may request approval for the entire group on a single approval form. Level 2 Private data for students enrolled in the current semester may be stored on a local computer for the current term only. At the end of the term, such data shall be removed to an appropriate, secure archive medium and location.
Under no circumstance shall Level 1 Confidential data be stored on computers, other storage media, or other electronic devices not owned by the California State University, its auxiliaries or its foundations.
Devices containing Level 1 Confidential or Level 2 Private data may not be used for any purpose by any person not employed by the University.
Additional information on this policy can be found at: http://www.humboldt.edu/its/security-protectedinformation/.
Storage and System Security Requirements:
When storage on computers, other storage media, or other electronic devices is approved, the following additional minimum requirements must be met:
Disposal requirements:
Any computer, other storage media, or other electronic device which stores Level 1 Confidential or Level 2 Private data must be sanitized prior to disposal or re-use in accordance with the campus procedures for destruction of media.
Reporting Loss or Theft:
Theft or loss of computers, other storage media, or other electronic devices that contain Level 1 Confidential or Level 2 Private data must be reported to (1) the employee’s appropriate administrator, (2) University Police and (3) the Office of Information Security. When the loss or theft of a computer, other storage media, or other electronic device is reported, the presence of Level 1 Confidential or Level 2 Private data must be indicated. If stolen off-campus, local law enforcement must be notified and a police report obtained.
Periodic Review:
The Office of Information Security will conduct periodic audits to determine if Level 1 Confidential and Level 2 Private data are being appropriately protected on university owned equipment.
Appendix A – CSU Data Classification Standard, Level 1 Confidential
Description
Level 1 Confidential information is intended solely for use within HSU and is limited to those with a “business need-to know.”
Statutes, regulations, other legal obligations or mandates protect much of this information.
Disclosure of Level 1 Confidential information to persons outside of the University is governed by specific standards and controls designed to protect the information.
Unauthorized use, access, disclosure, or acquisition of private or confidential information could result in severe damage to HSU, its students, employees or customers. Financial loss, damage to HSU’s reputation and legal action could result.
Level 1 Confidential information is typically exempt from disclosure under the California Public Records Act or other applicable state or federal laws.
Examples
Appendix B – CSU Data Classification Standard, Level 2 Private
Description
Level 2 Private information should be protected due to FERPA, proprietary, ethical, or privacy considerations.
Although not specifically protected by statute, regulations, or other legal obligations or mandates, unauthorized use, access, disclosure or acquisition of information could cause financial loss, damage to HSU’s reputation, violate an individual’s privacy rights, or make legal action necessary.
Examples
Name in combination with:
Employee Information (including student employees):
Other:
Student Information-Educational Records (non-directory):
Appendix C – CSU Data Classification Standard, Level 3 Public
Description
This is information that is generally regarded as publicly available. Information at this level is either explicitly defined as public information, or is intended to be available to individuals both on and off campus, or is not specifically classified elsewhere in this standard. Knowledge of this information does not expose the CSU to financial loss or jeopardize the security of HSU’s information assets.
Level 3 Public information may be subject to appropriate campus review or disclosure procedures to mitigate potential risks of inappropriate disclosure.
Examples
Campus Identification Keys:
Student Directory Information: (unless a student requests in writing that their directory information not be released, resulting in a “confidentiality flag” being set in their CMS record)
Employee Information (including student employees):
Office of the President • 1 Harpst St., Arcata, CA 95521 • 707.826.3311• Contact Us.