Purpose The 91直播 of Maryland Global Campus ("91直播") maintains a vast amount of Information to support its administrative and educational activities. Data Classification plays a critical role in the 91直播's comprehensive approach to maintaining the Confidentiality, Integrity, Availability and/or Privacy of its Data. This Policy describes the roles, responsibilities, and procedures for classifying Data and for implementing and complying with the prescribed Data security measures.
Scope
This Policy applies to all 91直播 business operations across all 91直播 divisions and departments. This Policy applies to all 91直播 Employees, as well as contractors, consultants, temporary employees, and other third parties performing duties on behalf of the 91直播. This Policy applies to all Information and Data processed by the 91直播 and all Information Resources.
All Data Processed by the 91直播's Information Resources is the property of the 91直播, to the extent permitted by law or contract.
The 91直播 shall designate Data Stewards. The Information Governance Team, established by UMGC Policy X-1.01 Information Governance, shall maintain a record of Data Steward designations.
When an Information Resource(s) is purchased or renewed, the Information System Steward is responsible for ensuring that the relevant Data Steward(s) is(are) notified in order for the Data Steward to carry out their responsibilities as provided herein.
Data should only be Processed by the 91直播 to satisfy a legitimate business purpose and in a legal manner.
Adequate controls must be in place to protect the Confidentiality, Integrity, and Availability of Data commensurate to its Data Classification.
UMGC's Information Governance Team is responsible for overseeing compliance with 91直播 System of Maryland (USM) IT Security Standards, and applicable federal, state, and local laws regarding Data Classification.
Data Classification
Data Stewards are responsible for ensuring Data Classifications are assigned appropriately to each type of Data they oversee and that a record of those classifications is maintained.
Data Stewards are responsible for ensuring that the assigned Data Classifications are provided to applicable Information System Steward(s) and Technical System Lead(s) upon initial designation.
After initial Data Classifications are assigned, Data Stewards may change the Data Classification for particular Data as needed. Data Stewards are responsible for ensuring that the updated classifications are provided to the applicable Information System Steward(s) and Technical System Lead(s) in a timely manner.
The Information System Steward and Technical System Lead shall oversee the implementation of appropriate controls commensurate with the Data Classifications within the particular Information Resource.
Data Stewards shall assign Data Classifications to Data based on the risk associated with improper disclosure for the particular type of Data as follows:
High Risk Data
91直播 Data that (i) could be exploited for criminal or nefarious purposes; (ii) the 91直播 is obligated by state or federal statute or regulation to keep confidential; (iii) the 91直播 is contractually obligated to keep confidential, or (iv) are critical to the 91直播's operational performance and cannot be easily replaced. The loss of Confidentiality, Integrity, or Availability of such Data would cause severe harm to individuals or the 91直播 operations, safety, finances and/or reputation if disclosed.
Trade secrets, inventions, mask works, ideas, processes, research, formulas, source and object codes, Data, programs, other works of authorship, know-how, improvements, discoveries, developments, designs, techniques, and any other proprietary technology that is owned by the 91直播 by law, policy or contract;
Business and financial information or trade secrets received from a third party, which is subject to a duty on the 91直播's part to maintain the confidentiality of such information; and
Records pertaining to the 91直播's competitive position with respect to educational services, including but not limited to records addressing fees, tuition, charges, and supporting information held by the 91直播 (other than fees published in catalogs and ordinarily charged to students), proposals for the provision of educational services other than those generated, received or negotiated with its students, and research, analysis, or plans relating to the 91直播's operations or proposed operations.
Examples of such Data include, but are not limited to:
PII
Biometric Data
Education records
Medical records
Financial information
Controlled Unclassified Information (CUI)
Confidential information about 91直播 donors
Databases used for tax, health care, payroll
91直播-associated Account username(s) in combination with password(s)
Moderate Risk Data
91直播 Data that are not available to the public. The loss of the Confidentiality, Integrity, or Availability would cause limited harm to individuals or the 91直播's operations, safety, finances, and/or reputation. Data that were created or received primarily for use by the 91直播 or its Employees, Contractors, vendors, consultants, volunteers, students, alumni, donors, agents, or representatives for the 91直播's legitimate business purposes and can reasonably be expected to be secured from public view.
By default, all 91直播 Data that are not explicitly classified as High Risk Data or Low Risk Data shall be classified as Moderate Risk Data.
Examples of such Data include, but are not limited to:
91直播 research not considered High Risk
Non-public reports, budgets, operation plans
Low Risk Data
91直播 Data that contain any Information that is already available to the general public or is required by law, policies, procedures, contract or otherwise to be made available to the general public with no legal restrictions on its access or use. The loss of the confidentiality, integrity, or availability would cause little to no harm to individuals or the 91直播's operations, safety, finances, or reputation.
Examples of such Data include, but are not limited to:
Information found on the 91直播's publicly facing website
91直播 published marketing collateral
Combination of Data
If a set of Data contains multiple types of Data with different Data Classifications, Data Stewards are responsible for ensuring that at least the highest Data Classification that was applied to a particular Data element within that Data set is assigned to the entire Data set.
If a set of Data contains multiple types of Data with the same Data Classifications, Data Stewards are responsible for ensuring that a determination is made whether the Data set requires a higher level of Data Classification and if so, shall ensure that the higher classification is assigned accordingly.
Yearly Review
Data Stewards shall validate all applicable Data Classifications with the relevant Information System Steward(s) and Technical System Lead(s), in conjunction with the Data Protection Officer, as needed, or at least yearly, and update as necessary.
Enforcement
Any Employee, Contractor, or third-party performing duties on behalf of the 91直播 with knowledge of an alleged violation of this Policy shall notify the Office of Human Resources as soon as practical.
Data Stewards, in consultation with the Office of Human Resources, may instruct Information System Stewards and Technical System Leads to take down and remove content that violates this Policy as well as confiscate or temporarily suspend or terminate the use of Information Resource.
Employees or Contractors who violate this Policy may be denied access to Information Resources and may be subject to disciplinary action, up to and including termination of employment or contract.
Effective Date:聽This policy is effective as of the Version Effective Date set forth above.
By using our website you agree to our use of cookies. Learn more about how we use cookies by reading our聽Privacy Policy.