skip to primary navigationskip to content
 

Guidelines on University data security classifications

The University defines four levels for classifying data based on the impact that compromise of this data would have.

Level 3: High or Very High Impact

Data of the type where:

  • there is a pressing requirement to limit who has access to it
  • there is need to define who is on the access list specifically
  • there is a need to ensure that the above list is complete (that is, it is known for certain there aren't other people who can see it by nature of their jobs – for example, HR or systems administrators).

Level 2: Medium Impact

Data of the type where restricted access is required, but it is acceptable for systems administrators and super users to also have access to it.

Level 1: Low Impact

Data of the type that is not quite 'public' or publicised data, perhaps because it includes some degree of personal data, but required for people to do their work in the University, for example:

  • a photoboard of personnel in a building, with their job titles
  • a telephone list of staff in a department
  • a lecture list, with lecturer names and rooms for students in a certain tripos.

Level 0: Negligible Impact

All data that doesn't fall into one of the classifications above.


Ultimately, the data owner decides the data security classification

Once that decision is made, the appropriate storage can be determined, along with the access controls (that is: who has access and how granular that access is).

 


Further information

 Information Security Risk Assessment

 Information Classification Tables

Reducing the Information Security Risk

 Storage

 Storing and sharing personal data

UIS Service Status

Phone padded  Service status line: (01223) 463085
Website  Sign up for SMS/email status alerts
Website  Read major IT incident reports

UIS bITe-size bulletin


A regular newsletter aimed at the University's IT community, highlighting service and project news from UIS.

Sign up >  |  Back issues

RSS Feed Latest news

Wireless Service unavailable 08:00–09:00 Tuesday 7 July

Jul 02, 2020

The University Wireless Service will be unavailable between 08:00 and 09:00 on Tuesday 7 July while we apply an essential software upgrade. During this period, users will be unable to connect to eduroam, the UniOfCam guest system and local SSIDs.

Retirement of UIS Windows Software Update Service (WSUS) on 30 June

Jun 26, 2020

We need to accelerate our original plan and fully decommission the Windows Software Update Service (WSUS) server on 30 June, rather than the 1 September, due to security concerns and the need to prioritise our resources to support the University.

View all news