skip to content

IT Help and Support

University Information Services
 

This guidance for Microsoft OneDrive for Business ("OneDrive") is to help you understand what data can be stored within this public cloud service, and what classifications of data OneDrive can hold on the basis of the current University Guidance on Data Security Classification.

Similar guidance may apply to other devices you use to store this data and appropriate protections may be necessary on those devices. You should seek out and become familiar with such guidance. It is assumed here that you are already familiar with that guidance.

We have also taken into account the current UK Government Classification system in order to provide additional information and assurance for you to ascertain what data will be appropriate for storage within this Public Cloud Service. Both sets of Classification and Guidance are being provided because of the broad usefulness of the current UK Government Guidelines, which are in use throughout the UK public sector and which have established and considered application in the use of Public Cloud Services.

It is important to note, in all levels of security classification, the principal factor in good data management is the 'need to know’ principle (Information is only shared to people who need to know the information).

University data security classifications and guidelines

The University Guidance defines the following classifications.

  • Level 0: Unclassified or public information Unclassified or public information is the largest class containing the majority of information.
  • Level 1: Cambridge Only This covers information that is only available to students and staff within the Cambridge domain. It includes memoranda, minutes of meetings (not otherwise marked), and site-licensed software.
  • Level 2: Confidential information This covers certain minutes of meetings, general personal information, financial information, or other information designated as confidential but that may be dealt with by any staff with delegated responsibility from the recipient (i.e. it is not, in a strict sense, information 'for your eyes only').
  • Level 3: Personal and strictly confidential information This covers documents that contain highly sensitive information or personal details that are for the eyes of the recipient only where delegated authority is not appropriate.

Application to OneDrive

The Microsoft EES Agreement includes Terms and Conditions that are compliant with UK/EU Data Protection Law and the University Statutes and Ordinances. Microsoft provide EU Model clauses in agreements, hold ISO 27001 and ISO 27018 certifications and operate their data centres within the European Economic Area. The Services offered are integrated with authentication processes entirely within the control of the University of Cambridge.

Staff should note that specific contractual obligations applying to aspects of their work may supersede this guidance and those obligations should be treated as exceptions. Staff should ensure they are aware of any contractual obligations and treat those as having precedence; if in doubt, staff should seek guidance from local Data Protection Officers.

Hence the current policy on the use of OneDrive is:

Subject only to the exclusions below, data under Data Classification Levels 0, 1 and 2 above CAN be stored in OneDrive.

Data excluded from the above includes:

  • data classified as Level 3 above
  • patient identifiable data (including other identifiable data which is subject to the Clinical School’s mandatory data security policy which can be found at http://www.medschl.cam.ac.uk/research/information-governance/)
  • data that is subject to a specific contractual agreement that specifies a particular storage method (that is not OneDrive)
  • data that is subject to a specific contractual agreement that prohibits storage in a public cloud service.

Such data MUST NOT be stored in OneDrive.

Incident reporting

Any breach (loss of data, unauthorised access, 'over-sharing' or any other security incident) must be reported to:

Further information

For further information on classification of data or if you are unsure if your data may fall into an excluded category please contact: .

UIS Service Desk

Phone padded  Service status line: (01223 7)67999
Website  Sign up for SMS/email status alerts
Website  Read major IT incident reports

UIS bITe-size bulletin

A regular newsletter aimed at the University's IT community, highlighting service and project news from UIS.

Sign up >

Latest news

New University Wireless guest system coming soon

21 October 2021

Our University Wireless team is pleased to announce we'll be launching a new guest wifi system for visitors to the University and members of the public to use when in University buildings. This service will also be available on the 100 or so outdoor access points spread across the city. The new guest wifi will be much...

University Wireless Service maintenance: Tuesday 21 September, 08:00–09:00

16 September 2021

The University Wireless Service will be undergoing essential maintenance between 08:00 and 09.00 on Tuesday 21 September while we apply a security software patch. This is a security update to ClearPass, which provides Wireless Service network access control. We're not expecting any disruption to service, but it should be...

Mailing list migrations from Mailman to Sympa

31 August 2021

We intend to migrate all remaining lists associated with colleges from Mailman to Sympa during the week commencing 13 September 2020. The current total is 1,567. How this will affect users of the mailing list management service Most mailing list subscribers shouldn't notice any difference. During the switchover, there will...