1604 PR.01 Data Classification Procedure

Revision Date: 
December 8, 2023

Contents

1.     Overview

2.     Determine Data Classification

3.     Secure Devices Based on Minimum Security Standards

4.     Confirm Application Security Compliance

5.     Changes in Access to Data Security Levels

6.     Unintentional Data Access and Remedy

7.     Exception Process

Yale University requires all University Data Users who have access to, and responsibilities for, Yale Data to manage them according to the rules regarding storage, disclosure, access, classification, and minimum privacy and security standards, as set forth in Policy 1604 Data Classification Policy.  The University seeks to preserve and dispose of its Data in a manner that achieves the goals of confidentiality, integrity, and availability.  This procedure addresses the proper practices for Data Users and the security of Data under their control.

Yale has created a classification system that divides Yale Data into three types, depending on their importance, sensitivity, and potential for misuse.  Refer to Policy 1604 Data Classification Policy for definitions and examples of High Risk Data, Moderate Risk Data, and Low Risk Data.

All Data Users are responsible for understanding Yale’s Data classifications, applying the classifications to the Yale Data under their control, and implementing the Minimum Security Standards (“MSS”) for each classification. 

Departments should assist Data Users within the department in understanding the security level of Data to which the Data User has and will require access.

Questions about particular Data and the applicable classification should be directed to Information Technology Services (“ITS”).  Please contact the ITS Help Desk at 203-432-9000 with any questions.

Once the Data User has determined, in consultation with his/her department, the classification of Data to which he/she has access, all devices through which the Data User will access Yale Data should be configured to meet the appropriate Minimum Security Standards (“MSS”).  Data Users should contact the ITS Help Desk at 203-432-9000 to ensure the proper configuration of their devices.

All applications that create, access, store, or transmit Yale Data, must be approved for the Data classification they utilize.  All Data Users are responsible for ensuring the applications they use in conjunction with Yale Data are approved for the Data’s classification level. Certain services can meet the MSS requirement for each Data classification. A list of these services can be found on the Yale Information Security website.

The Information Security Office (“ISO”) offers the Security Planning Assessment (“SPA”) process. The SPA process can confirm if services are secure for the risk classification of your work. This includes services not listed on the list mentioned above.

If a Data User’s role changes in such a way that they will require access to a higher level of secure Data, the Data User should contact the ITS Help Desk at 203-432-9000 to receive guidance and assistance in appropriately elevating any necessary security measures.  Every Data User is responsible for ensuring the appropriate level of security for the Data they use.  Contacting ITS is the surest way to ensure compliance with the policy.

Although compliance with Policy 1604 Data Classification Policy and this procedure will minimize incidents, it is possible that Data Users may occasionally and unintentionally access Yale Data in a classification level above their usual security level.  In such instances, Data Users should contact their supervisor to confirm whether there is a business justification for accessing the higher classification of Data.  If the Data User does not require access to this classification of Data, the Data User is responsible for contacting the ITS Help Desk to ensure proper removal and incident tracking.  If the Data User does require access to this classification of Data, the Data User should contact the ITS Help Desk at 203-432-9000 to configure their devices for the appropriate level of Data security.

In general, all Yale Data Users must comply with the standards set forth in Policy 1604 Data Classification Policy and this procedure. If a Data User believes they have a valid business justification for an exception to the standards, the Data User should submit an Exception Request to the ISO.  Data Users may not deviate from the standards until the ISO approves the exception request.