Contributed by Organizations or Campuses and Data Security

Data Classification Standards

Added by the EDUCAUSE Librarian
Title:Data Classification Standards (ID: CSD5481)
Author(s):Brian Basgen (Pima County Community College District)
Source:Pima Community College
Origin:Contributed by Organizations or Campuses (08/19/2008)
Type:Policies and Procedures
Abstract:

The purpose of this policy is to protect the confidentiality, integrity, and availability of Pima Community College data.

View this resource:

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Policy on Institutional Data

Added by the EDUCAUSE Librarian
Title:Policy on Institutional Data (ID: CSD5463)
Source:Ohio State University
Origin:Contributed by Organizations or Campuses (10/18/2007)
Type:Policies and Procedures
Abstract:

Ohio State University's policy includes institutional data procedures and resources. It also defines the scope and applicability of the policy, as well as enforcement.

View this resource:

Sensitive Data Best Practices

Added by the EDUCAUSE Librarian
Title:Sensitive Data Best Practices (ID: CSD5462)
Source:Louisiana State University
Origin:Contributed by Organizations or Campuses (01/10/2007)
Type:Policies and Procedures
Abstract:

Louisiana State University's Best Practices for Sensitive Data covers the following: Electronic Handling, Storage and Disposal; Physical Handling, Storage and Disposal; Security; and Legal Disclosure Requirements.

View this resource:

Asset Classification

Added by the EDUCAUSE Librarian
Title:Asset Classification (ID: CSD5356)
Origin:Contributed by Organizations or Campuses (03/03/2008)
Type:Web Sites
Abstract:

These are Asset Classification resources from the IT Security Guide wiki created by the EDUCAUSE Security Task Force and Internet2. This wiki includes resources on Accountability of Assets. Inventory of Assets, and Information Classification.

View this resource:

Data Classification Security Policy

Added by the EDUCAUSE Librarian
Title:Data Classification Security Policy (ID: CSD5354)
Source:George Washington University
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Policies and Procedures
Abstract:

This is George Washington University Data Classification Security Policy.
The purpose of this policy is to educate the University community about the importance of protecting data generated, accessed, transmitted and stored by the University, to identify procedures that should be in place to protect the confidentiality, integrity and availability of University data, and to comply with local and federal regulations regarding privacy and confidentiality of information.

View this resource:

Data Classification Standard

Added by the EDUCAUSE Librarian
Title:Data Classification Standard (ID: CSD5353)
Source:University of Texas at Austin
Origin:Contributed by Organizations or Campuses (12/14/2007)
Type:Policies and Procedures
Abstract:

This University of Texas at Austin Data Classification Standard serves as a supplement to the IT Security Operations Manual, which was drafted in response to Texas Administrative Code 202 and UT System UTS-165. Adherence to the standard will facilitate applying the appropriate security controls to university data.

The objective of this standard is to assist data stewards, IT owners and custodians in the assessment of information systems to determine what level of security is required to protect data on the systems for which they are responsible.

View this resource:

Standards for Security Categorization of Federal Information and Information Systems (FIPS-199)

Added by the EDUCAUSE Librarian
Title:Standards for Security Categorization of Federal Information and Information Systems (FIPS-199) (ID: CSD5355)
Source:National Institute of Standards and Technology
Origin:Contributed by Organizations or Campuses (02/18/2004)
Type:Government Documents, Laws, Testimonies or Reports
Abstract:

The E-Government Act of 2002 (Public Law 107-347), recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act of 2002 (FISMA), tasked NIST with responsibilities for standards and guidelines, including the development of:
- Standards to be used by all federal agencies to categorize all information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels;
- Guidelines recommending the types of information and information systems to be included in each category; and
- Minimum information security requirements (i.e., management, operational, and technical controls), for information and information systems in each such category.

View this resource:

State of Ohio Data Classification Policy

Added by the EDUCAUSE Librarian
Title:State of Ohio Data Classification Policy (ID: CSD5340)
Source:Ohio State University
Origin:Contributed by Organizations or Campuses (03/19/2007)
Type:Policies and Procedures
Abstract:

This state policy is intended to provide a high-level data classification methodology to state agencies for the purpose of understanding and managing data and information assets with regard to their level of confidentiality and criticality. Accurate identification provides a basis to employ an appropriate level of security. This policy applies to Ohio State University.

View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource: