This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
wiki:policies:data [2021/11/15 21:29] katcow |
wiki:policies:data [2024/01/24 21:30] (current) katcow |
||
---|---|---|---|
Line 1: | Line 1: | ||
+ | ====== Data Classification Policy ====== | ||
+ | ===== I. Purpose ===== | ||
- | - | + | The purpose of this policy is to categorize, describe, and determine the level of protection required for various types of Nested Knowledge data. |
- | ===== Purpose | + | ===== II. Scope ===== |
- | - | + | Nested Knowledge Data: Company data is information generated by or for, owned by, or otherwise in Nested Knowledge’s possession. Company data includes, but is not limited to, research data, business data, and computer programs. |
- | ===== Scope ===== CKGE_TMP_i Nested Knowledge Data: // Company data is information generated by or for, owned by, or otherwise in Nested Knowledge’s possession. Company data includes, but is not limited to, research data, business data, and computer programs. | + | ===== III. Data Classification Policy ===== |
+ | |||
+ | === Public Data: === | ||
+ | |||
+ | Data classified as public may be disclosed to anyone, regardless of their affiliation with Nested Knowledge. | ||
+ | |||
+ | === Internal Data === | ||
+ | |||
+ | Internal data is information that is potentially sensitive and is not intended to be shared with the public. Internal data generally should not be disclosed outside of Nested Knowledge without the permission of the person or group that created the data. | ||
+ | |||
+ | === Confidential | ||
+ | |||
+ | Confidential data is information that, if made available to unauthorized parties, may adversely affect individuals, | ||
+ | |||
+ | Users are prohibited from sharing confidential information through the following means: | ||
+ | |||
+ | * sending to un-authorized websites, | ||
+ | * sending by phone messaging, WhatsApp, or similar technologies, | ||
+ | * posting on social media, such as Twitter | ||
+ | * uploading to removable media, such as USB devices. | ||
+ | |||
+ | Confidential information should be stored in secure, encrypted environments. Employees are prohibited from storing confidential information on their personal device filesystems. | ||
+ | |||
+ | === Loss of Confidentiality === | ||
+ | |||
+ | Any unauthorized disclosure or loss of Confidential data must be reported to the Incident Response Team at 507-271-7051. | ||
+ | |||
+ | === Restricted Use === | ||
+ | |||
+ | Restricted Use data includes any information that Nested Knowledge has a contractual, | ||
+ | |||
+ | * Personally identifiable health information that is not subject to HIPAA but used in research, such as Human Subjects Data. | ||
+ | * Personally Identifiable Information (PII), including an individual’s name plus the individual’s Social Security Number, driver’s license number, or a financial account number. | ||
+ | * Unencrypted data used to authenticate or authorize individuals to use electronic resources, such as passwords, keys, and other electronic tokens. | ||
+ | * “Criminal Background Data” that might be collected as part of an application form or a background check. More stringent requirements exist for some types of Restricted Use data | ||
+ | |||
+ | __Nested Knowledge DOES NOT process any personal health information (PHI) or criminal background | ||
+ | |||
+ | ==== High-Risk Personal Data ==== | ||
+ | |||
+ | Potential high-risk data types we may encounter include the following: | ||
+ | |||
+ | * Information on employee health and/or disability status. | ||
+ | * Information on employee ethnicity, race, religion, sexuality, or political beliefs. | ||
+ | * User location data and online behavior | ||
+ | |||
+ | High-risk personal data fall under the same guidelines as restricted use data. | ||
+ | |||
+ | === Other Regulations === | ||
+ | |||
+ | Some data may be subject to specific protection requirements under a contract or grant, or according to a law or regulation not described here. In those circumstances, | ||
+ | |||
+ | === Compliance === | ||
+ | |||
+ | Failure to comply with data protection may result in harm to individuals, | ||
+ | |||
+ | === Review and Update === | ||
+ | |||
+ | This data classification policy will be updated at least on an annual basis, or when a signficant change in data processing occurs. | ||
+ | |||
+ | ===== Revision History ===== | ||
+ | |||
+ | ^Author^Date of Revision/Review^Comments| | ||
+ | |K. Cowie|01/ | ||
+ | |K. Kallmes|11/ | ||
+ | |P. Olaniran|09/ | ||
+ | |K. Cowie|09/ | ||
+ | |||
+ | [[: | ||