Sensitive Information Classification Policy
| Policy Category | Issuing Authority | Responsibility | Publication Date | Next Review Date |
|---|---|---|---|---|
| Risk Management & Security | Enterprise Risk Management | Information Security Program Council & Data Governance Council | 9/16/2025 | 9/16/2028 |
Policy Statement & Background:
Stony Brook University is committed to the confidentiality, integrity, and availability of information important to the University's mission. University Data fall into one of three categories described in this policy. Data must be protected using the appropriate security measures consistent with the minimum standards for the classification category, where available.
Scope
This policy applies to all members of the university community, including the academic and research enterprise, the health system, Long Island State Veterans Home, other units as may come under management of the University, and third parties that handle University Data.
Policy:
Stony Brook classifies physical and electronic data into three risk-based categories for the purpose of determining access, permissions, and security precautions. This policy facilitates applying the appropriate security controls to University Data and assists data caretakers in determining the level of security required to protect data on the systems for which they are responsible.
All University Data fall into one of the three categories. Based on the data classification, individuals who use University Data are required to implement approved minimum-security standards, where available, for protecting the data. The standard for protecting the data becomes more stringent as the risk from disclosure increases.
University business processes must treat data according to this policy. Data that are personal to the operator of a system and stored on a university information technology (IT) resource as a result of incidental personal use are not considered University Data. University Data stored on non-university IT resources must still be verifiably protected according to respective minimum-security standards.
All data classified as Category 2 or Category 3 as described below are considered to be sensitive information (SI). Systems that store, transmit, or process SI are considered to be sensitive systems (SS).
Data Classifications
|
Data Risk Classification Category |
Category 3 |
|
Risk to University from Disclosure |
HIGH |
|
Definition |
|
|
Examples |
|
|
Data Risk Classification Category |
Category 2 |
|
Risk to University from Disclosure |
MODERATE |
|
Definition |
|
|
Examples |
|
|
Data Risk Classification Category |
Category 1 |
|
Risk to University from Disclosure |
LOW |
|
Definition |
|
|
Examples |
|
Definitions:
University Data: information collected or created through a function of the university.
Sensitive Information (SI): data classified as Category 2 or Category 3 as described in this policy.
Sensitive Systems (SS): systems that store, transmit, or process sensitive information.
Contact:
Additional information about this policy is available here:
Information Security Program Council (ISPC)
ISPC@stonybrook.edu
Relevant Standards, Codes, Rules, Regulations, Statutes and Policies:
- Data Classification Security Standards
- Information Security Program Administration Policy
- Policy on Data and Data Access
- New York State Breach Notification Law
- SUNY Policy 6900: Information Security