Information Services & Technology

Sensitive University Data


IS&T Can Help

IS&T is committed to providing the tools required to help you maintain data security. If you have sensitive data, store it on the secured network server provided by IS&T. If you do not currently have secure network server storage, please contact us to discuss your needs.

Questions about sensitive data:

Michael Holstein, University Security Administrator
Phone: 216-875-9662
email:michael.holstein @csuohio.edu

General Policy for University Information and Technology Resources

Technology Policies

Whose data are you protecting?

Prospective Students                Prospective Employees
Current Students                        Current Employees
Past Students                             Past Employees
Alumni                                         Continuing Education Students

Do you fall into one of these categories?  If you do then you’re protecting your own data!

What data are sensitive?

Any data protected by FERPA, HIPPA, or any other legislated act. Here are some examples (this is not the entire list of data that is considered sensitive).

The Big Three:
    • Name
    • Social Security Number
    • Birth Date

Student Data
    • Grades data
    • Degree data
    • Registration (including transcript data)
    • All Financial Aid data

General Data
    • Mother’s maiden name
    • Bank ISO and credit card numbers
    • Addresses
    • Health history
    • Giving history

Employee Data
    • Race
    • Sex
    • Veteran Status
    • Disability
    • Leave information
    • Medical or health insurance
    • Disciplinary information
    • Performance evaluations


Sensitive Data Rules

Never:
    • Store Social Security Numbers, birth dates and/or credit card numbers on your computer
    • Store sensitive student or employee data, especially social security numbers and birth   dates, on any department computers (servers, desktops, laptops), PDAs, CDs, or USB
      drives.
    • Email files containing sensitive data
    • Request Social Security Number and/or birth date on web forms unless authorized by a
      data custodian and transmitted on a secure web connection approved by the University
      Security Administrator
    • Assign students or student employees query or download ability to sensitive data files
    • Share your ID and password
    • Authorize your staff to access sensitive data unless it’s absolutely required
    • Provide sensitive data to another staff member

Always:
    • Store sensitive data on the IS&T provided network server
    • Password protect files in those rare instances when they must be emailed (no Social
      Security Numbers and/or birth dates)
    • Become authorized and knowledgeable on how to obtain sensitive data from the system