Information Security Data Classifications

Information Security Data Classifications

Quick Overview
  • SFA classifies all university data into one of three categories: Confidential, Protected, or Public.
  • Data Owners and Data Custodians are responsible for classifying data under their stewardship.
  • Classification determines the level of protection required and governs how data may be stored, shared, or disclosed.
  • Multiple federal and state laws drive classification requirements — see the Regulatory Drivers section below.

Stephen F. Austin State University's Information Security Program requires that all institutional data be classified according to its sensitivity and applicable legal protections. Proper classification ensures data is handled consistently and that legal obligations under laws such as FERPA, HIPAA, and PCI-DSS are met. The guidelines below define each category, provide extended examples by data type, and summarize the regulatory frameworks that drive classification decisions.

Data Classification Categories

All university data must be assigned to one of the following three categories. When in doubt, classify at the higher (more restrictive) level.

Category Sensitivity Description Example Data
Category I — Confidential High Must be protected from unauthorized disclosure by state or federal law. Unauthorized exposure presents serious risk of harm to individuals or the university. Social Security Numbers, credit card data, personal health information, crime victim records, access credentials
Category II — Protected Medium May be subject to disclosure under the Texas Public Information Act, but requires additional controls. Unauthorized disclosure could adversely impact the university, individuals, or affiliates. Personnel records, security procedures, internal communications, university research, performance appraisals
Category III — Public Low Intended or required for public release under the Texas Public Information Act. May be shared broadly at the discretion of the data owner. Job postings, published research, degree programs, directory information, general university information
!
Important
Data Owners and Data Custodians are responsible for classifying data under their stewardship. If you are unsure how to classify a particular data set, contact the Information Security Office for guidance before storing or sharing the data.

Extended Guidelines by Data Type

Expand each section below to view specific data elements and their classification for common university data types.

Patient Medical / Health Information  Confidential  Health Insurance Portability and Accountability Act (HIPAA)

The following patient and health-related data elements are classified as Confidential and are governed by HIPAA:

  • Social Security Number
  • Patient names, street address, city, county, zip code, telephone/fax numbers
  • Dates (except year) related to an individual; account/medical record numbers; health plan beneficiary numbers
  • Personal vehicle information
  • Certificate/license numbers, device IDs and serial numbers, email addresses, URLs, IP addresses
  • Access device numbers
  • Biometric identifiers and full face images
  • Any other unique identifying number, characteristic, or code
  • Payment guarantor's information
Governing Policy SFA Information Security Standard 06-107.1.7 — HIPAA Security Standard
Student Records  Protected / Confidential  Family Educational Rights and Privacy Act (FERPA)

Protected Student Data

The following student record elements require protection and are not considered directory information:

  • Residency status
  • Marital status and married/previous name
  • Parents' name and address
  • Transfer credits, courses completed, grades, and grade point average
  • Rank in class and academic status
  • Current class schedule and advisor's name
  • Current disciplinary status

FERPA Directory Information (Public)

SFA has designated the following student information as public directory information. Students may request that directory information be withheld:

  • Name, address, telephone number, and email address
  • Date and place of birth
  • Major field of study and enrollment status
  • Dates of attendance and classification
  • Most recent previous educational institution attended
  • Degrees, certificates, awards (including scholarships) received; date of graduation
  • Participation in officially recognized activities and sports
  • Physical factors (height and weight) of athletes
  • Photographs
i
Tip
Students may submit a FERPA hold request to restrict release of their directory information. Contact the Registrar's Office for the appropriate form.
Donor / Alumni Information  Confidential  Texas Identity Theft Enforcement and Protection Act

The following donor and alumni data elements are classified as Confidential:

  • Donor name
  • Personal financial information
  • Credit card numbers, bank account numbers, and donation amounts
Research Information  Confidential  Granting Agency Agreements / IRB Governance

The following research data elements are classified as Confidential:

  • Data on human subjects that contains personal identifiers
  • Sensitive digital research data
i
Tip
Research involving human subjects must be reviewed by the Institutional Review Board (IRB) prior to data collection. Contact the Office of Research & Sponsored Programs for guidance.
Export Controlled Information  Confidential  ITAR / EAR

Information or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) is classified as Confidential. This includes:

  • Information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a controlled item — including blueprints, drawings, photographs, plans, instructions, or documentation
  • Classified information relating to defense articles and defense services
  • Software directly related to a controlled item
i
Note
Export controls do not apply to general scientific, mathematical, or engineering principles commonly taught in universities, information already in the public domain, or basic marketing information about an article's function or general system description.
Employee Information  Confidential  SFASU Policy Manual / Texas Identity Theft Enforcement and Protection Act

The following employee data elements are classified as Confidential:

  • Social Security Number
  • Date of Birth
  • Personal financial information
  • Insurance benefit information
  • Access device numbers
  • Biometric identifiers
  • Family information
i
Note
Certain employee information is considered public and subject to open records requests, including employee names, salary, and performance review information.
Business / Vendor Data  Confidential  Gramm-Leach-Bliley Act / Non-Disclosure Agreements

The following business and vendor data elements are classified as Confidential:

  • Credit card information
  • Contract information (between SFA and a third party)
  • Access device information
  • Biometric identifiers
  • Certificate/license numbers, device IDs and serial numbers, email addresses, URLs, and IP addresses
Other Institutional Data  Confidential  Gramm-Leach-Bliley Act / Additional Considerations

The following institutional data elements are classified as Confidential:

  • Information pertaining to the Offices of Audit Services and General Counsel
  • Financial records and contracts
  • Physical plant details
  • Credit card numbers
  • Certain management information
  • Critical infrastructure details
  • User account passwords

Regulatory Drivers

Data classification obligations arise from a variety of state and federal laws and industry standards. The following are the primary regulatory drivers applicable to SFA. This is not an exhaustive list.

Gramm-Leach-Bliley Act (GLBA)  Confidential  Financial data safeguards

The GLBA requires all financial institutions that provide financial products or services — such as student loans — to safeguard customer information and adequately protect customer identity and sensitive data. Covered data must be classified as Confidential.

Family Educational Rights and Privacy Act (FERPA)  Confidential  Student education records

FERPA is a federal law protecting the privacy of student education records. It applies to all schools that receive funds under applicable U.S. Department of Education programs. Covered data must be classified as Confidential.

Health Insurance Portability and Accountability Act (HIPAA)  Confidential  Medical data privacy and security

HIPAA is a federal law providing data privacy and security provisions for safeguarding medical information. Covered data must be classified as Confidential.

Payment Card Industry Data Security Standard (PCI-DSS)  Confidential  Credit card processing, storage, and transmission

PCI-DSS is an industry standard focusing on securing the processing, storing, and transmitting of credit card information. Covered data must be classified as Confidential.

Federal Information Security Act (FISMA)  Confidential  Federal government information protection

FISMA defines a comprehensive framework to protect government information, operations, and assets against natural or man-made threats. Covered data must be classified as Confidential.

Controlled Unclassified Information (CUI)  Protected  Replaces For Official Use Only (FOUO)

CUI is information considered unclassified but requiring protection from public disclosure. CUI replaces the legacy "For Official Use Only" (FOUO) designation. Covered data must be classified as Protected.

Export Controlled Information (ITAR / EAR)  Confidential  U.S. export control laws

ITAR and EAR are U.S. export control laws governing the manufacturing, sales, and distribution of controlled technology. They are designed to prevent disclosure or transfer of sensitive information to foreign nations. Covered data must be classified as Confidential.

Red Flag Rules  Confidential  Identity theft prevention

The Red Flag Rules require organizations to develop, implement, and administer Identity Theft Prevention Programs to help prevent identity theft. Covered data must be classified as Confidential.

Health Information for Economic and Clinical Health (HITECH) Act  Confidential  Strengthens HIPAA enforcement

HITECH promotes the adoption and meaningful use of health information technology and addresses privacy and security concerns related to the electronic transmission of health information. It strengthens civil and criminal enforcement of HIPAA rules. Covered data must be classified as Confidential.

Children's Online Privacy Protection Act (COPPA)  Confidential  Privacy of children under age 13

COPPA protects the privacy of children under the age of 13 and requires parental consent for the collection or use of personal information by websites targeting younger users. Covered data must be classified as Confidential.

Criminal Justice Information Services (CJIS)  Confidential  Criminal Justice Information (CJI) protection

The CJIS Security Policy provides controls to protect Criminal Justice Information (CJI) from unauthorized access or disclosure. Covered data must be classified as Confidential.

Fair and Accurate Credit Transaction Act (FACTA)  Confidential  Consumer identity theft protection / secure disposal

FACTA is a federal law focused on protecting consumers from identity theft and is an amendment to the Fair Credit Reporting Act. It requires the secure disposal of consumer information. Covered data must be classified as Confidential.

Need Help?

For questions about data classification, contact the Information Security Office or reach the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu.