Information Security Data Classifications
Quick Overview
- SFA classifies all university data into one of three categories: Confidential, Protected, or Public.
- Data Owners and Data Custodians are responsible for classifying data under their stewardship.
- Classification determines the level of protection required and governs how data may be stored, shared, or disclosed.
- Multiple federal and state laws drive classification requirements — see the Regulatory Drivers section below.
Stephen F. Austin State University's Information Security Program requires that all institutional data be classified according to its sensitivity and applicable legal protections. Proper classification ensures data is handled consistently and that legal obligations under laws such as FERPA, HIPAA, and PCI-DSS are met. The guidelines below define each category, provide extended examples by data type, and summarize the regulatory frameworks that drive classification decisions.
Data Classification Categories
All university data must be assigned to one of the following three categories. When in doubt, classify at the higher (more restrictive) level.
| Category |
Sensitivity |
Description |
Example Data |
| Category I — Confidential |
High |
Must be protected from unauthorized disclosure by state or federal law. Unauthorized exposure presents serious risk of harm to individuals or the university. |
Social Security Numbers, credit card data, personal health information, crime victim records, access credentials |
| Category II — Protected |
Medium |
May be subject to disclosure under the Texas Public Information Act, but requires additional controls. Unauthorized disclosure could adversely impact the university, individuals, or affiliates. |
Personnel records, security procedures, internal communications, university research, performance appraisals |
| Category III — Public |
Low |
Intended or required for public release under the Texas Public Information Act. May be shared broadly at the discretion of the data owner. |
Job postings, published research, degree programs, directory information, general university information |
|
!
|
Important
Data Owners and Data Custodians are responsible for classifying data under their stewardship. If you are unsure how to classify a particular data set, contact the Information Security Office for guidance before storing or sharing the data.
|
Extended Guidelines by Data Type
Expand each section below to view specific data elements and their classification for common university data types.
Patient Medical / Health Information Confidential Health Insurance Portability and Accountability Act (HIPAA) ⌄
The following patient and health-related data elements are classified as Confidential and are governed by HIPAA:
- Social Security Number
- Patient names, street address, city, county, zip code, telephone/fax numbers
- Dates (except year) related to an individual; account/medical record numbers; health plan beneficiary numbers
- Personal vehicle information
- Certificate/license numbers, device IDs and serial numbers, email addresses, URLs, IP addresses
- Access device numbers
- Biometric identifiers and full face images
- Any other unique identifying number, characteristic, or code
- Payment guarantor's information
Governing Policy SFA Information Security Standard 06-107.1.7 — HIPAA Security Standard
Student Records Protected / Confidential Family Educational Rights and Privacy Act (FERPA) ⌄
Protected Student Data
The following student record elements require protection and are not considered directory information:
- Residency status
- Marital status and married/previous name
- Parents' name and address
- Transfer credits, courses completed, grades, and grade point average
- Rank in class and academic status
- Current class schedule and advisor's name
- Current disciplinary status
FERPA Directory Information (Public)
SFA has designated the following student information as public directory information. Students may request that directory information be withheld:
- Name, address, telephone number, and email address
- Date and place of birth
- Major field of study and enrollment status
- Dates of attendance and classification
- Most recent previous educational institution attended
- Degrees, certificates, awards (including scholarships) received; date of graduation
- Participation in officially recognized activities and sports
- Physical factors (height and weight) of athletes
- Photographs
|
i
|
Tip
Students may submit a FERPA hold request to restrict release of their directory information. Contact the Registrar's Office for the appropriate form.
|
Donor / Alumni Information Confidential Texas Identity Theft Enforcement and Protection Act ⌄
The following donor and alumni data elements are classified as Confidential:
- Donor name
- Personal financial information
- Credit card numbers, bank account numbers, and donation amounts
Research Information Confidential Granting Agency Agreements / IRB Governance ⌄
The following research data elements are classified as Confidential:
- Data on human subjects that contains personal identifiers
- Sensitive digital research data
|
i
|
Tip
Research involving human subjects must be reviewed by the Institutional Review Board (IRB) prior to data collection. Contact the Office of Research & Sponsored Programs for guidance.
|
Export Controlled Information Confidential ITAR / EAR ⌄
Information or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) is classified as Confidential. This includes:
- Information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a controlled item — including blueprints, drawings, photographs, plans, instructions, or documentation
- Classified information relating to defense articles and defense services
- Software directly related to a controlled item
|
i
|
Note
Export controls do not apply to general scientific, mathematical, or engineering principles commonly taught in universities, information already in the public domain, or basic marketing information about an article's function or general system description.
|
Employee Information Confidential SFASU Policy Manual / Texas Identity Theft Enforcement and Protection Act ⌄
The following employee data elements are classified as Confidential:
- Social Security Number
- Date of Birth
- Personal financial information
- Insurance benefit information
- Access device numbers
- Biometric identifiers
- Family information
|
i
|
Note
Certain employee information is considered public and subject to open records requests, including employee names, salary, and performance review information.
|
Business / Vendor Data Confidential Gramm-Leach-Bliley Act / Non-Disclosure Agreements ⌄
The following business and vendor data elements are classified as Confidential:
- Credit card information
- Contract information (between SFA and a third party)
- Access device information
- Biometric identifiers
- Certificate/license numbers, device IDs and serial numbers, email addresses, URLs, and IP addresses
Other Institutional Data Confidential Gramm-Leach-Bliley Act / Additional Considerations ⌄
The following institutional data elements are classified as Confidential:
- Information pertaining to the Offices of Audit Services and General Counsel
- Financial records and contracts
- Physical plant details
- Credit card numbers
- Certain management information
- Critical infrastructure details
- User account passwords
Regulatory Drivers
Data classification obligations arise from a variety of state and federal laws and industry standards. The following are the primary regulatory drivers applicable to SFA. This is not an exhaustive list.
Gramm-Leach-Bliley Act (GLBA) Confidential Financial data safeguards ⌄
The GLBA requires all financial institutions that provide financial products or services — such as student loans — to safeguard customer information and adequately protect customer identity and sensitive data. Covered data must be classified as Confidential.
Family Educational Rights and Privacy Act (FERPA) Confidential Student education records ⌄
FERPA is a federal law protecting the privacy of student education records. It applies to all schools that receive funds under applicable U.S. Department of Education programs. Covered data must be classified as Confidential.
Health Insurance Portability and Accountability Act (HIPAA) Confidential Medical data privacy and security ⌄
HIPAA is a federal law providing data privacy and security provisions for safeguarding medical information. Covered data must be classified as Confidential.
Payment Card Industry Data Security Standard (PCI-DSS) Confidential Credit card processing, storage, and transmission ⌄
PCI-DSS is an industry standard focusing on securing the processing, storing, and transmitting of credit card information. Covered data must be classified as Confidential.
Federal Information Security Act (FISMA) Confidential Federal government information protection ⌄
FISMA defines a comprehensive framework to protect government information, operations, and assets against natural or man-made threats. Covered data must be classified as Confidential.
Controlled Unclassified Information (CUI) Protected Replaces For Official Use Only (FOUO) ⌄
CUI is information considered unclassified but requiring protection from public disclosure. CUI replaces the legacy "For Official Use Only" (FOUO) designation. Covered data must be classified as Protected.
Export Controlled Information (ITAR / EAR) Confidential U.S. export control laws ⌄
ITAR and EAR are U.S. export control laws governing the manufacturing, sales, and distribution of controlled technology. They are designed to prevent disclosure or transfer of sensitive information to foreign nations. Covered data must be classified as Confidential.
Red Flag Rules Confidential Identity theft prevention ⌄
The Red Flag Rules require organizations to develop, implement, and administer Identity Theft Prevention Programs to help prevent identity theft. Covered data must be classified as Confidential.
Health Information for Economic and Clinical Health (HITECH) Act Confidential Strengthens HIPAA enforcement ⌄
HITECH promotes the adoption and meaningful use of health information technology and addresses privacy and security concerns related to the electronic transmission of health information. It strengthens civil and criminal enforcement of HIPAA rules. Covered data must be classified as Confidential.
Children's Online Privacy Protection Act (COPPA) Confidential Privacy of children under age 13 ⌄
COPPA protects the privacy of children under the age of 13 and requires parental consent for the collection or use of personal information by websites targeting younger users. Covered data must be classified as Confidential.
Criminal Justice Information Services (CJIS) Confidential Criminal Justice Information (CJI) protection ⌄
The CJIS Security Policy provides controls to protect Criminal Justice Information (CJI) from unauthorized access or disclosure. Covered data must be classified as Confidential.
Fair and Accurate Credit Transaction Act (FACTA) Confidential Consumer identity theft protection / secure disposal ⌄
FACTA is a federal law focused on protecting consumers from identity theft and is an amendment to the Fair Credit Reporting Act. It requires the secure disposal of consumer information. Covered data must be classified as Confidential.
Need Help?
For questions about data classification, contact the
Information Security Office or reach the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.