Skip navigation

Potential Impact

POTENTIAL IMPACT

Security Objective

LOW

MODERATE

HIGH

Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.

The unauthorized disclosure of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.

The unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.

The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

Integrity
Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.

The unauthorized modification or destruction of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.

The unauthorized modification or destruction of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.

The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

Availability
Ensuring timely and reliable access to and use of information.

The disruption of access to or use of information or an information system could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.

The disruption of access to or use of information or an information system could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.

The disruption of access to or use of information or an information system could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

 

As the total potential impact to the University increases from Low to High, the classification of data should become more restrictive moving from Public to Restricted. If an appropriate classification is still unclear after considering these points, contact the Information Security Office for assistance.

 

Storing Restricted Data:

THE BEST WAY TO PROTECT RESTRICTED DATA IS NOT TO HAVE IT IN THE FIRST PLACE!

  • Store the minimum amount of restricted data possible, and know where it is stored.

  • Securely delete restricted data when there is no longer a business need for its retention.

    • Don't forget about email, attachments, screenshots, old or previous versions of files, drafts, archives, copies, backups, CDs/DVDs, Zip disks, old floppies, etc.

    • Always shred or otherwise destroy restricted data when disposing of it or equipment that contains it.

  • Truncate, de-identify or redact restricted data that you must retain whenever possible.

  • Restricted Data should not be stored on:

    • SharePoint sites
    • File Shares
    • Personal Computers
    • Removable device
    • Mobile devices

Your Next Step is Within Reach.

With over 135 years of excellence and 70,000 alumni, we provide an extraordinary education that’s within your reach.