Public |
University information that can be seen by anyone. |
Electronic information should be stored using University of Staffordshire provided IT facilities to ensure appropriate management, backup and access. |
Information can be shared via the web without requiring a University of Staffordshire username. Electronic and hard copy information can be circulated freely subject to applicable laws e.g. copyright, contract, competition May be accessed remotely and via portable and mobile devices without encryption. |
Information can be exchanged via email or file sharing without needing encryption. |
Electronic information should be deleted using normal file deletion processes in accordance with any retention schedule. Printed copy should be disposed of via the University paper recycling scheme and in accordance with any retention schedule. |
Restricted |
Non-confidential information where dissemination is restricted in some way e.g. information restricted to members of the University, a committee, project or partnership. |
Electronic and paper-based Information must be stored using University of Staffordshire provided facilities. |
Information can be shared via the web, but the user must provide University of Staffordshire authentication, or a federated authentication Electronic and hard copy information can be circulated on a need-to-know basis to University members subject to applicable laws (e.g. copyright) and University Regulations May be accessed remotely and via disk-encrypted portable and mobile devices without further encryption. |
Information can be sent in unencrypted format via email. Information can be shared using University of Staffordshire IT facilities e.g. OneDrive, SharePoint, shared filestore. Information can be printed and circulated via the University internal mail service. |
Electronic equipment holding this information must be disposed of using the University secure IT waste disposal service and in accordance with any retention schedule. Printed copy should be disposed of via the University confidential waste scheme and in accordance with any retention schedule. |
Confidential |
Information which is sensitive in some way because it may be personal data, commercial or legal information, or be under embargo prior to wider release. Includes data about individuals, and data about the institution. May also include data provided to the University by other organisations e.g. research datasets |
Information must be stored using University of Staffordshire IT facilities. Portable devices must have full disk encryption. Unencrypted removable media (e.g. USB sticks) must not be used. Encrypted removable media are not permitted without undertaking evaluation of other options.
Storage on Personally owned (e.g. home) computer is NOT permitted.
|
Access to confidential data must be strictly controlled by the Data Owner who should conduct regular access reviews. Some types of confidential information may be shared with authorised users via University of Staffordshire IT facilities, including remote access, subject to University of Staffordshire authentication. For web access encryption must be used.
Confidential data must not be extracted from University IT systems and stored on local IT systems.
If a portable device (e.g. a laptop, tablet or phone) is used to access University confidential information, the device must be encrypted and require a password or PIN to access
|
The method to be used for exchanging confidential information must take account of the nature and volume of the data to be exchanged so that the impact of inappropriate disclosure can be assessed, and an appropriate method selected. Approved data exchange methods are available from Digital Services. Confidential data must be encrypted prior to exchange.
Exchange must be conducted using University of Staffordshire provided facilities. Duplicate copies of confidential information must be avoided. Where copies are necessary the protective marking must be carried with the data. Where paper copies are required for circulation or sharing, secure delivery methods must be used. Paper and electronic copies must be marked ‘Confidential’ and the intended recipients clearly indicated. An optional descriptor, to state the reason for confidentiality, may be used. Electronic equipment holding this information must be disposed of using the University secure IT waste disposal service and in accordance with any retention schedule. Printed copy should be disposed of in accordance with any retention schedule via the University confidential waste scheme or departmental shredding facilities. Large accumulations of data should not be downloaded or copied.
|
Electronic equipment holding this information must be disposed of using the University secure IT waste disposal service and in accordance with any retention schedule. Printed copy should be disposed of in accordance with any retention schedule via the University confidential waste scheme or departmental shredding facilities. Large accumulations of data should not be downloaded or copied. |
Highly Confidential |
Information which is sensitive and has the potential to cause serious damage or distress to individuals or serious damage to the University’s interests if disclosed inappropriately
Data contains highly sensitive private information about living individuals and it is possible to identify those individuals e.g. Medical records, serious disciplinary matters
|
Information must be stored using University of Staffordshire IT facilities. Portable devices must have full disk encryption. Unencrypted removable media (e.g. USB sticks) must not be used. Encrypted removable media are not permitted without undertaking evaluation of other options.
Storage on Personally owned (e.g. home) computer is NOT permitted.
|
Access to confidential data must be strictly controlled by the Data Owner who should conduct regular access reviews. Some types of confidential information may be shared with authorised users via University of Staffordshire IT facilities, including remote access, subject to University of Staffordshire authentication. For web access encryption must be used.
Confidential data must not be extracted from University IT systems and stored on local IT systems.
If a portable device (e.g. a laptop, tablet or phone) is used to access University confidential information, the device must be encrypted and require a password or PIN to access
|
The method to be used for exchanging confidential information must take account of the nature and volume of the data to be exchanged so that the impact of inappropriate disclosure can be assessed, and an appropriate method selected. Approved data exchange methods are available from Digital Services. Confidential data must be encrypted prior to exchange.
Exchange must be conducted using University of Staffordshire provided facilities. Duplicate copies of confidential information must be avoided. Where copies are necessary the protective marking must be carried with the data. Where paper copies are required for circulation or sharing, secure delivery methods must be used. Paper and electronic copies must be marked ‘Highly Confidential’ and the intended recipients clearly indicated. An optional descriptor, to state the reason for confidentiality, may be used.
|
Electronic equipment holding this information must be disposed of using the University secure IT waste disposal service and in accordance with any retention schedule. Printed copy should be disposed of in accordance with any retention schedule via the University confidential waste scheme or departmental shredding facilities. Large accumulations of data should not be downloaded . |