Sunteți pe pagina 1din 2

Data Classification Form Instructions

Name:

Provide the first and last name of data owner and an


alternate point of contact (POC) for this data.

Department:

Provide the name of the college, department, and/or


business unit which is responsible for this data.

Day Phone:

Provide the daytime phone number of the data owner or


alternate POC.

E-Mail:

Provide the E-Mail address of the data owner or alternate


POC

Description and location:

Provide a detailed description of the data and the


physical location of the data.

Regulated Data Elements

Select all of the data element types which are applicable


to this data. For definitions of each data element type see
the definitions document.

Categories

Select A, B, C, or D for the most appropriate/accurate


response for each of the four rows.

Overall Classification:

Using the responses identified under categories, where A


is highest and D is lowest, select the highest category
which applied to this data.

This data is classified as sensitive:

If overall classification is A or B, check Yes; otherwise,


check No.

Date:

Provide the date the Data Classification Form is


completed.

Version: 1.2

Revision Date: 06/02/2006

Data Classification Form


Name of
data
owner:

College:
Department:
Business
Unit:

Name of
alternate
POC:
Day Phone:

E-Mail:

Description
and location:

Regulated Data Element Types


HIPAA

GLB

FERPA

PCI

Financial

Categories
Category
A

Category
B

Category
C

Category
D

There is a legal or
contractual requirement to
protect data

No legal or contractual
requirement but there is an
obligation to protect data

Data is somewhat sensitive


but there is no obligation
to protect it

Data is not sensitive

There is a high level of


risk to reputation

There is a medium level of


risk to reputation

There is a low level of risk


to reputation

There is no risk to
reputation

Accuracy of data is
essential to business
functions

Accuracy is important to
business functions

Accuracy is only
somewhat important to
business functions

Accuracy has no bearing


on business functions

Business can not continue


without data

Business can continue


without data but would be
impacted

Business can continue and


would only be minimally
impacted by loss of data

Business would continue


as normal with loss of data

Data Classification
Overall Classification:
This data is classified as sensitive:

Version: 1.2

B
YES

C
NO

D
Date:

Revision Date: 06/02/2006

S-ar putea să vă placă și