Skip To Main Content
Site Name Here
MenuSearchA-ZSeven Schools One UniversitySeven Schools One University

Menu

  • Give
  • Apply
  • Visit
Close Menu
About
  • Administrative Offices
  • AI at UMB
  • Campus Maps
  • Core Values
  • Economic Impact
  • Fast Facts
  • Middle States
  • MPowering the State
  • News
  • Other USM Schools
  • Policies and Procedures
  • Strategic Plan
  • Sustainability
  • Travel and International Services
  • UMB Experts Guide
  • University Leadership
Academics
  • Academic Calendar
  • Academy of Lifelong Learning
  • Blackboard
  • Experience Student Portal
  • Libraries
  • Office of the Provost
  • PA Leadership and Learning Academy
  • UMB Program Explorer
Admissions
  • International Students
  • Military and Veterans
  • Office of the Registrar
  • University Student Financial Aid
Research
  • Breakthroughs Can’t Wait
  • Offices and Contacts
  • Resources for Investigators
  • Services for Investigators
  • UMB Research Profile
University Life
  • Arts and Culture
  • Bookstore
  • Emergency
  • Off-Campus Housing
  • Museums
  • One Card
  • Parking and Transportation Services
  • Rooms Available on Campus
  • SMC Campus Center
  • Student Organizations
  • Student Policies
  • UMB Connect
  • URecFit and Wellness
  • Welcome to Baltimore
Info For
  • Current Students
  • Faculty and Staff
  • Alumni and Donors
  • Community Members
Resources
  • The Elm
  • Calendar
  • myUMB
  • Directory
  • AI at UMB
  • Student Portal
  • Emergency
  • UMB Shuttle
Seven Schools One University

Search

Close Menu
Common Searched Terms
  • Campus Tour
  • Careers at UMB
  • Graduation
  • Help Desk
  • Human Resources
  • Parking
  • Qualtrics
  • Registrar
  • Tuition
  • Tuition Remission
  • URecFit and Wellness

A–Z

Close Menu
    Policies and Procedures

    Information Technology Policies

    1. UMB Home
    2. About UMB
    3. Policies and Procedures
    4. Library
    5. Information Technology
    6. Information Technology Policies
    • UMB HomeAbout UMBPolicies and ProceduresLibraryInformation TechnologyInformation Technology Policies
    • Information Technology Policies
    • Information Technology Procedures

    UMB Data Classification Policy

    X-99.06(A)  |  Information Technology  |  Approved April 13, 2015  |  Last Reviewed July 21, 2026

    Responsible VP/AVP: Peter J. Murray, PhD, CAS, MS

    Applies to: Faculty, Staff

    Revision History

    Approved April 13, 2015.

    Policy Statement

    Data and information are important assets of the University and must be protected from loss of integrity, confidentiality, or availability in compliance with University policy and guidelines, Board of Regents policy, and state and federal laws and regulations.  

    Policy

    All University Data must be classified according to the UMB Classification Schema and protected according to UMB Data Security Standards. This policy applies to data in all formats or media.

    Data Classification Schema

    Data and information assets are classified according to the risks associated with data being stored or processed. Data with the highest risk need the greatest level of protection to prevent compromise; data with lower risk require proportionately less protection. Three levels of data classification will be used to classify University Data based on how the data are used, its sensitivity to unauthorized disclosure, and requirements imposed by external agencies.

    Data are typically stored in aggregate form in databases, tables, or files. In most data collections, highly sensitive data elements are not segregated from less sensitive data elements. For example, a student information system will contain a student's directory information as well as their social security number. Consequently, the classification of the most sensitive element in a data collection will determine the data classification of the entire collection.

    UMB Data Classifications:

    Level 0 – Public - Information approved for public release. Sharing this data does not create institutional risk because it is already intended to be openly accessible.

    Examples:

    • University website content
    • Public directory information (name, title, department)
    • Published research or reports
    • Marketing materials, brochures, event schedules
    • Campus maps and publicly distributed announcements
    • Institutional statistics approved for public release (e.g., enrollment totals, graduation rates)

    Level 1 – Internal - Information intended for internal University use. This data is not public, but it does not contain sensitive or regulated elements. Unauthorized disclosure would be undesirable, but not seriously harmful.

    Examples:

    • Internal emails, memos, meeting notes
    • Draft documents not yet approved for publication
    • Course materials and instructional content
    • Non-sensitive research data
    • Department procedures, operational documentation
    • Most system configuration details
    • Internal reports, metrics, and dashboards

    Level 2 – Confidential - Sensitive or regulated information that requires the highest level of protection. If exposed, it could cause harm to individuals or the University. Includes data protected by federal, state, national laws or contractual obligations.

    Examples:

    • Personal Information (PII): SSNs, driver’s license numbers, passport numbers, DOB + identifiers
    • Education Records (FERPA): grades, transcripts, advising notes, student ID numbers
    • Health Data (HIPAA): medical records, diagnoses, test results, counseling information
    • Financial Data: bank account numbers, credit card numbers, payroll, tax documents, financial aid records
    • Authentication Data: usernames paired with passwords, passwords, MFA codes, API keys
    • Research Data: human subject data, restricted or proprietary research, sponsor-restricted datasets

     

    Aggregated/De-identified Data Sets:

    De-identified or aggregated data is Confidential if any of the following may apply; small sample sizes, unique populations, use of quasi-identifiers, IRB rules, contractual obligations, or realistic re-identification risks apply.


    • Back to Information Technology Policies

    Find a Policy or Procedure

    Browse the Library Filter and Sort With the Index

    Contact

    Office of Institutional Policy Management

    620 W. Lexington St.
    5th floor
    Baltimore, MD 21201

    PolicyOffice@umaryland.edu

    Related Information

    USM Bylaws, Policies, and Procedures Policy Application System
    University of Maryland Baltimore

    The University of Maryland, Baltimore is the founding campus of the University System of Maryland.

    620 W. Lexington St., Baltimore, MD
    21201 | 410-706-3100

    • The Elm
    • Calendar
    • Emergency
    • Mobile UMB
    • UMB Shuttle
    • myUMB
    • Directory
    • IT Help Desk
    • Facilities Work Request
    • Jobs
    • Middle States
    • Strategic Plan
    • Sustainability
    • Clery Report
    • UMB Hotline
    • UMB on Facebook
    • UMB on X
    • UMB on Instagram
    • UMB on LinkedIn
    • UMB on YouTube
    The University of Maryland, Baltimore prohibits sex discrimination in any education program or activity that it operates. Individuals may report concerns or questions to the Title IX Coordinator. Read the UMB Notice of Non-Discrimination.
    © 2025-2026 University of Maryland, Baltimore. All rights reserved.
    • Privacy Policy
    • Digital Accessibility
    • Web Feedback
    • Non-Discrimination