Data Standards & Procedures
Purpose
These standards establish expectations for the management, storage, sharing, reporting, and disposal of institutional data and will be reviewed annually or more frequently as needed. They should be used by employees, students, administrators, and IT personnel who access or use institutional data as part of their role. The Data Standards and Procedures are updated and managed through the UIT Enterprise Data Steering Committee.
Data Standards and Procedures by Topic
The following points of contact are recommended to receive access to data based by campus.
Questions regarding data classifications should be directed below if unknown and seeking guidance.
- MSU Billings: irdata@msubillings.edu
- MSU Bozeman: data@montana.edu
- MSU Great Falls: data@montana.edu
- MSU Northern: data@montana.edu
|
Data Classification |
Definition |
Examples |
|
Public |
Data that has been intended and/or approved for public release. |
Press releases; public website content; campus maps; job postings for hiring purposes; finalized University policy documents; published research data; data from existing public repositories. |
|
Low Risk |
Internal documents or data that pose little risk to the University or campus staff/students if exposed but have not been approved for public release. |
Draft communications that have not yet been approved for public release; internal planning documents; internal communications related to University operations; non-sensitive research data otherwise intended to be published without restrictions. |
|
Medium Risk Review Directory Information for guidance on what may be disclosed by campus. |
Data for which release or modification without authorization could have a moderately adverse effect on the operations, assets, or reputation of the University.
|
Employee and student ID numbers, including GIDs; employee and student NetIDs; detailed information about University IT assets, such as hostnames, IP addresses, or generalized vulnerability or risk documents; course evaluations; student education records as defined by FERPA; sensitive research data not otherwise intended to be published due to significant proprietary or intellectual property interests. |
|
High Risk |
Data that, if released without proper authorization and safeguarding, could have substantial fiscal or legal impacts on the University. |
Personally identifiable information, such as Social Security Numbers; financial account numbers; driver’s license numbers; passport or visa numbers; health insurance policy ID numbers; sensitive health information not subject to HIPAA; P-Card numbers, expiration dates, and security codes; personal finance data, such as Federal Tax Information; highly sensitive research data subject to express legal or contractual safeguarding requirements but is not within a Specialized Risk category. |
|
Specialized Risk |
Data or information that Montana State University researchers, faculty, or staff may access as part of their work duties, and that has specialized security or training requirements distinct from, or beyond, High Risk data. |
Specialized risk data will represent Controlled Unclassified Information (CUI), Protected
Health Information, Payment Card Information (PCI), and classified information. |
Standards to follow for Data Storage and Sharing:
- Data Storage guidelines assume FERPA and other legal conditions are met. For example, Medium Risk FERPA PII details are shared within the FERPA constraints.
- Cloud (OneDrive) reflects MSU Enterprise License and excludes personal accounts
- Local laptop or desktop hard drives are not a reliable or secure location to store data. If files need to reside on your local hard drive, they should not be the only copy (OneDrive Syncing), and no files containing data of Medium, High, or Specialized Risk may be stored on local hard drives without approval from UIT's Information Security Group.
GID Data Use Considerations: Employee and student identification numbers (GIDs) are internal identifiers that may be used and shared for legitimate University business. They should not be shared more broadly than necessary. The risk of disclosure increases when a GID is connected with a name, username, education or employment record, or other identifying or sensitive information.
Email Use with Medium-Risk Data: Emails sent outside the university may not be protected by university encryption. This increases the risk that the information could be accessed or shared without permission. When sending this data externally, use additional security measures.
Research Data Considerations: Contact the Research Security contact for specialized risk data storage options that are available through UIT.
|
Data Classification |
Microsoft storage products (Copilot, OneDrive, Teams, SharePoint) |
Box |
DocuSign |
|
IT Managed Servers |
|
Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data. |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published. |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication. |
Yes |
Yes |
Yes |
Yes |
Yes |
|
High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements. |
No |
No |
Yes |
No |
Yes |
|
Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls. |
No |
No |
No |
No |
No |
|
Data Classification |
Microsoft storage products (Copilot, OneDrive, Teams, SharePoint) |
Opal |
Knox |
DocuSign |
|
Blackmore |
|---|---|---|---|---|---|---|
|
Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data. |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published. |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication. |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements. |
No |
No |
Yes |
Yes |
No |
No |
|
Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls. |
No |
No |
No |
No |
No |
No |
|
Data Classification |
Microsoft storage products (Copilot, OneDrive, Teams, SharePoint) |
Knox |
DocuSign |
|
|
Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data. |
Yes |
Yes |
Yes |
Yes |
|
Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published. |
Yes |
Yes |
Yes |
Yes |
|
Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication. |
Yes |
Yes |
Yes |
Yes |
|
High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements. |
No |
Yes |
Yes |
No |
|
Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls. |
No |
No |
No |
No |
|
Data Classification |
Microsoft storage products (Copilot, OneDrive, Teams, SharePoint) |
Rigel |
DocuSign |
|
Sulafat |
|
Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data. |
Yes |
Yes |
Yes |
Yes |
No |
|
Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published. |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication. |
Yes |
Yes |
Yes |
Yes |
Yes |
|
High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements. |
No |
No |
Yes |
No |
Yes |
|
Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls. |
No |
No |
No |
No |
No |
Under FERPA, “directory information” refers to student information that may be released by an institution without prior written consent, unless the student has opted out of disclosure. Each campus defines its own directory-information categories. The table below compares the data elements each MSU-affiliated campus identifies as directory information.
Campus FERPA sources:
|
Directory Information |
MSU Billings |
MSU Bozeman |
MSU Great Falls |
MSU Northern |
|---|---|---|---|---|
|
Activities and affiliations |
— |
— |
— |
✓ |
|
Age |
— |
✓ |
— |
— |
|
Athlete height and weight |
✓ |
✓ |
— |
— |
|
Campus address |
— |
✓ |
— |
— |
|
Campus email address |
— |
✓ |
— |
— |
|
Class level / classification |
✓ |
✓ |
— |
✓ |
|
College |
✓ |
✓ |
— |
— |
|
Date of birth |
✓ |
✓ |
— |
— |
|
Dates of attendance |
✓ |
✓ |
✓ |
— |
|
Degrees received / conferred |
✓ |
✓ |
✓ |
✓ |
|
Division / department / program |
— |
✓ |
— |
— |
|
Email address |
✓ |
— |
✓ |
✓ |
|
Full-time / part-time status |
✓ |
— |
— |
— |
|
GPA required for honor or award |
— |
✓ |
— |
— |
|
Graduation date |
— |
✓ |
— |
— |
|
Home / permanent address |
✓ |
✓ |
✓ |
✓ |
|
Honor roll |
✓ |
— |
— |
✓ |
|
Honors and awards received |
✓ |
✓ |
✓ |
✓ |
|
Local address |
✓ |
— |
— |
✓ |
|
Major / field of study |
✓ |
✓ |
✓ |
✓ |
|
Marital status |
— |
✓ |
— |
— |
|
Most recent institution / school attended |
✓ |
✓ |
— |
— |
|
Name of advisor |
— |
✓ |
— |
— |
|
Parent name and address |
— |
✓ |
— |
— |
|
Participation in officially recognized activities |
✓ |
✓ |
✓ |
✓ |
|
Participation in sports |
✓ |
✓ |
— |
— |
|
Place of birth |
✓ |
✓ |
— |
— |
|
Sex |
— |
✓ |
— |
— |
|
State of residence |
— |
✓ |
— |
— |
|
Student name |
✓ |
✓ |
✓ |
✓ |
|
Student photographic, video, or electronic images |
— |
✓ |
— |
— |
|
Telephone number |
✓ |
✓ |
✓ |
✓ |
AI tools are useful, but not every tool is approved for every type of university data. Following these guidelines helps protect sensitive information, prevent accidental exposure, and ensure data are used responsibly.
| AI Tool |
Public Data |
Low Risk Data |
Medium Risk Data |
High Risk Data |
Specialized Risk Data |
| Public AI Tools (Personal OpenAI, Claude..etc) |
Yes |
No |
No |
No |
No |
| Microsoft CoPilot when signed in with MSU Account |
Yes |
Yes |
Yes |
No |
No |
| OpenAI CatChat Teams |
Yes |
Yes |
Yes |
No |
No |
| Panopto Elai |
Yes |
Yes |
Yes |
No |
No |
| Adobe Fire Fly |
Yes |
Yes |
Yes |
No |
No |
| CatChat |
Yes |
Yes |
Yes |
No |
No |
| AI Tool |
Public Data |
Low Risk Data |
Medium Risk Data |
High Risk Data |
Specialized Risk Data |
| Public AI Tools (Personal OpenAI, Claude..etc) |
Yes |
No |
No |
No |
No |
| Microsoft CoPilot when signed in with MSU Account |
Yes |
Yes |
Yes |
No |
No |
| CatChat |
Yes |
Yes |
Yes |
No |
No |
| AI Tool |
Public Data |
Low Risk Data |
Medium Risk Data |
High Risk Data |
Specialized Risk Data |
| Public AI Tools (Personal OpenAI, Claude..etc) |
Yes |
No |
No |
No |
No |
| Microsoft CoPilot when signed in with MSU Account |
Yes |
Yes |
Yes |
No |
No |
| CatChat |
Yes |
Yes |
Yes |
No |
No |
| AI Tool |
Public Data |
Low Risk Data |
Medium Risk Data |
High Risk Data |
Specialized Risk Data |
| Public AI Tools (Personal OpenAI, Claude..etc) |
Yes |
No |
No |
No |
No |
| Microsoft CoPilot when signed in with MSU Account |
Yes |
Yes |
Yes |
No |
No |
| CatChat |
Yes |
Yes |
Yes |
No |
No |
The goal of data loss prevention (DLP) is to give users the knowledge and tools they need to manage Personally Identifiable Information (PII) appropriately, in order to minimize data loss, should a breach occur.
Visit Data Loss Prevention to learn more: https://www.montana.edu/uit/security/dlp/index.html
University records should also be retained and disposed of in accordance with the Montana University System General Record Retention Schedule, which directs MUS campuses to use the schedule for the management and disposition of Montana University System records.
Disposal of computer storage devices
Before repurposing, recycling, transferring, or disposing of devices or storage media, electronic information must be properly purged. This includes internal hard drives, external hard drives, removable media, and other computer storage devices. Disposal of computer storage devices should follow Montana Board of Regents Information Technology Policy 1308 – Disposal of Computers, which states that computer storage devices and removable storage media must be cleaned prior to disposal
Printed material disposal
Paper reports or printed materials containing non-public sensitive information must be shredded before disposal. A cross-cut shredder should be used for these materials.
