Purpose

These standards establish expectations for the management, storage, sharing, reporting, and disposal of institutional data and will be reviewed annually or more frequently as needed. They should be used by employees, students, administrators, and IT personnel who access or use institutional data as part of their role. The Data Standards and Procedures are updated and managed through the UIT Enterprise Data Steering Committee.

Data Standards and Procedures by Topic

Questions regarding data classifications should be directed below if unknown and seeking guidance. 

 

Data Classification

Definition

Examples

Public

Data that has been intended and/or approved for public release. 

Press releases; public website content; campus maps; job postings for hiring purposes; finalized University policy documents; published research data; data from existing public repositories.

Low Risk 

Internal documents or data that pose little risk to the University or campus staff/students if exposed but have not been approved for public release.

Draft communications that have not yet been approved for public release; internal planning documents; internal communications related to University operations; non-sensitive research data otherwise intended to be published without restrictions.

Medium Risk

Review Directory Information for guidance on what may be disclosed by campus.

Data for which release or modification without authorization could have a moderately adverse effect on the operations, assets, or reputation of the University.

 

 

Employee and student ID numbers, including GIDs; employee and student NetIDs; detailed information about University IT assets, such as hostnames, IP addresses, or generalized vulnerability or risk documents; course evaluations; student education records as defined by FERPA; sensitive research data not otherwise intended to be published due to significant proprietary or intellectual property interests.

High Risk

Data that, if released without proper authorization and safeguarding, could have substantial fiscal or legal impacts on the University.

Personally identifiable information, such as Social Security Numbers; financial account numbers; driver’s license numbers; passport or visa numbers; health insurance policy ID numbers; sensitive health information not subject to HIPAA; P-Card numbers, expiration dates, and security codes; personal finance data, such as Federal Tax Information; highly sensitive research data subject to express legal or contractual safeguarding requirements but is not within a Specialized Risk category.

Specialized Risk

Data or information that Montana State University researchers, faculty, or staff may access as part of their work duties, and that has specialized security or training requirements distinct from, or beyond, High Risk data.

Specialized risk data will represent Controlled Unclassified Information (CUI), Protected Health Information, Payment Card Information (PCI), and classified information.

For guidance on how to appropriately protect, store, share, and work with this data, contact the appropriate office or itsecurity@montana.edu.

 

Standards to follow for Data Storage and Sharing:

  • Data Storage guidelines assume FERPA and other legal conditions are met. For example, Medium Risk FERPA PII details are shared within the FERPA constraints.
  • Cloud (OneDrive) reflects MSU Enterprise License and excludes personal accounts
  • Local laptop or desktop hard drives are not a reliable or secure location to store data. If files need to reside on your local hard drive, they should not be the only copy (OneDrive Syncing), and no files containing data of Medium, High, or Specialized Risk may be stored on local hard drives without approval from UIT's Information Security Group.

GID Data Use Considerations: Employee and student identification numbers (GIDs) are internal identifiers that may be used and shared for legitimate University business. They should not be shared more broadly than necessary. The risk of disclosure increases when a GID is connected with a name, username, education or employment record, or other identifying or sensitive information. 

Email Use with Medium-Risk Data: Emails sent outside the university may not be protected by university encryption. This increases the risk that the information could be accessed or shared without permission. When sending this data externally, use additional security measures.

Research Data Considerations: Contact the Research Security contact for specialized risk data storage options that are available through UIT.

Data Classification

 Microsoft storage  products (Copilot, OneDrive,  Teams, SharePoint)

Box

DocuSign

Email

IT Managed Servers

Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data.

Yes

Yes

Yes

Yes

Yes

Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published.

Yes

Yes

Yes

Yes

Yes

Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication.

Yes

Yes

Yes

Yes

Yes

High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements.

No

No

Yes

No

Yes

Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls.

No

No

No

No

No

Data Classification

 Microsoft storage  products (Copilot, OneDrive,  Teams, SharePoint)

Opal

Knox

DocuSign

Email

Blackmore

Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data.

Yes

Yes

Yes

Yes

Yes

Yes

Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published.

Yes

Yes

Yes

Yes

Yes

Yes

Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication.

Yes

Yes

Yes

Yes

Yes

Yes

High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements.

No

No

Yes

Yes

No

No

Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls.

No

No

No

No

No

No

Data Classification

 Microsoft storage  products (Copilot, OneDrive,  Teams, SharePoint)

Knox

DocuSign

Email

Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data.

Yes

Yes

Yes

Yes

Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published.

Yes

Yes

Yes

Yes

Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication.

Yes

Yes

Yes

Yes

High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements.

No

Yes

Yes

No

Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls.

No

No

No

No

Data Classification

 Microsoft storage  products (Copilot, OneDrive,  Teams, SharePoint)

Rigel

DocuSign

Email

Sulafat

Public: Information approved for public release, such as press releases, public website content, campus maps, job postings, finalized policies, and published research data.

Yes

Yes

Yes

Yes

No

Low Risk: Internal information with limited sensitivity, such as draft communications, planning documents, operational emails, and non-sensitive research data intended to be published.

Yes

Yes

Yes

Yes

Yes

Medium Risk: Internal data that requires protection, such as student (GID) or employee IDs, NetIDs, IT asset details, IP addresses, course evaluations, FERPA education records, and sensitive research data with significant proprietary or intellectual property value not intended for publication.

Yes

Yes

Yes

Yes

Yes

High Risk: Sensitive personal, financial, legal, or regulated data, such as SSNs, financial account numbers, driver’s license/passport numbers, health insurance IDs, P-Card data, tax information, and highly sensitive research data subject to express legal or contractual safeguarding requirements.

No

No

Yes

No

Yes

Specialized Risk: Highly regulated or restricted data, such as CUI, HIPAA data, PCI/payment card data, classified information, and research data subject to U.S. Export Controls.

No

No

No

No

No

Under FERPA, “directory information” refers to student information that may be released by an institution without prior written consent, unless the student has opted out of disclosure. Each campus defines its own directory-information categories. The table below compares the data elements each MSU-affiliated campus identifies as directory information.

Campus FERPA sources:

Directory Information

MSU Billings

MSU Bozeman

MSU Great Falls

MSU Northern

Activities and affiliations

Age

Athlete height and weight

Campus address

Campus email address

Class level / classification

College

Date of birth

Dates of attendance

Degrees received / conferred

Division / department / program

Email address

Full-time / part-time status

GPA required for honor or award

Graduation date

Home / permanent address

Honor roll

Honors and awards received

Local address

Major / field of study

Marital status

Most recent institution / school attended

Name of advisor

Parent name and address

Participation in officially recognized activities

Participation in sports

Place of birth

Sex

State of residence

Student name

Student photographic, video, or electronic images

Telephone number

AI tools are useful, but not every tool is approved for every type of university data. Following these guidelines helps protect sensitive information, prevent accidental exposure, and ensure data are used responsibly.

AI Tool

Public Data

Low Risk Data

Medium Risk Data

High Risk Data

Specialized Risk Data

Public AI Tools (Personal OpenAI, Claude..etc)

Yes

No

No

No

No

 Microsoft CoPilot when signed in with MSU Account

Yes

Yes

Yes

No

No

OpenAI CatChat Teams

Yes

Yes

Yes

No

No

Panopto Elai

Yes

Yes

Yes

No

No

Adobe Fire Fly

Yes

Yes

Yes

No

No

CatChat

Yes

Yes

Yes

No

No

AI Tool

Public Data

Low Risk Data

Medium Risk Data

High Risk Data

Specialized Risk Data

Public AI Tools (Personal OpenAI, Claude..etc)

Yes

No

No

No

No

 Microsoft CoPilot when signed in with MSU Account

Yes

Yes

Yes

No

No

 CatChat

Yes

Yes

Yes

No

No

AI Tool

Public Data

Low Risk Data

Medium Risk Data

High Risk Data

Specialized Risk Data

Public AI Tools (Personal OpenAI, Claude..etc)

Yes

No

No

No

No

 Microsoft CoPilot when signed in with MSU Account

Yes

Yes

Yes

No

No

 CatChat

Yes

Yes

Yes

No

No

AI Tool

Public Data

Low Risk Data

Medium Risk Data

High Risk Data

Specialized Risk Data

Public AI Tools (Personal OpenAI, Claude..etc)

Yes

No

No

No

No

 Microsoft CoPilot when signed in with MSU Account

Yes

Yes

Yes

No

No

 CatChat

Yes

Yes

Yes

No

No

The goal of data loss prevention (DLP) is to give users the knowledge and tools they need to manage Personally Identifiable Information (PII) appropriately, in order to minimize data loss, should a breach occur.     

Visit Data Loss Prevention to learn more: https://www.montana.edu/uit/security/dlp/index.html

University records should also be retained and disposed of in accordance with the Montana University System General Record Retention Schedule, which directs MUS campuses to use the schedule for the management and disposition of Montana University System records.

Disposal of computer storage devices

Before repurposing, recycling, transferring, or disposing of devices or storage media, electronic information must be properly purged. This includes internal hard drives, external hard drives, removable media, and other computer storage devices. Disposal of computer storage devices should follow Montana Board of Regents Information Technology Policy 1308 – Disposal of Computers, which states that computer storage devices and removable storage media must be cleaned prior to disposal

Printed material disposal

Paper reports or printed materials containing non-public sensitive information must be shredded before disposal. A cross-cut shredder should be used for these materials.