Information Technology Services

Data Classification, Storage, and Collaboration Requirements

Overview

George Mason University employees and other authorized individuals are responsible for protecting university information throughout its lifecycle. The level of protection required depends on the information’s sensitivity, intended use, and applicable legal, regulatory, or university requirements. Classifying information helps determine the appropriate safeguards, storage locations, access permissions, sharing methods, and retention requirements. Information that requires greater protection must be secured with stronger controls.

Classification helps determine:

  • How it may be shared or transferred
  • How it must be protected
  • How it must be retained and disposed of
  • Where it may be stored
  • Who may access it

Who Must Follow These Requirements

The requirements apply when the following individuals conduct administrative, educational, financial, research, service, or other university business:

  • Affiliates
  • Faculty
  • Independent contractors
  • Other individuals who handle university information
  • Staff
  • Student and Student employees
  • Vendors

Information Covered

These requirements apply to university data, information, and records in any format, including:

  • Audio and video
  • Digital text and files
  • Images
  • Microfilm
  • Other physical or electronic records
  • Paper documents

Handling information includes:

  • Accessing or viewing
  • Creating or collecting
  • Disposing of or destroying
  • Managing or preserving
  • Sharing, transferring, or mailing
  • Storing
  • Using

Before You Store or Share University Information

  • Determine its classification.
  • Follow applicable records-retention and disposal requirements.
  • Identify any legal, regulatory, contractual, security, or university requirements that apply.
  • Identify the information involved.
  • Limit access to individuals with an authorized university business need.
  • Select a Mason-approved storage or collaboration service appropriate for the information’s classification.

IMPORTANT

If a file, dataset, or record contains information from more than one classification, apply the requirements for the highest classification. This approach is known as the high-watermark principle.


Storage Solutions and Data Classification Matrix and Tables

Storage Services/Solution Matrix

Use the following resources to classify information and select an appropriate storage service:

CategoryServiceDescriptionPrimary Use CasesKey Features
Collaboration StorageOneDrivePersonal cloud storage tied to Microsoft 365 for George Mason filesIndividual file storageAccessible from anywhere, multi-device sync, personal library
Microsoft TeamsEnterprise-wide collaboration platform within Microsoft 365Team collaboration, file storage and sharingAccessible from anywhere, synchronous editing, team-based storage
SharePoint Document LibrariesCloud-based document management system in SharePointOrganized team file storage, external sharingAccessible from anywhere, drag-and-drop organization
Enterprise StorageAzure FilesManaged file share service in AzureApp storage, cloud workloadsStandard file system access, scalable cloud storage
Azure BlobObject-based cloud storage in AzureLarge datasets, backups, archives, analyticsHandles unstructured data, highly scalable
Patriot DriveOn-premises enterprise storageAccess databases, automated file transfersLimited use case, internal enterprise system
Research Computing StorageHPC Hot StorageHigh-speed flash storage on HPC clustersActive computation, data analysis, project collaborationHigh performance; hosts /home, /projects, /scratch; external sharing via Globus
HPC Warm StorageHybrid HDD-SSD storageActive analysis, data sharing, long-term storageCost-effective balance of performance and capacity;
Secure Research ComputingControlled research environmentSensitive or regulated research dataSecure laptops and infrastructure, supports export-controlled and unclassified data
Media StorageKaltura MyMedia LibraryPersonal media repository in CanvasVideo, audio, and image storage; Zoom recordingsAutomatically stores Zoom recordings, easy media management within Canvas
Highly Sensitive Data
Storage LocationAdditional InformationProtected – Highly Sensitive DataJustification
Patriot Drive

Secure SharePoint (Refer to Highly Sensitive Data)

NA

The following student Information/ records:
  • Non-directory data
  • Student records (including directory data) flagged as confidential/private.


Attributes defined as ‘Directory Information’ in Mason: FERPA.


For Student Financial Aid that constitutes Federal Tax Information (FTI)**, refer to the separate listing below.

NA

Passwords/PINs and cryptographic private keys associated with User ID and/or system or technology services
  • Cybersecurity and fraud risk considerations

NA

The following attributes when used in this combination should only be released to non-school officials for verification purposes.
  • Student ID (G Number)
  • Date of Birth

NA

Datasets containing Date of Birth
Personally Identifiable Information (PII)*

*Any personal information that can lead to identity theft if exposed.

IMPORTANT: credit card data MUST NEVER be stored on Mason systems.
Social Security Numbers (SSN)
Financial account numbers
Driver’s license, state ID, military ID, passport, visa numbers
Protected Health InformationMedical/mental history, treatment, or diagnoses information; health insurance policy numbers, protected health information in hard copy or electronic formats.

NA

Allegation and investigation records (all roles including students)

NA

Data that must be withheld from release under the Virginia Freedom of Information Act (FOIA).

NA

Engineering, design, or operational information associated with Mason’s infrastructure. Such information should also be evaluated for FOIA exemption.

This would include Network diagrams that contain detailed configuration information or network devices associated with systems categorized as ‘High” category.

NA

Draft financial statements and similar reports that have not been approved for publication or distribution.
  • Drafts that may not be complete or accurate for being ‘work in progress’ can have material negative impact (e.g., reputational) if disclosed without being finalized.
Patriot Drive

Archer Integrated Risk Management (IRM)

NA

Information shared by vendors or other parties under confidentiality or non-disclosure agreements.
  • Contractual obligations
Systems approved to store FTI such as Banner

NIST 800-53 and NIST 800-171 compliant systems only

NA

**Federal Tax Information (FTI) for Federal Student Aid Programs
Secure Research Computing (SRC)** Contact the Office of Research Integrity and Assurance for applicable requirements and control restrictionsResearch Support Services: Export control, Controlled Unclassified Information (CUI)
Rapid Prototyping Research Center*Research Support Services: Controlled Unclassified Information (CUI)
Restricted Data
Storage LocationProtected: RestrictedJustification
George Mason’s subscribed M365 including OneDriveStudent information attributes that may not be released under the directory information exception of FERPA. These are:
  • Student Email
  • Address
  • Phone Number
See Code of Virginia § 23.1-405(C) for conditions.
Unpublished research data that are not classified as Highly Sensitive Data (by the Principal Investigator or the Data Owner)
  • Patent, competitive and commercial potential, intellectual property, work product
G numbers, Cardinal ID (by themselves, without any context or other attributes)
  • Privacy and potential fraud considerations
Employment applications, employee performance evaluations, and personnel files without PII, as well as non-directory contact information
  • Privacy
Personnel and financial information not covered by the definition of Highly Sensitive Data, but not intended to be made public.
  • N/A
Internal communications and email, non-public reports or contracts, intellectual property, and all other information releasable in accordance with the Virginia Freedom of Information Act.
  • Least privilege, need-to-know
Donor contact information and non-public gift information
  • Donor Privacy
Hopper Cluster by Office of Research ComputingResearch project datasets that:
  • Do NOT contain Personally Identifiable Information
  • Are de-identified
Secure custom-configured George Mason-managed encrypted laptop or desktop Research project datasets that:
  • Do NOT contain Personally Identifiable Information
  • Are de-identified
Public Use
Storage LocationPublic Use DataJustification
George Mason’s subscribed M365 including OneDrivePublished directory information (faculty, staff, students, etc.)
Research data that is unrestricted or based on publicly available information
  • Public Use
George Mason’s Public Websites
  • Public Use
Procedure manuals designated by the owner as intended for public use
  • Public Use
Employment advertisements
  • Public Use
Information in the public domain (e.g., campus maps, parking information, published news releases and announcements, events calendars)
  • Public Use

Definitions

Data Owner

A data owner is the university official or designated authority responsible for approving access to and appropriate use of specific university information.

High-Watermark Principle

The high-watermark principle requires applying the controls associated with the highest classification when information from multiple classification levels is stored, shared, or handled together.

Personally Identifiable Information

Personally identifiable information is information that allows an individual’s identity to be reasonably determined through direct or indirect means.

Examples may include:

  • Biometric record
  • Name
  • Other information that can be linked to a specific individual
  • Social Security number
Record

A record is any document, data, or file created or received while conducting public business that provides evidence of that business, regardless of its format or storage medium.

Examples may include:

  • Administrative records
  • Fiscal documentation
  • Student academic files
Data Stewardship

University Policy 1114 establishes responsibilities and general methods for controlling and appropriately managing public and university data. The policy applies to university information systems and uses of public and university data.

Physical and Logical Access Security

University Policy 1312 establishes access and security requirements intended to protect the privacy, security, and confidentiality of university systems.

Records Management

University Policy 1102 establishes responsibilities for managing, retaining, and destroying public records.

Responsible Use of Computing

University Policy 1301 establishes requirements for the appropriate use of Mason computing services.

Additional Resources

Need Help?

The classifications and examples provided in university guidance are not all-inclusive. If information is not listed or you are unsure how to classify, store, or share it:

Related Articles