Information Security Management and Compliance
California State University, Long Beach's databases and files, regardless of format, are essential public resources that must be protected from unauthorized use, access, disclosure, modification, loss, or deletion. However, the appropriate level of physical, technical and administrative safeguards necessary to provide protection is relative to the value, legal requirements, sensitivity and criticality of the information.
The California State University, Long Beach Information Classification and Protection Standard establishes information classification levels based on these factors; describes the types of information residing at each level; and prescribes the safeguards to protect university information assets.
The CSULB Information Classification and Protection Standard applies to all information in written format that is collected, generated, and/or maintained by CSU Long Beach and CSU Long Beach auxiliary organizations except where superseded by grant, contract, or federal copyright law
The California State University (CSU) has identified three (3) classification levels of University information referred to as Level 1, Level 2, and Level 3. Types of university information are assigned to each level based on the value, legal requirements, sensitivity and criticality assigned to them.
Aggregates of information shall be classified based upon the most secure classification level. That is, when information of mixed classifications exists in the same file, document or other written format, the entire file, document, etc. shall be classified at the most secure classification level.
Confidential Information is information maintained by the University that is exempt from disclosure under the provisions of the California Public Records Act or other applicable state or federal laws.
Confidential information is information whose unauthorized use, access, disclosure, acquisition, modification, loss, or deletion could result in severe damage to CSULB, its students, employees, or customers. Financial loss, damage to CSULB's reputation, and legal action could occur. Level 1 information is intended solely for use within CSULB and limited to those with a "business need-to know." Statutes, regulations, other legal obligations or mandates protect much of this information. Disclosure of Level 1 information to persons outside of the University is governed by specific standards and controls designed to protect the information. Level 1 information includes, but is not limited to:
Internal use information is information which must be protected due to proprietary, ethical or privacy considerations. Although not specifically protected by statute, regulations, or other legal obligations or mandates, unauthorized use, access, disclosure, acquisition, modification, loss or deletion of information at this level could cause financial loss, damage to CSULB's reputation, violate an individual's privacy rights or legal action could occur. Level 2 information includes, but is not limited to:
Non-directory student information may not be released except with Enrollment Services approval under prescribed conditions.
This is information that is generally regarded as publicly available. Information at this level is either explicitly defined as public information or intended to be available to individuals both on and off campus or not specifically classified elsewhere in this standard. Knowledge of this information does not expose CSULB to financial loss or jeopardize the security of CSULB's information assets. Level 3 information may be subject to appropriate campus review or disclosure procedures to mitigate potential risks of inappropriate disclosure. Level 3 information includes, but is not limited to:
Note: The University may disclose the above information without prior written consent, unless the student has requested that certain information not be released (non-disclosure).
This table describes the protection measures required for each information classification level.
| Confidential Level 1 |
Internal Use Level 2 |
PublicLevel 3 | |
|---|---|---|---|
Handling |
Please refer to the Clean Desk and Clear Screen Standard. |
Same as Level 1 |
No restrictions |
Transmitting |
Distribution: Limited to those employees with an established business need-to-know and are either CSULB employees or who someone who has signed a confidentiality agreement. Electronic Mail (email or attachments to email: May be sent within the CSULB email system (@csulb.edu) but not over a public network unless password protected or encrypted. All email transmissions of confidential information must contain the follow statement: "The information contained in this email message or its attachment is confidential. Dissemination or copying of this email is strictly prohibited. If you think that you have received this email in error, please email the sender." Mail (hard copy): Printed information may be sent through intercampus or U.S. mail but must be sealed in a plain envelope clearly marked, "To be Opened by Addressee Only". FAX: Authorized only from and to CSULB FAX machines. Information may not be sent to public FAX machines. Telephone: Authorized, but only to CSU employees and others with a business need-to-know. |
Distribution: Transmission only to CSULB employees and those individuals with a business need-to-know. Electronic Mail (email or attachments to email): May be sent within the CSULB email system (@csulb.edu) or over a public network to persons with a business need-to-know. Mail (hard copy): Printed information may be sent through intercampus or U.S. mail with no special markings or handling. FAX: Same as Level 1. Telephone: Same as Level 1. |
No restrictions |
Storage |
Must be stored on secured databases or file servers. When access to a secure server is not available and when approved by the employee's Appropriate Administrator, Level 1-Confidential Information may be stored on laptops, desktops or portable electronic storage media, including but not limited to, CD-ROMs, DVD-ROMs, external hard drives, zip disks, floppy disks, reel and cassette format magnetic tapes, flash-memory cards, magnetic cards and USB flash drives (a.k.a. Memory Sticks, Thumb or Jump Drives. Laptops, desktops and portable electronic storage media must be encrypted or otherwise rendered unreadable and unusable by unauthorized persons and must be located in a secure location at the University or another site approved by ITS management (including off-site backup services). Level 1 information may not be stored on personal equipment such as personal laptops, personal desktops, personal digital assistants (PDAs) iPods® or cell phones (such as BlackBerry®, Treo®, and iPhones®. See Note 1 for prohibitions regarding the storage of specific Payment Related Data. Printed information must be stored in a locked enclosure. |
Same as Level 1. |
No restrictions |
Retention |
Records of any type of medium, such as paper, microfiche, magnetic, or optical, shall not be retained beyond the minimum retention period identified in the CSU Record Retention Schedule. |
Same as Level 1 |
Same as level 1 |
Destruction |
Destroy in accordance with the campus Media Sanitation Standard. |
Same as Level 1 |
Normal waste disposal |
Note 1: Payment Related Data The Primary Account Number (PAN) may not be stored unless encrypted.
The following types of payment related data may not be stored even if encrypted: