Understanding data sensitivity is critical to an effective sensitive data management strategy. The variety of data types and combinations factor into the sensitivity level of files and documents containing them. This presents a challenge when trying to clearly define the metrics by which they are classified. The following information is offered as guidance to users for handling sensitive information. All departments are required to submit Business Impact Analysis documentation that is part of the suite of actions utilized to ensure proper sensitive data management. The college Information Security Officer (ISO) is tasked with assisting departments on matters of sensitive data management and risk assessments for the data storage requirements required to fulfil their mission. All inquiries regarding security of sensitive information should be directed to the Help Desk at 540-857-7354, by email at HelpDesk@virginiawestern.edu or by submission of a ticket in Team Dynamix.
Definitions
Sensitive Data: Sensitive Data is information that requires protection because its disclosure, misuse, or unauthorized access could lead to harm, discrimination, or adverse consequences for individuals or organizations. This includes personal information like health records, tax returns or financial details, demographic data, and confidential business information such as trade secrets. Protecting sensitive data is crucial to prevent identity theft, financial loss, reputational damage, and violations of privacy
Encrypted: Encrypted means to encode the data in such a manner as to render it unreadable without an encryption key, as defined by accepted encryption standards.
Redacted: Redacted implies alteration (black out) or (omit or truncate) data such that no more than parts of the information are accessible as part of the information provided. It is often used to mask sensitive data from unauthorized access while providing it in context with other non-sensitive information
Reversible Encryption: Information of a sensitive nature should only be encrypted using encryption techniques provided by the college’s computer systems. Use of encryption technologies on college business data that are not capable of being reversed by administrative processes authorized by IET is strictly prohibited.
Sensitive PII and Non-Sensitive PII Data Types
Sensitive PII
Sensitive PII is typically not publicly available. Many data privacy laws require organizations to safeguard it by encrypting it, controlling who accesses it and taking other security measures.
Examples of sensitive PII include:
- Unique identification numbers, such as driver’s license numbers, social security numbers (SSN), passport numbers and other government-issued ID numbers
- Biometric data, such as fingerprints and retinal scans
- Financial information, including bank account numbers and credit card numbers
- Medical records
- Electronic and digital account information, such as email addresses and internet account numbers
- Employee personnel records
- Password information
- School identification numbers
Non-sensitive PII
Non-sensitive PII is information that may or may not be unique to an individual person. This type of data can be transmitted without being encrypted, and disclosure of it will not cause harm to the individuals that the data concerns. Non-sensitive PII tends to be publicly available – for example, phone numbers can be listed in a phone book. Some data privacy regulations don’t require the protection of non-sensitive PII, but companies should still employ safeguards to limit the risks to individuals.
Examples of non-sensitive PII include:
- A person’s full name.
- Mother’s maiden name.
- Social media nickname.
- Telephone number.
- IP address.
- Place of birth.
- Date of birth.
- Geographical details (ZIP code, city, state, country, etc.).
- Employment information.
- Email address or mailing address.
- Race or ethnicity.
- Religion.
Important: Sensitive data shall not be stored on portable storage devices in unencrypted form!
In the event of a business requirement to store sensitive data on a portable device, documentation of the nature of the data, justification for storing it on portable media must be submitted in writing to the Chief Information Officer CIO and Information Security Officer ISO along with documentation of processes that will be used to secure this data. Information and Educational Technologies will work with the data owner to establish encryption of this storage in compliance with the applicable state, VCCS and college guidelines.
Hours
Mon – Fri: 7:45 AM – 5:00 PM
Contact Us
Business Science M269
540-857-7354
helpdesk@virginiawestern.edu (Students)
Submit a Ticket (Faculty & Staff)
Report an IT Security Incident
VWCC Alerts
We use the VW Mass Notification System to immediately contact you during a major crisis or emergency. Get more info and register!
