home Future Students Current Students Faculty and Staff Business and Community Online Courses
 
Information Classification and Handling Standard

 

Information Classification

There are four classifications of MCC information:

 

Public – Information that is readily available or disclosed to all parties.

Internal – Information that is intended for a widespread distribution to MCC employees.

Sensitive – Information that is intended only for a limited audience within MCC, or whose release would likely have a materially adverse effect on MCC, employees or students.

Confidential – Highly sensitive information that is intended only for a limited audience within MCC with a need-to-know or whose release would likely have a materially adverse effect on MCC, employees, or students.

Data should be handled as stated in the Data Classification Standard.  All other data at MCC is to be presumed to be at least “Internal” unless you have solid reason to believe otherwise.  In all circumstances, use sound business judgment and not publicly release any unlabeled information unless it is confirmed with the applicable area’s VP that it is public information.

 

 

Internal

Sensitive

Confidential

Storage

Physical

Store in locked tape cabinet daily as directed by management.

Transportation

Do not leave media unattended in vehicles or offices, directly transport tapes from data center into designated locked cabinets.

Physical

Store in locked tape cabinet daily as directed by management.

Transportation

Do not leave media unattended in vehicles or offices, directly transport tapes from data center into locked cabinets.

Incident

Report any missing or stolen tapes immediately to your manager.

Colleague

Store at remote site monthly.

ITS

Store at remote site weekly.

Physical

Store in locked tape cabinet daily as directed by management.

Transportation

Do not leave media unattended in vehicles or offices, directly transport tapes from data center into locked cabinets.

Incident

Report any missing or stolen tapes immediately to your manager.

Colleague

Store at remote site monthly.

ITS

Store at remote site weekly.

Note:  Data that should never be stored:

The Primary Account Number (PAN).

The full contents of any track from the magnetic stripe (on the back of the card, in a chip, etc.)

The three-digit or four-digit Card Verification Value data (CVV2, CVC2) printed on the front or back of a payment card.

The PIN Verification Value (PVV).

Labeling

 

“Confidential – Property of MCC” must be marked on all media.

“Confidential – Property of MCC” must be marked on all media.

Disposal

Tapes should be placed in an Iron Mountain container for shredding.

Tapes should be placed in an Iron Mountain container for shredding.

Tapes should be placed in an Iron Mountain container for shredding.

E-Mail, instant messaging, chat

   

Do not use to send confidential information.

Transfer

 

Use a secure encrypted link.

Use a secure encrypted link.

 

Version

Date

Approver

Change Description

1.0

8/15/2011

Information Security Steering Committee

Initial construction

1.0 8/13/2012 Information Security Steering Committee Annual Review

 

Back to Technology Procedures

Top

 
 
 
Contact Us