Information Technology Security at UVa

Guidelines for Identifying Sensitive and Legally-Protected Data

How can I tell if there is sensitive data on the machine?

  1. Pay attention to the work that the individual does. For example, if the person is a researcher, ask about research data that may contain names or other identifying tags. Ask if the research data should be secret and known only to the department. For example, if the person works in Procurement, think about tax IDs, which can be Social Security numbers.
  2. Ask this question: "If data on the drive was in the newspaper, would it be embarrassing for you or the department?"
  3. Contact the supervisor of the individual and ask about the type of work performed by this person.
  4. Be aware of the types of legally protected data:
    1. Sensitive University Data as defined in the Administrative Access Policy. (Examples)
    2. FERPA
    3. HIPAA
    4. GLBA
  5. Be aware of agreements with external parties such as data covered under Non-Disclosure Agreements, Confidentiality Agreements, Proprietary Information Agreements, or otherwise restricted from distribution. Examples of third parties include Department of Homeland Security, Department of Defense, and National Institute of Health. Also, be aware of International Traffic in Arms Regulations and Export Administration Regulations.
  6. If you do not feel confident in the answers provided and feel the drive needs further investigation, contact the IT Security and Policy Office where a copy of the drive can be made. The copy will be given to the department for further searching.

© 2008 by the Rector and Visitors of the University of Virginia.

The information contained on the University of Virginia’s Department of Information Technology and Communication (ITC) website is provided as a public service with the understanding that ITC makes no representations or warranties, either expressed or implied, concerning the accuracy, completeness, reliability or suitability of the information, including warrantees of title, non-infringement of copyright or patent rights of others. These pages are expected to represent the University of Virginia community and the State of Virginia in a professional manner in accordance with the University of Virginia’s Computing Policies.