Everyone at Ohio State handles data. Whether it's their personal information, someone else's or valued research, we're often balancing our need for security with our desire to preserve the open, information-sharing mission of our academic culture.
The Institutional Data Policy (IDP) outlines requirements for protecting institutional data in accordance with legal, regulatory, administrative, and contractual requirements; intellectual property and ethical considerations; strategic or proprietary value; and/or operational use. All institutional data is assigned one of four data classifications, and the university’s Information Security and Privacy Standard (ISPS) and Information Security Control Requirements define the security and privacy controls required to protect it. If you have a data element that has previously not been classified or you believe a data element needs to be re-classified, please submit your request via our ServiceNow form. To help understand institutional data, its use, and how to protect it, everyone must take training or awareness based on the type of data they can access.
View the Institutional Data Policy Access the IDP Calculator How to Use the IDP Calculator
What is Institutional Data?
Ohio State institutional data is information created, collected, maintained, transmitted, or recorded by or for the university to conduct university operations. It includes research data and data used for planning, managing, operating, controlling, or auditing university functions, operations, and mission, but does not include personally created data. Institutional data includes, but is not limited to, information in paper, electronic, audio, and visual formats.
The university’s institutional data are significant assets that must be properly managed and protected by all members of the university community. The Institutional Data Policy establishes the need to protect institutional data. It goes further to require that all institutional data are assigned one of four data classification levels based on legal, regulatory, university, and contractual requirements; intellectual property and ethical considerations; strategic or proprietary value; operational use; and/or privacy. documents.
If you have any questions about the IDP or using these resources, please contact the Data Governance team at DataGovernance@osu.edu.
The IDP Calculator is available to provide a better understanding of how singular or combined data elements directly relate to security classification levels. For more information on how to use the IDP Calculator, please refer to the IDP Calculator Job Aid.
S-Level Data Classifications
S-level: a security level which links an institutional data classification with a level of effort to protect the institutional data. Four S-levels are defined: S1, S2, S3, and S4.
- S1: Public Institutional Data
- S2: Internal Institutional Data
- S3: Private Institutional Data
- S4: Restricted Institutional Data
Determining Data Classification Levels
Whenever a new data type is added to the IDP calculator, we work with data stewards to ensure we are considering all of the included data elements, the sensitivity of those elements once combined and any other nuances of the data type. There are a number of factors that are considered, including but not limited to the following:
| Criteria | Examples that are considered |
|---|---|
| Who is impacted? (population) | Faculty, staff, students, minors, all |
| How many are impacted? | One person, all staff, students only |
| What is the impact? | Local, widespread, one department, one team |
| What regulations, rules, or laws apply? | PII, HIPAA, Clery |
| Is there a mandated timeframe for reporting a breach? | None, short, long |
| Is there reputational risk? | Personal, university-wide |
| Financial cost of mitigating risk? | ID protection, credit monitoring |
| System criticality level | Critical to proper system operations or business continuity; critical data element such as Employee ID |
| Privacy risk, privacy principles involved | For examples visit the Privacy Principles page |
| Whole data or a piece of the data? | Social security number, partial SSN, part of another document such as a photo on a passport |
| Where is data housed? | PeopleSoft, RAE, Workday, Epic, spreadsheet in OneDrive |
| Where is data exposed? | Public, other units not needed access to the data |
| Is it part of mandatory reporting? | IPEDs, Clery |
| Is it self-reported? | Elect to report after made aware of risk, such as when race is optional |
Protecting Institutional Data
Everyone at Ohio State interacts with institutional data and has a responsibility to be a caretaker of institutional data. Whether it's personal information, someone else's data, or valued research, we're often balancing our need for security with the need to preserve the open, information-sharing mission of our academic culture. To protect the reputation of the university as a leader in higher education, research, business, and as a medical provider, everyone must understand how institutional data is classified and what is the authorized and appropriate use based on the classification.
Training
The university assigns one of four data classifications that define the level of protection based on compliance, privacy, sensitivity, operational use, and risk. The university’s Information Security and Privacy Standard and Information Security and Privacy Control Requirements provide guidance to protect institutional data based on the classification level.
To help everyone understand these classifications and how to properly secure institutional data, all Ohio State and Wexner Medical Center employees, including faculty, staff and student employees, are required to complete Institutional Data Policy training annually. The training is automatically assigned as part of BuckeyeCore to every employee’s transcript in BuckeyeLearn. Wexner Medical Center employees can also review requirements through OneSource and other medical center communications.
- Completion window: Oct. 1 through March 31 at 11:59 p.m. EST
- Access training: Log in to BuckeyeLearn using your Ohio State credentials, select My Transcript on the homepage, locate BuckeyeCORE Curriculum and click Launch.
- Flexible learning: Modules can be completed at an individual pace throughout the completion window. However, exiting a module midway through may reset progress to the beginning of that specific course.
- System requirements: To ensure completion status is recorded accurately, complete all modules on a desktop or laptop computer using a stable internet connection and a modern browser (Google Chrome, Firefox, Edge or Safari).
In the training you will learn about useful resources to help you to understand your responsibilities, how to securely handle institutional data, and how to use Institutional Data Policy (IDP) Calculator.
Frequently Asked Questions
What is Institutional Data?
- Institutional data includes, but is not limited to, information in paper, electronic, audio, and visual formats.
- Institutional data is information created, collected, maintained, transmitted or recorded by or for the university to conduct university business.
- It includes: (a) data used for planning, managing, operating, controlling, or auditing university functions, operations, and mission; and (b) data outlined by requirements in the Research Data policy, information created, collected, and maintained in the conduct or reporting of research at or under the authority of Ohio State, as applicable.
- It does NOT include personal data, which is information that is personal in nature and not related to university business.
- All data created, collected, maintained, transmitted, or recorded by university owned devices, media, or systems must be used in accordance with the Responsible Use of University Computing and Network Resources policy.
What is Restricted (S4) data?
Institutional data that requires the highest level of protection due to legal, regulatory, administrative, contractual, rule, or policy requirements.
To whom does the policy apply?
The Institutional Data Policy applies to all faculty, staff, students, student employees, contractors, volunteers, visitors, sponsored guests of units, and affiliated entities who are acting on behalf of the university.
My job doesn’t require I access institutional data. Do I need to take this?
Yes. The Institutional Data Policy states that everyone the policy applies to is a caretaker of institutional data.
How much time should I plan to complete?
The IDP training takes less than 15 minutes. There is a test-out option if you feel you understand the training content.
Who can I contact with comments, questions, and suggestions?
Start with your manager. If you still have questions, please submit to IDP-Support@osu.edu.
I started recently and took this before the window opened. Do I need to take it again?
Yes. However, the IDP offers a test-out option. If you feel you know the topic, take the test-out. If you do not pass, you will need to complete the course.