Data at Rest Policy
Version 1.0.2
For Students, Faculty, Staff, Guests, Alumni
Purpose
The purpose of this policy is to govern how University data is stored.
Scope
This policy applies to all data stored by all employees, contractors, consultants, temporary, and other workers at the University, including all personnel affiliated with third parties conducting University business. All data covered by the scope of this policy will be classified as Fordham Protected Data, Fordham Sensitive Data, or Public Data.
Policy Statement
Fordham Protected Data, Fordham Sensitive Data, or Public Data must be stored according to the Data Classification Guidelines.
Related Policies and Procedures
- Acceptable Uses of IT Infrastructure and Resources Policy
- Data Classification Guidelines
- Data Classification Policy
- Data in Transit Policy
- Disk Encryption Policy
Implementation Information
Review Frequency | Triennial |
---|---|
Responsible Person | Senior Director of IT Security and Assurance |
Approved By | CISO |
Approval Date | May 22, 2018 |
Revision History:
Version | Date | Description |
---|---|---|
1.0 | 01/23/2017 | Initial policy. |
1.0.1 | 02/07/2018 | Minor edits are pointing to existing policies and the renamed Acceptable Uses of IT Infrastructure and Resources Policy. There are no substantial changes to this policy. |
1.0.2 | 05/22/2018 | Updated disclaimer statement. |
06/09/2020 | Periodic review. No changes. | |
07/26/2023 | Periodic review. No changes. |
Policy Disclaimer Statement
Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) may only be done cooperatively between ISA and the requesting entity with sufficient time to allow for appropriate risk analysis, documentation, and possible presentation to authorized University representatives. Failure to adhere to ISA written policies may be met with University sanctions.