Text Only Version

Guidelines for Handling Sensitive Information


Mishandling of sensitive information is a significant risk to the University, and may cause considerable financial or reputational harm. It is the responsibility of all UGA personnel, regardless of position, to protect sensitive information by being aware of any sensitive information they may be handling, retaining, or transmitting. It is also the responsibility of UGA system administrators to keep track of which of their systems contain or use sensitive information. Please use the guideline below as recommendations for how to best protect sensitive information.

A definition of sensitive information can be found on the University's Information Classification Standard, while more technical recommendations for securing systems that store or process sensitive information can be found in the University Guidelines for Trusted Computing.

Click any statement to reveal the official text and commentary where available.
Expand All   View Printable Version

Guidelines

  1. Employees are expected to have a sufficient understanding of "sensitive" information.
  2. Sensitive information may only be collected, stored, or processed if a need to do so exists, and if that need cannot be satisfied in any other way.
  3. Employees are expected to be aware of the sensitive information for which they are responsible and the purpose of its use.
  4. Access to sensitive information should be kept on a "need to know" basis.
  5. Access to sensitive information should only be allowed to "trusted" individuals.
  6. Employees should not access or seek to access sensitive information without authorization.
  7. Sensitive information must be stored securely.
  8. When transmission of sensitive data is required, use only secure methods.
  9. Sensitive information must be destroyed when it is no longer needed.
  10. When loss of or unauthorized access to information has been detected, or if it is suspected, the Office of Information Security must be notified.