Policies, Standards & Classification

Classify before you handle.

Every institutional data asset is assigned a protection level. Classification drives access decisions, security controls, and handling rules-aligned to UC's Institutional Information protection levels (P1–P4).

The four protection levels

Public P1

Information that may be disclosed freely; no harm results from its release.

e.g. published directories, course catalogs.
 

Internal P2

Information for university business use; not intended for public release.

e.g. internal reports, operational data.
 

Confidential P3

Information protected by policy or law; disclosure causes harm to individuals or the university.

e.g. student records, personnel data.
 

Restricted P4

Information requiring the highest protection; disclosure causes severe harm or legal exposure.

e.g. SSNs, health, financial account data.
 

Classification drives everything downstream.

A data asset's protection level determines who may access it, what security controls apply, how it may be stored and shared, and how it is handled through its lifecycle. Classification is the first step-done before access is granted or data is used.

View UC Protection Levels (P1–P4) ↗