Policies, Standards & Classification
Classify before you handle.
Every institutional data asset is assigned a protection level. Classification drives access decisions, security controls, and handling rules-aligned to UC's Institutional Information protection levels (P1–P4).
The four protection levels
Public P1
Information that may be disclosed freely; no harm results from its release.
e.g. published directories, course catalogs.
Internal P2
Information for university business use; not intended for public release.
e.g. internal reports, operational data.
Confidential P3
Information protected by policy or law; disclosure causes harm to individuals or the university.
e.g. student records, personnel data.
Restricted P4
Information requiring the highest protection; disclosure causes severe harm or legal exposure.
e.g. SSNs, health, financial account data.
Classification drives everything downstream.
A data asset's protection level determines who may access it, what security controls apply, how it may be stored and shared, and how it is handled through its lifecycle. Classification is the first step-done before access is granted or data is used.