Data Management Policy
Purpose
Managing data within an enterprise includes data classification, inventory, handling, retention, and disposal. The Data Management Policy provides the processes and procedures for governing data within the enterprise. This includes creating a data inventory and classifying data based on sensitivity. Additionally, procedures for securely protecting data from unauthorized access or modification alongside appropriate methods for how users should handle their data during their day-to-day work activities. Finally, authorized methods to destroy and remove data from the enterprise are discussed.
Responsibility
- The IT business unit is responsible for securing the enterprise's data as this information is housed on workstations and servers primarily maintained by Information owners are responsible for coordinating data maintenance activities with IT.
- Users have the responsibility to protect data associated with their role from unauthorized access and IT is responsible for informing all users of their responsibilities associated with protecting data entrusted to them.
Exceptions
Exceptions to this policy are likely to occur. Requests for exception must be made in writing and must contain:
- The reason for the request,
- Risk to the enterprise of not following the written policy,
- Specific mitigations that will not be implemented,
- Technical and other difficulties, and
- Date of review.
Policy
Howard Community College began at IG1 in FY26 with a roadmap to IG2 in FY27.
Data Inventory
- IT must conduct an inventory of data on an annual
- All sensitive data must be marked accordingly in the data
- A data owner must be associated with all data tracked within the
- Data with specific data retention needs must be labeled
- All data owners are required to contact IT upon the creation of, or obtaining, sensitive data to ensure the data is tracked within the data inventory.
Data Classification
- PROD and IT must establish and enforce labels for sensitive data.
- PROD and IT must review data classification labels and their usage on an annual basis.
Data Protection
- IT must configure access control lists on enterprise assets in accordance with user's need to know. This is to include laptops, smartphones, tablets, centralized file systems, remote file systems, databases, and all
- Sensitive data must be encrypted on all user
Data Handling
- PROD and IT, with input from relevant data owners, must develop and maintain a written data retention
- All data and documents must be preserved for the appropriate amount of time as dictated by regulatory, legal, and business requirements
Data Disposal
- IT, or other authorized parties, must destroy data that have outlasted their specified retention
- Allusers are required to contact IT before disposing of sensitive
- Non-sensitive data may be disposed of without speaking to IT via common destruction methods (e.g., trash, commonplace deletion from a computer system).
- Sensitive data destruction must be performed in a manner that preserves
- Reports, correspondence, and other printed media:
- Shredding - Documents must be shredded using approved cross-cut shredders,
- Shredding Bins - Disposal must be performed using locked bins located on-site using an IT approved shredding service, or
- Incineration - Materials are_ physically destroyed using an IT approved incineration service.
- Portable Media (e.g., Solid State Drives (SSDs), digital, video discs (DVDs), universal serial bus (USB) data storage devices):
- Reports, correspondence, and other printed media:
Physical Destruction - Complete destruction of media by means of shredding, crushing, or disassembling the asset and ensuring no data can be recovered.
- Hard Disc Drives (HDDs) and other magnetic media to include printer and copier hard-drives:
- Overwriting - Using a program to write binary data sector by sector onto the media, or
- Physical Destruction - Crushing, disassembling, or degaussing the asset to ensure no data can be extracted or recreated.
- Tape Cartridges
- Degaussing - Using strong magnets or electric degaussing equipment to magnetically scramble the data on a hard drive into an unrecoverable state, or
- Physical Destruction - Complete destruction of the
- Third-party service provider systems (e.g., cloud services) must be disposed of by first requesting the appropriate methods to permanently delete data stored in their systems, and then performing those actions according to the received instructions.
- All destruction of data must be logged in the data inventory, when
IT must obtain proof of destruction if using a third-party disposal contractor.
Appendix A: Acronyms and Abbreviations
- CIS Center for Internet Security
- CIS Controls Center for Internet Security Critical Security Controls
- COTS Commercial-off-the-shelf
- DVD Digital Video Discs
- GDPR General Data Protection Regulation
- HOD Hard Disk Drives
- IaaS Infrastructure as a Service (IaaS)
- IG Implementation Group
- IoT Internet of Things
- IT Information Technology
- PII Personal Identifiable Information
- PROD Planning, Research, and Organizational Development
- SSD Solid State Drives
- SSN Social Security Number
- USB Universal Serial Bus
Appendix B: Glossary
|
Asset |
Anything that has value to an organization, including, but not limited to, another organization, person, computing device, information technology (IT) system, IT network, IT circuit, software (both an installed instance and a physical instance), virtual computing platform (common in cloud and virtualized computing), and related hardware (e.g., locks, cabinets, keyboards). Source: Asset(s) - Glossary I CSRC (nist.gov) |
|
Asset inventory |
An asset inventory is a register, repository or comprehensive list of an enterprise's assets and specific information about those assets.
Source: Asset Inventory I FIA (dot.gov\ |
|
Asset owner |
The department, business unit, or individual responsible for an enterprise asset. Source: CIS |
|
Cloud environment |
A virtualized environment that provides convenient, on-demand network access to a shared pool of configurable resources such as network, computing, storage, applications, and services. There are five essential characteristics to a cloud environment: on-demand self service, broad network access, resource pooling, rapid elasticity, and measured service. Some services offered through cloud environments include Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (laaS). |
|
Enterprise assets |
Assets with the potential to store or process data. For the purpose of this document, enterprise assets include end-user devices, network devices, non-computing/Internet of Things (loT) devices, and servers in virtual, cloud-based, and physical environments. Source: CIS Controls v8 |
|
End-user devices |
Information technology (IT) assets used among members of an enterprise during work, off hours, or any other purpose. End-user devices include mobile and portable devices such as laptops, smartphones, and tablets as well as desktops and workstations. For the purpose of this document, end-user devices are a subset of enterprise assets. Source: CIS Controls v8 |
|
Enterprise asset identifier |
Often a sticker or tag with a unique number or alphanumeric string that can be tracked within an enterprise asset inventory. Source: CIS
|
|
Mobile end-user devices |
Small, enterprise-issued end-user devices with intrinsic wireless capability, such as smartphones and tablets. Mobile end-user devices are a subset of portable end-user devices, including laptops, which may require external hardware for connectivity. For the purpose of this document, mobile end-user devices are a subset of end-user devices. Source: CIS Controls v8 |
|
Network devices |
Electronic devices required for communication and interaction between devices on a computer network. Network devices include wireless access points, firewalls, physical/virtual gateways, routers, and switches. These devices consist of physical hardware as well as virtual and cloud-based devices. For the purpose of this document, network devices are a subset of enterprise assets.
Source: CIS Controls v8 |
|
Non-computing/Internet of Things (lol) devices |
Devices embedded with sensors, software, and other technologies for the purpose of connecting, storing, and exchanging data with other devices and systems over the internet. While these devices are not used for computational processes, they support an enterprise's ability to conduct business processes. Examples of these devices include printers, smart screens, physical security sensors, industrial control systems, and information technology sensors. For the purpose of this document, non-computing/loT devices are a subset of enterprise assets. Source: CIS Controls vs |
|
Physical environment |
Physical hardware parts that make up a network, including cables and routers. The hardware is required for communication and interaction between devices on a network. Source: CIS Controls vs |
|
Portable end-user devices |
Transportable, end-user devices that have the capability to wirelessly connect to a network. For the purpose of this document, portable end-user devices can include laptops and mobile devices such as smartphones and tablets, all of which are a subset of enterprise assets. Source: CIS Controls vs |
|
Remote devices |
Any enterprise asset capable of connecting to a network remotely, usually from public internet. This can include enterprise assets such as end-user devices, network devices, non-computing/Internet of Things (loT) devices, and servers. Source: CIS Controls vs |
|
Servers |
A device or system that provides resources, data, services, or programs to other devices on either a local area network or wide area network. Servers can provide resources and use them from another system at the same time. Examples include web servers, application servers, mail servers, and file servers.
Source: CIS Controls vs |
|
User |
Employees (both on-site and remote), third-party vendors, contractors, service providers, consultants, or any other user that operates an enterprise asset. Source: CIS
|
|
Virtual environment |
Simulates hardware to allow a software environment to run without the need to use a lot of actual hardware. Virtualized environments are used to make a small number of resources act as many with plenty of processing, memory, storage, and network capacity. Virtualization is a fundamental technology that allows cloud computing to work.
Source: CIS Controls v8 |