Information Classification
Every day, colleagues work with information that varies in its sensitivity and how it should be handled. Information must be classified and marked so that everyone who has access to it understands its sensitivity and knows what they need to do to protect it.
The classification of information may change over its lifetime. For example, drafts of communications may be ‘Confidential’ while in draft but ‘Public’ once approved. Some information will require additional handling instructions to be provided or more context for audit purposes.
In some storage locations such as Microsoft 365 technical controls are in place which can enforce activity based on the classification.
What must you do?
- Once information is classified it must be marked to ensure its classification is available to any user handling it.
- Users must consider the classification assigned to a piece of information when storing or transferring the information.
- Users must consider the classification of a piece of information and consult the AI catalogue to determine the appropriate tool that can be used. Please note if specific AI use cases fall outside of the approved information classification for that tool a separate risk assessment will be required, please contact InformationGovernance@exeter.ac.uk for support.
- If information a user receives is not classified or is incorrectly classified, they must consult with the author or originator of the information and either reclassify the received copy or update the source as appropriate.
Classification of information ensures that everyone who uses it understands its value and allows us to enforce handling requirements to make sure our information is safe.
Unrestricted data which is intended to be made available to the general public.
Risk of harm if disclosed: None
UK Government Equivalent: Not Classified
Information not intended for the public at large, but which may be made available to University of Exeter students, peers, and partner organisations through non-public channels.
Risk of harm if disclosed: Low
UK Government Equivalent: Not Classified
Information which may be made available to all University of Exeter employees and associates who require it for their role.
Risk of harm if disclosed: Low
UK Government Equivalent: Official
Information which may be made available to authorised employees in order to carry out their role.
Risk of harm if disclosed: Medium
UK Government Equivalent: Official
Information to which access is strictly controlled and restricted only to predetermined, approved groups or members of staff by name or role.
Risk of harm if disclosed: High
UK Government Equivalent: Official Sensitive
The existence of the information is known only to a very small number of named individuals who have been explicitly cleared for access.
Risk of harm if disclosed: Critical
UK Government Equivalent: Secret and Above
More information about information and records management at University of Exeter can be found on our SharePoint sites.