Kean University DG – Data Classification & Labeling (SOP) 1


Kean University – Data Classification & Labeling (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines the repeatable process for classifying and labeling Kean University data using the four approved data classification levels: Public, Internal, Confidential, and Restricted.

This SOP operationalizes the requirements in the Kean University Data Governance & Protection Policy (KU DG 01) and ensures consistent, compliant data handling across all systems and repositories.

Scope

This SOP applies to:

  • All University departments that create, store, process, or share data
  • Data Owners, Data Stewards, and IT Custodians
  • All digital and physical data assets in on‑premises, cloud, and hybrid environments

Both classification (deciding sensitivity) and labeling (applying visible or technical indicators) are covered.

Definitions

  • Data Owner – Role accountable for determining the classification of data and approving access.
  • Data Steward – Role responsible for applying classifications and labels and maintaining inventories.
  • Data Custodian – Kean IT role responsible for enforcing technical controls such as encryption and approved storage.
  • Classification – Assignment of a sensitivity level to a data asset.
  • Labeling – Application of classification indicators such as metadata, sensitivity labels, or document markings.

Roles & Responsibilities

Data Owners

  • Determine and approve data classification
  • Review classifications annually or upon material change

Data Stewards

  • Apply labels to documents, systems, and repositories
  • Ensure handling requirements match classification
  • Maintain the Data Classification Register

Data Custodians (Kean IT)

  • Configure technical labeling, encryption, and access controls
  • Ensure Confidential and Restricted data reside only on approved platforms

Employees

  • Handle data according to assigned labels
  • Report missing or incorrect classifications

Procedure

Step 1 — Identify the Data Asset

Identify the type of data (student, financial, human resources, research, operational) and document its source and intended use.

Step 2 — Assess Classification Criteria
Classification Criteria Examples
Public Approved for public release Marketing materials, course catalogs
Internal University use only Internal procedures, department communications
Confidential Sensitive data requiring encryption and multi‑factor authentication HR records, budgets, evaluations
Restricted Legally regulated, highest risk FERPA records, health information, financial aid data
Step 3 — Assign the Classification

The Data Owner selects the appropriate classification. The Data Steward records the decision in the Data Classification Register.

Step 4 — Apply Labels (Digital Assets)
  • Microsoft 365 sensitivity labels
  • SharePoint classification metadata
  • Automated data loss prevention (DLP) labeling
  • System‑specific metadata fields

Confidential and Restricted data must be encrypted at rest and in transit.

Step 5 — Apply Labels (Physical Assets)
  • Include classification in headers and footers
  • Store sensitive records in secured, access‑controlled locations
  • Shred Restricted records after retention requirements are met
Step 6 — Verify Handling Requirements

Verify that access controls, storage platforms, and sharing methods align with the assigned classification.

Step 7 — Review & Reclassification

Reclassification is required annually, after regulatory or system changes, or following a security incident. All changes must be documented.


  • KU DG 01 – Data Governance & Protection Policy
  • KU DG 02 – Data Access & Privacy Policy
  • KU ID 01 – Identity & Authentication
  • KU ID 02 – Access Control
  • KU IT 03 – Cybersecurity Training & Awareness

Compliance Mapping

NIST CSF Function Category Subcategory
Identify ID.IM – Information Management ID.IM01
Protect PR.DS – Data Security PR.DS01, PR.DS02
Protect PR.AC – Access Control PR.AC01, PR.AC04

Metrics & KPIs

  • Percentage of data assets with documented classification
  • Percentage of systems with labeling controls enabled
  • Annual classification review completion rate
  • Number of incidents involving misclassified data

Required Records & Storage

  • Data Classification Register (Governance SharePoint site)
  • Labeling audit logs (Microsoft 365 Compliance Center)
  • Annual review evidence (GRC repository)

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Data Governance Lead Chief Information Security Officer

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.