Kean University – Data Classification & Labeling (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines the repeatable process for classifying and labeling Kean University data using the four approved data classification levels: Public, Internal, Confidential, and Restricted.
This SOP operationalizes the requirements in the Kean University Data Governance & Protection Policy (KU DG 01) and ensures consistent, compliant data handling across all systems and repositories.
Scope
This SOP applies to:
- All University departments that create, store, process, or share data
- Data Owners, Data Stewards, and IT Custodians
- All digital and physical data assets in on‑premises, cloud, and hybrid environments
Both classification (deciding sensitivity) and labeling (applying visible or technical indicators) are covered.
Definitions
- Data Owner – Role accountable for determining the classification of data and approving access.
- Data Steward – Role responsible for applying classifications and labels and maintaining inventories.
- Data Custodian – Kean IT role responsible for enforcing technical controls such as encryption and approved storage.
- Classification – Assignment of a sensitivity level to a data asset.
- Labeling – Application of classification indicators such as metadata, sensitivity labels, or document markings.
Roles & Responsibilities
Data Owners
- Determine and approve data classification
- Review classifications annually or upon material change
Data Stewards
- Apply labels to documents, systems, and repositories
- Ensure handling requirements match classification
- Maintain the Data Classification Register
Data Custodians (Kean IT)
- Configure technical labeling, encryption, and access controls
- Ensure Confidential and Restricted data reside only on approved platforms
Employees
- Handle data according to assigned labels
- Report missing or incorrect classifications
Procedure
Step 1 — Identify the Data Asset
Identify the type of data (student, financial, human resources, research, operational) and document its source and intended use.
Step 2 — Assess Classification Criteria
| Classification | Criteria | Examples |
|---|---|---|
| Public | Approved for public release | Marketing materials, course catalogs |
| Internal | University use only | Internal procedures, department communications |
| Confidential | Sensitive data requiring encryption and multi‑factor authentication | HR records, budgets, evaluations |
| Restricted | Legally regulated, highest risk | FERPA records, health information, financial aid data |
Step 3 — Assign the Classification
The Data Owner selects the appropriate classification. The Data Steward records the decision in the Data Classification Register.
Step 4 — Apply Labels (Digital Assets)
- Microsoft 365 sensitivity labels
- SharePoint classification metadata
- Automated data loss prevention (DLP) labeling
- System‑specific metadata fields
Confidential and Restricted data must be encrypted at rest and in transit.
Step 5 — Apply Labels (Physical Assets)
- Include classification in headers and footers
- Store sensitive records in secured, access‑controlled locations
- Shred Restricted records after retention requirements are met
Step 6 — Verify Handling Requirements
Verify that access controls, storage platforms, and sharing methods align with the assigned classification.
Step 7 — Review & Reclassification
Reclassification is required annually, after regulatory or system changes, or following a security incident. All changes must be documented.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU ID 01 – Identity & Authentication
- KU ID 02 – Access Control
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Identify | ID.IM – Information Management | ID.IM01 |
| Protect | PR.DS – Data Security | PR.DS01, PR.DS02 |
| Protect | PR.AC – Access Control | PR.AC01, PR.AC04 |
Metrics & KPIs
- Percentage of data assets with documented classification
- Percentage of systems with labeling controls enabled
- Annual classification review completion rate
- Number of incidents involving misclassified data
Required Records & Storage
- Data Classification Register (Governance SharePoint site)
- Labeling audit logs (Microsoft 365 Compliance Center)
- Annual review evidence (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Data Governance Lead | Chief Information Security Officer |