University Policies
924 Data Security and Handling Policy
Approved by President
Effective Date: August 31, 2026
Responsible Division: Information Technology
Responsible Office: Information Technology
Responsible Officer: Vice President for Information Technology
I. Purpose
This policy describes the requirements and standards for securing 乐播传媒入口 (MTSU) data and its handling. The policy applies to the data and information that is created, maintained, used, or displayed, wholly or in part, and in any data format, including, but not limited to, digital, oral, or written words, screen display, electronic transmission, stored media, printed material, facsimile, or other data medium as utilized.
II. Scope
This policy applies to all University faculty, staff, students, affiliates, third-party support contractors, and all others granted access to MTSU information assets.
III. Definitions
- Data 鈥 information, regardless of medium, that can be processed, transmitted, or stored.
- Data User 鈥 any University administrators, faculty, staff, students, affiliates, third-party support contractors, and all others granted access to MTSU data.
IV. Policy
All data users must adhere to the requirements applicable to each data classification as defined by MTSU Policy 922 Data Classification.
V. Data Security and Visual Identifiers (Labeling)
- Level I: Public Information: Information in this category does not require any colored marking or notation and is not restricted in its distribution or handling.
- Level II: General Information: Information in this category must be marked or denoted with a 鈥淟evel II: General鈥 footer, when technically feasible text should be in blue. When stored or transmitted electronically, General Information is not required to be encrypted, but access must be limited to employees, contracted entities, or research partners conducting 乐播传媒入口 business, or research General Information must not be transferred, transmitted, or disseminated externally, except on official business, and must follow MTSU Policy 121 Privacy of Information.
- Level III: Restricted Information: Information in this category must be marked or denoted with a 鈥淟evel III: Restricted鈥 footer, when technically feasible text should be in orange. When stored or transmitted electronically, Restricted Information must be encrypted at a minimum of AES 128-bit encryption. Access to Restricted Information must be limited to employees, contracted entities, or research partners conducting 乐播传媒入口 business or research. Restricted Information in a non-electronic format must be secured in a locked location when not in use. Distribution of Restricted Information should only be on a need-to-know basis.
- Level IV: Confidential Information: Confidential Information must be marked or denoted as such with a 鈥淟evel IV: Confidential鈥 footer, when technically feasible text should be in red. When stored or transmitted electronically, Confidential Information must be encrypted at the highest available level, preferably AES 256-bit encryption or higher. On systems where AES 256-bit encryption is not available, the minimum acceptable encryption is AES 128-bit encryption, unless express written exception is obtained from the Chief Information Security Officer or their designee. Access must be limited to employees, contracted entities or research partners conducting 乐播传媒入口 business or research. Confidential Information in a non-electronic format must be secured in a locked location when not in use. Distribution of Confidential Information should only be on a need-to-know basis.
VI. Data Storage
- Level I: Public Information: Information may be saved and stored on any medium without restriction.
- Level II: General Information: When stored or transmitted electronically, General Information is not required to be encrypted, but access must be limited to employees or contracted entities conducting 乐播传媒入口 business. General Information must not be transferred, transmitted, or disseminated externally, except on official business, and must follow security best practices. Cloud storage is only permitted with MTSU contracted storage providers or MTSU ORSP approved providers that meet storage requirement above.
- Level III: Restricted Information: When stored or transmitted electronically, Restricted Information must be encrypted at no less than AES 128-bit encryption. Access to Restricted Information must be limited to employees or contracted entities conducting 乐播传媒入口 business. Information in a non-electronic format must be secured in a locked location when not in use. Distribution of Restricted Information should only be on a need-to-know basis.聽 Cloud storage is only permitted with MTSU contracted storage providers or MTSU ORSP approved providers that meet storage requirement above.
- Level IV: Confidential Information: When stored or transmitted electronically, Confidential Information must be encrypted at the highest available level, preferably AES 256-bit encryption or higher. On systems where AES 256-bit encryption is not available, the minimum acceptable encryption is AES 128-bit encryption, unless an express written exception is obtained from the Chief Information Security Officer or his/her designee. Access must be limited to employees or contracted entities conducting 乐播传媒入口 business. Confidential Information in a non-electronic format must be secured in a locked location when not in use. Distribution of Confidential Information should only be on a need-to-know basis. Cloud storage is only permitted with MTSU contracted storage providers or MTSU ORSP approved providers that meet storage requirement above.
- All encryption requirements must, absent good cause, adhere to the current relevant National Institute of Standards & Technology (NIST) policy. The Chief Information Security Officer must approve in writing any exception to this requirement.

VII. Data and Media Reassignment and Destruction Handling
- Level I: Public Information – Media devices with Public Information must be erased using acceptable procedures and security best practices. A single-pass of zeros or random bits must be executed before returning the media device to a working state. Non-electronic media with Public Information should have no restriction in its handling or method of destruction and should be recycled, where available.
- Level II: General Information – Media devices with Internal Information must be erased using NIST 800-88 R1 standard procedures and security best practices. Destruction of media is not required unless circumstances require otherwise or the media is inoperable. Non-electronic media with General Information must be disposed of via secure document disposal, such as a secure shredding service, or be destroyed using a cross-cut paper shredder.
- Level III: Restricted Information – Media devices with Restricted Information must be erased using NIST 800-88 R1 standard procedures and security best practices. Destruction of media is not required unless circumstances require otherwise, the media is inoperable, or the media is assigned to designated 乐播传媒入口 personnel. Media under warranty may not be returned to the manufacturer unless the data has been erased using the above-mentioned procedure. Non-electronic media with Restricted Information must be disposed of via secure document disposal, such as a secure shredding service, or be destroyed using a cross-cut paper shredder.
- Level IV: Confidential Information – Media devices with Confidential Information must be erased using NIST 800-88 R1 standard procedures and security best practices. Destruction of media is required in all cases where used and may not be surplused or recycled. Media may not be returned to the manufacturer under any circumstances. Non-electronic media with Confidential Information must be destroyed using a cross-cut paper shredder or reduction of the media to a pulp form.
- If the media device鈥檚 data classification is unknown, Level III procedures must be followed.
- Any destruction of data set forth in this Policy must also comply with the record retention requirements set forth in Policy 129 Records Management and Disposal of Records.
Violation of this policy may result in one or more actions, including, but not limited to:
- The immediate suspension of network access, access to administrative systems, and access to the internet.
- Use of the applicable disciplinary processes and procedures of the University for students, staff, administrators, and faculty.
- Referral to appropriate law enforcement agencies, in the case where violation resulted in a suspected breach of confidential information.
- Personal liability for willful, malicious, or criminal acts or omissions or acts or omissions done for personal gain.
IX. Policy Development and Maintenance
This policy was drafted by the Information Security Leadership and shall be reviewed by the Chief Information Security Officer (CISO) at least every three (3) years. Recommended revisions shall be forwarded to the Vice President for Information Technology and CIO for further review.
Forms: None
Revisions:
References: 500 Access to Education Records; 922 Data Classification.
