Data Governance
What is Data Governance?
Data is a valued asset maintained and utilized by the University of Louisville to support our strategic goals. Institutional data, while not owned by units, is effectively and securely managed by units on behalf of the university.
Data governance is an institution-wide framework of principles to define and manage the availability, usability, integrity and security of an institution’s data (information in digital form) based on internal policies, processes and compliance standards.
Data governance, for the University of Louisville, ensures that our data is secure, private, accurate, available and usable. It includes the actions people must take, the processes they must follow, and the technology that supports them throughout the data life cycle.
Data governance looks to achieve a range of goals:
- Definition of data
- Security, compliance and privacy of data
- Stewardship of data
- Availability of data
- Utilization and quality of data for business decisions
- Enforcement of data policies
Classification Levels
The University intentionally provides this information to the public.
L1 Categories & Examples:
- Published University Announcements, Communications and Events
- Press releases, public event announcements
- Publicly Accessible Web Content
- Campus maps, course catalogs, admissions criteria, tuition info, campus housing, public safety information, public directory information
- Public Meetings, Reports and Statistics
- Board of Trustees meeting minutes, reports to the Board of Trustees
- Public Directory Information
- University Policies and Governance Documents
- Published university-wide policies, mission statement, The Redbook, Student Code of Conduct
- Academic and Administrative Offerings
- Admissions criteria, tuition info
- External Job Postings and Opportunities
- Public job postings
- Campus Services Information
- Dining menus, campus safety info, housing
- Public Events and Cultural Programming
- Public lectures, performances
- Research Publications and Projects
Open access publications, cleared project descriptions
The University chooses to keep this information private, but its disclosure would not cause material harm.
L2 Categories & Examples:
- Non-public University Announcements, Communications and Events
- Announcements of internal activities and non-public events; changes in administration or operations
- Intranet Web Content
- non-public web content (training modules, unit policies and procedures)
- Administrative and Operational Information
- Internal memos, draft policies
- Instructional Materials
- Syllabi, non-public lectures
- Research
- Pre-publication findings or similar shared in university seminars, talks, colloquiums, poster sessions, or similar
- Internal Job Postings and Opportunities
- Internal job postings
- Technology and Systems
- Non-sensitive IT documentation
Disclosure of this information beyond intended recipients might cause material harm to individuals or the University.
L3 Categories & Examples
- Student Records
- Grades, transcripts
- Personnel Records**
- Performance evaluations, personnel files
- Financial Information
- Budget plans, contracts
- Research
- Confidential research data, draft research papers
- Alumni and Donor Info
- Risk, Audit and Compliance Reports
- IT Systems and Security
**Employees have the right to discuss terms and conditions of their own employment, including salary and benefits, with each other or with third parties.
Disclosure of this information beyond specified recipients would likely cause serious harm to individuals or the University.
L4 Categories & Examples
- Personally Identifiable Information
- SSNs, passport numbers
- Protected Health Information***
- Medical records, insurance info
- Financial Information
- Credit card data, IRS forms
- Research
- Human subject data, IRB materials
- Security and Access Controls
- Admin passwords, access logs
- Legal and Regulatory
- Legal case files, audits
***UofL units or programs that qualify as "covered entities" under the Health Insurance Portability and Accountability Act (HIPAA) must comply with HIPAA's data security rules.
Data that could place the subject at severe risk of harm or data with contractual requirements for exceptional security measures.
L5 Categories & Examples:
- Legal and Law Enforcement
- Subpoenaed data, investigations
- High-Risk Research Data
- Export-controlled research
- Identity and Security Infrastructure
- Encryption keys, incident data
- Executive or Strategic
- Board communications, financial strategy
- Protected Whistleblower or Ethics Information
- Whistleblower identities
Control Requirements
- Proper user authentication and authorization prior to data access
- Users with elevated access must have 2nd factor authentication
- Log in attempts must be controlled
- Where technically feasible, data is encrypted when not accessed. Encryption can occur at the database, application, OS levels, or hardware level. Where not technically feasible, other compensating controls, such as physical security controls, must be implemented to protect the data at rest.
- Transmission of data through its flow must be secure via cryptographic means or other secure means (e.g., locked box during transport, etc.). Network traffic must be encrypted using strong cryptography (e.g., TLS v1.2)
- Data must go through integrity checks during transmission and actions through software and hardware controls. (e.g., ECC RAM, SHA-256, data validation)
- Systems where data is stored must have security and access logs enabled.
- Data must be secure-wiped (e.g., DBAN) from storage media prior to destruction or re-use.
Acronym Key
Health Insurance Portability and Accountability Act
- Federal law that sets a national standard to protect medical records and other personal health information.
Family Educational Rights and Privacy
Social Security Number
Payment Card Industry
Kentucky Revised Statutes
International Traffic in Arms Regulations
Institutional Review Board