Data and IT Resource Classification Standard Overview
Why Classify Data and IT Resources?
Classification of campus Institutional Information and IT Resources is a key component of UC Berkeley’s risk-based information security program. Classification levels indicate the adverse impact that a loss of confidentiality, integrity or availability would have upon the Campus. This in turn informs the required security protections and maximum “down time” to help prevent those adverse impacts.
Classification Types
The UC system has three types of classifications for Institutional Information and IT Resources:
Protection Level:
Indicates the impact of loss of confidentiality or integrity. Higher Protection Levels require more security protections to help prevent loss of confidentiality or integrity
|
|
|
|
P4 - High Impact | P3 - Moderate Impact | P2 - Low Impact | P1 - Minimal Impact |
Availability Level:
Indicates the impact of loss of availability. Higher Availability Levels require more security protections to help prevent loss of availability.
|
|
|
|
A4 - High Impact | A3 - Moderate Impact | A2 - Low Impact | A1 - Minimal Impact |
Recovery Level:
Represents the urgency to restore the availability or functionality of Institutional Information or IT Resources after a disaster or disruption. Higher Recovery Levels require more business continuity/disaster recovery (BC/DR)-related planning and protections.
|
|
|
|
|
RL5 - Very High Urgency | RL4 - High Urgency | RL3 - Moderate Urgency | RL2 - Low Urgency | RL1 - Minimal Urgency |
15 min recovery | 6 hr recovery | 24 hr recovery | 5 day recovery | 30 day recovery |
What Needs To be Classified?
Protection Level and Availability Level classification is required for all UC Institutional Information and IT Resources.
At UC Berkeley, Recovery Level classification is generally required for non-research IT Infrastructure and Services.
Campus Data and IT Resource Classification Standard
The campus Data and IT Resource Classification Standard is UC Berkeley’s framework for determining these classification levels. It is a living document that includes definitions and common examples of each classification level, along with related references and information for getting help.
If you are trying to classify something that is not included in the common examples, see which definition matches the most closely. If you’re not sure, contact the Information Security Office for assistance: security-policy@berkeley.edu
Classification Guides and Resources
As companions to the full Data and IT Resource Classification Standard, the Information Security Office has developed several self-help classification guides to assist with Protection Level and Availability Level classification:
- Data and IT Resource Classification Guideline - step-by-step guide for classifying common categories of information
- How to Classify Research Data