In order to properly secure your data, you must understand its classification and appropriate options for transporting and storage.
Confidential Information | Public | ||||
---|---|---|---|---|---|
Electronic Devices andLehigh Hosted or Contracted Services | Class I | Class I | Class II | Class III | Class IV |
Lehigh Owned - LTS-Managed Whole Disk Encrypted Devices | ![]() | ![]() | ![]() | ||
Personally Owned Computers or Storage Devices | ![]() | ![]() | ![]() | ![]() | ![]() |
Unmanaged Devices (Lehigh Owned or Personal, e.g. mobile) | ![]() | ![]() | ![]() | ![]() | ![]() |
Lehigh University LAN Drive (H: I: J: Drives) | ![]() | ![]() | ![]() | ![]() | ![]() |
Approved Access-Controlled LAN Drive Storage* | ![]() | ![]() | ![]() | ![]() | ![]() |
Web and Storage Space | ![]() | ![]() | ![]() | ![]() | ![]() |
Ceph Storage with LTS Access-Control (R Drive) | ![]() | ![]() | ![]() | ![]() | ![]() |
Cloud Storage | |||||
AWS - Secure Research Cloud (SRC) | ![]() | ![]() | ![]() | ![]() | ![]() |
AWS - Lehigh Administrative Data Lake (LADL) | ![]() | ![]() | ![]() | ![]() | ![]() |
Confluence | ![]() | ![]() | ![]() | ![]() | ![]() |
Course Site | ![]() | ![]() | ![]() | ![]() | ![]() |
DocuSign | ![]() | ![]() | ![]() | ![]() | ![]() |
Drupal and Lehigh Hosted Webpages | ![]() | ![]() | ![]() | ![]() | ![]() |
Email - Lehigh Gmail | ![]() | ![]() | ![]() | ![]() | |
JIRA | ![]() | ![]() | ![]() | ![]() | ![]() |
Lehigh File Sender | ![]() | ![]() | ![]() | ![]() | ![]() |
Lehigh Google Drive** (encrypted in transit and at rest) | ![]() | ![]() | ![]() | ![]() | ![]() |
Lehigh Dropbox for Business3 (encrypted in transit and at rest) | ![]() | ![]() | ![]() | ![]() | ![]() |
Personal Dropbox | ![]() | ![]() | ![]() | ![]() | ![]() |
Lehigh Microsoft OneDrive** (encrypted in transit and at rest) | ![]() | ![]() | ![]() | ![]() | ![]() |
Qualtrics | ![]() | ![]() | ![]() | ![]() | ![]() |
REDCap | ![]() | ![]() | ![]() | ![]() | ![]() |
Slack | ![]() | ![]() | ![]() | ![]() | ![]() |
Zoom | ![]() | ![]() | ![]() | ![]() | ![]() |
Zoom - HIPAA2 | ![]() | ![]() | ![]() | ![]() | ![]() |
Acceptable
Not Acceptable
Some exclusions (noted below)
*Must be approved by Information Security
** ITAR and Export controlled information under U.S.laws are excluded. Although ITAR and Export controlled information under U.S. laws are classified as Type II data, it cannot be stored on systems outside the US. In addition to storage restrictions on this type of data, there are also restrictions on sharing such data with foreign nationals of restricted countries. It is up to the data owner to determine whether any export-controlled data may be shared with someone or transported to a particular country. Guidance can be found at the US Department of Commerce Control List site at: http://www.bis.doc.gov/index.php/regulations/commerce-control-list-ccl
1 Protected Health Information (PHI)
2 Zoom can be used for PHI or Class 1 data but you MUST have your account converted to a HIPAA compatible account and you will lose some Zoom functionality (i.e. Cloud recording, breakout rooms, etc)
3 Dropbox for Business can be used for PHI or Class 1 data but you MUST have a team drive set up by LTS and the Class 1 data put into the C1 folder. Do not share any files externally.