Understanding Data Classification

Understanding Data Classification

In order to properly secure your data, you must understand its classification and appropriate options for transporting and storage.

  • NOTE: If you have any questions about the proper handling of data, please contact Information Security
  • Classification of Data Policy and Table

    Confidential Information


    Electronic Devices and

    Lehigh Hosted or Contracted Services

    Class I
    Class I
    Class II
    Class III
    Class IV
    Lehigh Owned - LTS-Managed Whole Disk Encrypted Devices
    including, but not limited to:
      • Computers
      • Network-Attached Storage (NAS)
      • Externally Connected Storage Devices





    Personally Owned Computers or Storage Devices
    Unmanaged Devices (Lehigh Owned or Personal, e.g. mobile)
    Lehigh University LAN Drive (H: I: J: Drives)
    Approved Access-Controlled LAN Drive Storage*
    Web and Storage Space
    Ceph Storage with LTS Access-Control (R Drive)
    Cloud Storage

    AWS - Secure Research Cloud (SRC)
    AWS - Lehigh Administrative Data Lake (LADL)
    Course Site
    Drupal and Lehigh Hosted Webpages
    Email - Lehigh Gmail


    Lehigh File Sender
    Lehigh Google Drive** (encrypted in transit and at rest)
    NOTE: Google stores data on servers located domestically and abroad.
    Lehigh Dropbox for Business3 (encrypted in transit and at rest)
    NOTE: All data is stored in the US.
    Personal Dropbox
    Lehigh Microsoft OneDrive** (encrypted in transit and at rest)
    Zoom - HIPAA2

    (tick) Acceptable  (error) Not Acceptable (warning) Some exclusions (noted below)

    *Must be approved by Information Security

    ** ITAR and Export controlled information under U.S.laws are excluded. Although ITAR and Export controlled information under U.S. laws are classified as Type II data, it cannot be stored on systems outside the US.  In addition to storage restrictions on this type of data, there are also restrictions on sharing such data with foreign nationals of restricted countries. It is up to the data owner to determine whether any export-controlled data may be shared with someone or transported to a particular country. Guidance can be found at the US Department of Commerce Control List site at: http://www.bis.doc.gov/index.php/regulations/commerce-control-list-ccl

    1 Protected Health Information (PHI)

    2 Zoom can be used for PHI or Class 1 data but you MUST have your account converted to a HIPAA compatible account and you will lose some Zoom functionality (i.e. Cloud recording, breakout rooms, etc)

    3 Dropbox for Business can be used for PHI or Class 1 data but you MUST have a team drive set up by LTS and the Class 1 data put into the C1 folder.  Do not share any files externally.

Related content

Request a Dropbox Team Folder
Request a Dropbox Team Folder
Read with this
HIPAA Security Compliance Standard
HIPAA Security Compliance Standard
More like this
eduroam: Access WiFi (wireless) at Affiliated Institutions
eduroam: Access WiFi (wireless) at Affiliated Institutions
Read with this
Risk Assessment Standard
Risk Assessment Standard
More like this
Opening a new Lehigh Account
Opening a new Lehigh Account
Read with this
IT Asset Management Standard
IT Asset Management Standard
More like this

For immediate help, contact the LTS Help Desk (Hours)
EWFM Library | Call: 610-758-4357 (8-HELP) | Text: 610-616-5910 | Chat | helpdesk@lehigh.edu
Submit a help request (login required)