Information Security Policy

The purpose of this policy is to establish comprehensive standards for the classification, protection, handling, retention, and disposal of Colorado College’s institutional data assets. (Appendix A). It ensures the confidentiality, integrity, and availability of college information, aligns practices with regulatory requirements, and provides expectations for employees and contractors. The policy also supports responsible data access and use by helping the College guard against operational, legal, financial, reputational, and personal harms that may result from unauthorized access, disclosure, misuse, or loss of institutional data. (Appendix B).

Responsible office
Information Technology Services
Responsible party
Chief Technology Officer/Vice President for Information Technology
Last revision
July 2026
Approved by
The Cabinet
Approval date
July 2026
Effective date
July 2026
Last review
July 2026
Additional references
FERPA ,GLBA, HiPAA, PCI/DSS 11.4, Data Classification Policy

Scope

All financial and administrative policies involving community members across campus, including volunteers are within the scope of this policy. If there is a variance between departmental expectations and the common approach described through college policy, the college will look to the campus community, including volunteers to support the spirit and the objectives of college policy. Unless specifically mentioned in a college policy, the college’s Board of Trustees are governed by their Bylaws.

Policy

Colorado College requires institutional data assets to be properly classified, protected, retained, and disposed of based on its sensitivity, regulatory requirements, and data asset lifecycle. The following sections establish the enforceable rules for protecting information assets.

Data Minimization Standard

Faculty, Staff, Students, Contractors, and Third-Party Vendors shall generate, collect, process, retain, and share personal, sensitive, and restricted data only as permitted under applicable federal, state, and international privacy laws, regulations, contractual obligations, and institutional policies. Consistent with data protection principles—including data minimization, purpose limitation, and storage limitation—data collection and use must be limited to what is legally permissible and necessary to support documented institutional functions.

Data that is excessive, irrelevant, improperly obtained, or no longer required to meet legal, regulatory, or institutional retention obligations must be securely deleted, anonymized, or otherwise disposed of in accordance with established records retention schedules and data governance standards. Colorado College shall conduct periodic reviews and audits of data storage, processing, and access practices to ensure continued compliance with applicable data protection requirements.

Data assets Classification & Handling 

All institutional data assets must be classified into one of four categories below at the time of creation or collection to ensure appropriate handling, access controls, and safeguards are applied based on the level of sensitivity and potential harm resulting from unauthorized disclosure.

  • Unrestricted: Data assets approved for public release with no restrictions (e.g., press releases, course catalogs).
  • Internal Use: Data assets intended only for Colorado College authorized employees, students, and authorized community members in support of legitimate academic or business purposes. These assets are not intended for public dissemination, and unauthorized external disclosure may create reputational or operational risk (e.g., online directory, budgets).
  • Sensitive: Data assets intended for limited use within the college community; unauthorized disclosure may cause reputational or operational harm (e.g., internal memos; building floor plans).
  • Restricted: Data assets requiring the highest protection; unauthorized disclosure could cause legal, financial, or personal harm (e.g., Social Security numbers, financial records, student grades, health records).

Handling rules

  • Sensitive and Restricted data assets must be encrypted at rest, in transit, and in use. These assets must only be accessed by authorized individuals with legitimate business need
  • Internal, Sensitive and Restricted data assets must not be stored in personal accounts, unapproved systems / unapproved cloud services.
  • All classifications must be reviewed periodically by data stewards

Encryption Requirements

Encryption is mandatory for Sensitive and Restricted data assets:

  • Data assets at rest on magnetic storage must use AES-256 or stronger.
  • Data assets in transit must use TLS 1.2 or higher.
  • Sensitive and Restricted data assets must not be stored on unencrypted media (such as, but not limited to USB drives, CDs). If the media cannot be encrypted, do not use it to store sensitive and restricted data.
  • Encryption keys must be securely managed, rotated, and accessible only to authorized ITS staff.
  • Emailing restricted data assets must use secure, college-approved encryption methods and systems.

Data Asset Sharing

Institutional data assets may only be shared externally under controlled conditions:

  • Approval from the data steward is required prior to sharing Sensitive or Restricted data assets.
  • A formal written agreement (such as an NDA) must define purpose, security responsibilities, retention period, and restrictions.
  • Data assets must be transmitted using secure transfer methods (VPN, SFTP, encrypted email).
  • Shared data assets must not be used beyond the defined purpose referenced in the formal written agreement without additional approval.
  • Third-party recipients must comply with Colorado College data assets protection requirements, and the third-party recipients of College data will be a party to the formal written agreement

Data Asset Retention

Institutional data assets must be retained only as long as required by law, regulation, or business need:

  • Exceptions to retain data must be documented, justified, and approved by the data trustee.
  • Data assets must follow the Records Retention Policy.
  • Retention schedules must be applied consistently across all systems.
  • Data assets past retention limits must be securely disposed of (see Section 4).
  • Data stewards are accountable for enforcing retention schedules.

Cloud Storage

The use of cloud storage must meet institutional security standards:

  • Only college-managed cloud services (CC OneDrive and MS Teams) may be used.
  • Colorado College data assets shall not be stored on personal cloud accounts
  • ITS must evaluate and approve according to the College security standard all third-party vendors handling institutional data assets.
  • Cloud services must enforce single sign-on, multi-factor access, encryption standards, access controls, and monitoring.
  • Unauthorized or unapproved cloud services (shadow IT) are strictly prohibited.

Secure Disposal of Assets

All Sensitive and Restricted data assets must be securely destroyed once retention requirements have expired:

  • Paper documents must be shredded or destroyed by approved vendors.
  • Electronic data assets must be wiped using industry-standard tools, or physically destroyed in compliance with DoD/NIST standards
  • ITS must certify secure disposal for decommissioned equipment with magnetic storage and vendors handling devices with magnetic storage disposal must provide written certification of destruction including device/system and/or magnetic storage serial number(s)
  • Employees are prohibited from discarding physical college assets (including data assets) in unsecured disposal bins.

Data Roles 

  • Executive Data Sponsor: Provides institutional sponsorship for data governance, ensuring alignment with strategic priorities and holding executive leadership accountable for effective data management
    • Champions data governance as an institutional priority
    • Ensure cabinet-level accountability for data stewardship
    • Supports policy adoption and enforcement at the highest level
    • Removes organizational barriers to effective data governance
  • Data Trustees: Data Trustees are Cabinet members who have policy ratification and planning responsibilities for data within their designated domain. Responsibilities include:
    • ExpectING and facilitating divisional compliance with data protection, privacy, and retention policies (including completion of required training).
    • Designating Data Stewards and asigning other data roles within their division.
    • Ensuring data role responsibilities in their division are being fulfilled
    • Ensuring divisional data-related use and decisions are in line with the College’s strategic goals and policies
    • Escalating significant data risks or policy compliance issues 
  • Data Stewards: Data Stewards are responsible for the security, quality, accuracy, integrity and availability of specific data domains (subject areas) – typically those for which they are most directly responsible for the data creation or collection. Responsibilities include:
    • Establishing expectations for appropriate data access and responsible use
    • Ensuring data policies and guidelines are reflected in day-to-day domain operations
    • Upholding data classification and protection requirements (ensuring appropriate handling, sharing, and storage practices)
    • Approving and reviewing data access requests related to their domain
    • Supporting compliance with records retention schedules
    • Communicating data governance policies and expectations
    • Communicating changes to data related policies or practices within their domain that may impact other campus stakeholders
    • Coordinating with IT and custodians on data security controls
    • Creating and managing processes to ensure data integrity
    • Creating and maintaining processes to certify analysis and published reports
    • (In collaboration with Data Trustees) are responsible for approving the unit’s participation in external surveys and for overseeing the integrity of data collected, managed and reported by the unit.
    • Developing and maintaining an inventory of external surveys/reports submitted by them/their unit.
    • Data Stewards, or their designee(s), are responsible for ensuring that all third-party vendor contracts related to their unit operations have been reviewed and meet necessary data protection and compliance requirements. 
  • Associate Data Stewards: Division/unit subject matter experts who have responsibility for helping implement and manage Data Steward efforts. Associate Data Stewards are appointed by a Data Steward.

 

  • Data Custodians (Functional): Data Custodians are responsible for the transparency, auditability, and uniformity of data within a specific domain. Responsibilities include:
    • Maintaining secure storage, transmission, and system protections
    • Implementing access controls, monitoring, and audit logging
    • Supporting data integration, system architecture, and data pipelines
    • Executing data archival and secure disposal
    • Ensuring systems align with data classification and protection requirements, including their party vendors whose roles require the sharing/exchange of institutional data.

  

  • Data Concierges: Serve as the primary point of contact for individuals seeking the creation of – or information about – specific domain data sets that address research goals or questions. Responsibilities include:
    • Helping requestors understand available data and its limitations
    • Providing context about data sources, definitions, process origins and metadata
    • Supporting responsible and compliant data use in research and reporting
    • Routing requests to the appropriate Data Steward for access authorization

  

  • Data Users: Faculty, staff, students, contractors, and volunteers who access institutional data to perform authorized college activities. Responsibilities include:
    • Accessing data only for authorized institutional purposes
    • Following institutional policies for data protection, handling, and storage
    • Ensuring data is handled and processed securely, including protecting sensitive and restricted data from unauthorized disclosure
    • Maintaining the integrity, accuracy, and sufficiency of data they alter
    • Reporting suspected misuse or security incidents
    • Completing required data privacy and security training

 

  • Enterprise Technical Data Lead: IT leaders with significant and broad campus data access that are responsible for setting direction, priorities, and standards for technical data management, ensuring systems and infrastructure align with institutional data governance policies. Responsibilities include:
    • Providing direction and oversight to Technical Data Custodians and related IT staff
    • Establishing standards for data architecture, system integration, and data flow across college systems (e.g., ERP, APIs, data warehouse)
    • Ensuring data governance policies are properly implemented within technical systems
    • Partnering with Data Stewards to translate business rules into technical solutions
    • Advising on system capabilities, limitations, and risks related to data initiatives
    • Overseeing data security practices at the infrastructure and system level (e.g., access controls, monitoring, backups)
    • Ensure reliability, performance, and sustainability of data environments

 

  • Enterprise Technical Data Custodian: IT professionals (often with significant and broad campus data access) responsible for the technical implementation, maintenance, and security of systems that store, process, and transmit institutional data. Responsible for supporting the structural integrity, usability, and operational reliability of data — translating business governance into implemented data assets — without owning the business meaning or accuracy of the data input origin. Responsibilities include:
    • Configuring and managing enterprise system-level access controls (e.g., roles, permissions, authentication with applications like Banner and Microsoft)
    • Maintaining infrastructure supporting data storage and processing (servers, databases, cloud platforms)
    • Managing data integrations and pipelines (e.g., ERP feeds, APIs, ETL processes)
    • Monitoring systems for performance, security risks, and data integrity issues
    • Executing data backup, recovery, and disaster recovery procedures
    • Implementing data governance policies within systems and tools
    • Supporting secure data transfer and sharing across systems and with third parties
    • Maintaining logs and audit trails for data access and movement

Data Access

Access to data assets is governed by the principle of least privilege and authorized based on legitimate academic or operational need to ensure both appropriate protection and efficient institutional functioning.

  • Access requests must be approved by the appropriate data steward.
  • All access must be periodically reviewed regularly by data stewards.
  • Emergency access is allowed in the case of life safety, and must be logged, reviewed, and revoked once the emergency ends.
  • Access must be revoked immediately when no longer required (e.g., employee departure).

Policy Enforcing Procedures

  • Classify data assets appropriately
  • Encrypt all sensitive and confidential data assets before storage or transmission.
  • Conduct regular access reviews and remove unnecessary permissions.
  • Apply retention schedules and securely destroy expired data assets.
  • Obtain required approvals before sharing data assets externally.

Information Security Standards

The College requires a security standard across all systems and devices:

  • Multi-factor authentication (MFA) is required for all accounts associated with college business.
  • Endpoint protection must be installed on all college-owned computing devices.
  • Configure servers and applications according to secure standards maintained by ITS.
  • Enable logging and monitoring for all critical systems.
  • Monitor network traffic for anomalies or unauthorized activity.
  • Annual security awareness training is mandatory for everyone with a CC account.

Removal of Malicious Email (Notice)

In the event of an email-based cyberattack (often taking the form of a phishing scam sent widely to most or all of the email accounts at the institution), ITS may remove the malicious email from all CC email accounts to which it has been delivered.

ITS will not necessarily do this for every phishing email received, but may employ the method for particularly widespread or tricky scam messages in order to reduce the likelihood of community members falling for the scam.

Criteria for removal

Verified by ITS staff as a phishing or scam email designed to gain access to an individual’s account credentials or otherwise trick them into providing information they shouldn’t or doing something they shouldn’t.

Approval

Due to the nature of cyberattacks and how quickly they can proliferate, approval is not required for ITS to remove malicious emails from mailboxes. However, the incident must be documented in the ITS ticketing system including a screenshot of the email being removed, and these tickets will be subsequently reviewed by leadership within 48 hours of the event.

Review & Update

This policy will be reviewed regularly, or as required by new technologies, incidents, or regulatory changes.

 

 

 

Procedures

This policy applies to all faculty, staff, students, contractors, volunteers, and third-party vendors who generate, collect, process, store, manage, analyze, visualize, or interpret Colorado College institutional data assets in any form, whether digital, paper, or verbal. It covers all college-owned systems, applications, networks, and approved cloud solutions.

 

 

Definitions

  • Encryption: Encoding data assets to prevent unauthorized access.
  • Financial harm: refers to direct or indirect monetary losses incurred by the institution or affected individuals as a result of unauthorized access to or disclosure of institutional data.
  • Institutional data asset: Any data resource that is owned, stewarded, or maintained by the institution and has ongoing operational, academic, legal, financial, or strategic value to the college.
  • Legal harm: refers to adverse consequences arising from violations of applicable laws, regulations, contractual obligations, or legal duties resulting from the unauthorized access, disclosure, or misuse of institutional data.
  • Operational risk: the risk of institutional harm or disruption arising from unauthorized access to, disclosure of, or release of internal, sensitive or restricted information due to inadequate internal controls, human error, or system failures.
  • Personal harm: refers to adverse effects experienced by individuals whose personal sensitive or restricted information is improperly accessed, disclosed, or misused.
  • Reputational harm: harm that includes loss of confidence among students, employees, alumni, donors, regulators, and the public resulting from unauthorized disclosure of institutional data, particularly when such disclosure suggests inadequate safeguards, governance failures, or noncompliance with applicable laws
  • Retention Schedule: Official timeline defining how long records must be maintained.
  • Shadow IT: Use of unauthorized cloud or technology services outside ITS approval.

 

Report an issue - Last updated: 07/09/2026