Duke Services and Data Classification

 Duke Services and Data Classification Author: Office of Information Technology (OIT) Version 1.0 Authority: Duke University Chief Information Officer Duke University Chief Information Security Officer Determining the nature of the data Questions to consider •
Are you storing Sensitive data elements (for example, ePHI, Social Security Numbers, DMCA, PCI DSS or FERPA data)? See the Duke University Data Classification Standard for the definitions of Sensitive, Restricted and Public data. Use of Duke services Selecting a Duke service depending on data classification The following chart outlines which Duke services are appropriate for use with Sensitive, Restricted and Public data: Service Available to: Sensitive Restricted Public ✔ ✔ Duke OIT CIFS/NFS Duke University Home Drive Service Duke Medicine ✔ ✔ Duke Shared Cluster Duke University Resource (DSCR) Duke Medicine ✔ ✔ Duke Medicine FISMA Duke Medicine Zone ✔ ✔ Duke OIT & Duke University Departmental File Shares ✔ ✔ Duke’s Protected Duke University Network Duke Medicine ✔ ✔ ✔ Duke Medicine Duke Medicine SharePoint ✔ ✔ Duke University Duke University SharePoint ✔ ✔ ✔ Duke’s Tableau Instance Duke University Duke Medicine ✔ ✔ Duke’s Wiki Duke University Duke Medicine *No ITAR related data may be stored on Box. Duke Services and Data Classification P a g e 1 | 2 Use of cloud services Selecting a cloud service depending on data classification The following chart outlines which Duke services are appropriate for use with Sensitive, Restricted and Public data: Service Available to: Sensitive Restricted Public ✔ ✔ Duke’s Box Service Duke University ✔* Duke Medicine ✔ ✔ ✔ Duke’s Qualtrics Service Duke University ✔ ✔ ✔ Duke’s Redcap Service Duke Medicine ✔ ✔ Duke’s Microsoft Duke University OneDrive Service Duke Medicine ✔
Amazon Web Services Duke University Duke Medicine Use of other cloud services (personal use) Selecting a cloud service depending on data classification The following chart outlines outside cloud services appropriate for personal use: Service Available for: Sensitive Restricted Public ✔ Apple iCloud Personal ✔ Personal Box Account Personal ✔ Personal OneDrive Personal Account ✔ DropBox Personal Duke Services and Data Classification P a g e 2 | 2