Risk Classification
Why Risk Classification Matters
To effectively protect its data and systems, the University relies on accurate risk classification. Categories are based on the likelihood and impact of an incident, whether it is a minor disruption or a major cyberattack.
If you are a System or Service Custodian, use the risk classifications to apply the appropriate Minimum Standards to the systems or services you control or manage.
If you are a Community Member who accesses, uses, or works with University Data, including Confidential Information, use the risk classifications to handle information appropriately and follow the University Information Security Policy.
Level 1: No impact on university operations, research, reputation, or finances.
- Data: Non-sensitive information that is intentionally made available to the public and can be used, reused, or redistributed without restriction.
- Systems: Failure could impact a Non-critical (Critical 4) service.
Level 2: Minimal impact on university operations, research, reputation, or finances.
- Data: Non-sensitive confidential information that may be shared internally within the Harvard community, or within a school, unit or specific department.
- Systems: Failure could impact an Important (Critical 3) service.
Level 3: Moderate impact on university operations, research, reputation, or finances.
- Data: Sensitive information that must be safeguarded as confidential and shared only with individuals with a need to know.*
- Systems: Failure could impact a Critical (Critical 2) service.
*Most university data falls into this broad classification, including most personal data.
Level 4: Significant impact on university operations, research, reputation, or finances.
- Data: Sensitive "Restricted Personal Information", credentials, security secrets, or contractually restricted data.
- Systems: Failure could impact a Foundational (Critical 0) or Mission Critical (Critical 1) service.
Level 5: Severe impact on university-wide operations, research, life safety systems, reputation, or finances.
- Data: Sensitive information that must be safeguarded in accordance with federal requirements.
- Systems: Failure could impact life safety services.
Key
Restricted Personal Information - Specific to privacy regulations, laws or sensitivity.
- Government IDs (e.g., Social Security, passport, driver's license)
- Personal financial details (e.g., bank or credit card numbers)
- HIPAA-protected health information
- GDPR/PIPL- extra sensitive data (e.g., biometric, health info)
- Identifiable genetic data
- Disclosure could put a subject at risk (e.g. legal, political, physical)
Systems: Critical 0-4 - Specific to University availability needs.
Data Examples
Choose the type below to view examples for each risk classification category.
Beyond the Basics: Privacy & Regulated Data
Protecting sensitive data takes more than following the Minimum Standards for IT security. Information such as student records, health details, and financial files demands custom steps to comply with legal and contractual rules. If you work with these data types, check the resources below to learn more.
Related Resources
Use these resources to take the next step, find University guidance, or explore trusted external references.
University Policies
Official University policies and governance guidance.
University Standards
Security and privacy requirements for protecting University information.
Roles & Responsibilities
Role-based guidance for supporting a secure University environment.