Risk Classification

colorful binders on a shelf

Why Risk Classification Matters

To effectively protect its data and systems, the University relies on accurate risk classification. Categories are based on the likelihood and impact of an incident, whether it is a minor disruption or a major cyberattack.

If you are a System or Service Custodian, use the risk classifications to apply the appropriate Minimum Standards to the systems or services you control or manage.

If you are a Community Member who accesses, uses, or works with University Data, including Confidential Information, use the risk classifications to handle information appropriately and follow the University Information Security Policy.

Risk Classifications

Always use the “high watermark”: If a system stores only Level 1 (public) data but requires Level 4 (mission‑critical) availability, classify the system as Level 4.

Level 1: No impact on university operations, research, reputation, or finances.

  • Data: Non-sensitive information that is intentionally made available to the public and can be used, reused, or redistributed without restriction.
  • Systems: Failure could impact a Non-critical (Critical 4) service.
Level 1 Green

Level 2: Minimal impact on university operations, research, reputation, or finances.

  • Data: Non-sensitive confidential information that may be shared internally within the Harvard community, or within a school, unit or specific department.
  • Systems: Failure could impact an Important (Critical 3) service.
Level 2 Yellow

Level 3: Moderate impact on university operations, research, reputation, or finances.

  • Data: Sensitive information that must be safeguarded as confidential and shared only with individuals with a need to know.*
  • Systems: Failure could impact a Critical (Critical 2) service.

*Most university data falls into this broad classification, including most personal data.

Level 3 Light Orange

Level 4: Significant impact on university operations, research, reputation, or finances.

  • Data: Sensitive "Restricted Personal Information", credentials, security secrets, or contractually restricted data.
  • Systems: Failure could impact a Foundational (Critical 0) or Mission Critical (Critical 1) service.
Level 4 Dark Orange

Level 5: Severe impact on university-wide operations, research, life safety systems, reputation, or finances.

  • Data: Sensitive information that must be safeguarded in accordance with federal requirements.
  • Systems: Failure could impact life safety services.
Level 5 Red

Key

Restricted Personal Information - Specific to privacy regulations, laws or sensitivity.

  • Government IDs (e.g., Social Security, passport, driver's license)
  • Personal financial details (e.g., bank or credit card numbers)
  • HIPAA-protected health information
  • GDPR/PIPL- extra sensitive data (e.g., biometric, health info)
  • Identifiable genetic data
  • Disclosure could put a subject at risk (e.g. legal, political, physical)

Systems: Critical 0-4 - Specific to University availability needs.

Data Examples

Choose the type below to view examples for each risk classification category.

Beyond the Basics: Privacy & Regulated Data

Protecting sensitive data takes more than following the Minimum Standards for IT security. Information such as student records, health details, and financial files demands custom steps to comply with legal and contractual rules. If you work with these data types, check the resources below to learn more.

Privacy Principles

Standard practices for collecting, storing, and sharing personal data.

Regulated & Contractual Data

Rules for handling HIPAA, PCI, GDPR, and data sourced from providers.

Related Resources

Use these resources to take the next step, find University guidance, or explore trusted external references.