-
UH System Policies and Procedures
- Board of Regents Policies
-
Executive Policies
-
+
1. General Provisions
-
+
2. Administration
-
+
3. Organization
-
+
4. Planning
-
+
5. Academic Affairs
-
+
6. Tuition, Financial Assistance, and Fees
-
+
7. Student Affairs
-
+
8. Business and Finance
-
+
9. Personnel
-
+
10. Land and Physical Facilities
-
+
11. Miscellaneous
-
+
12. Research
- Abolished Policies (Post Oct. 2014)
- Archived EP
-
+
- Administrative Procedures
-
UH‐Related Laws and Rules
- Hawaiʻi Revised Statutes (HRS) 304A
- Hawaiʻi Administrative Rules (HAR) Title 20
Executive Policy 2.214 Executive Policy 2.214Title
Institutional Data Classification Categories and Information Security Guidelines
Header
Executive Policy Chapter 2, Administration
Executive Policy EP 2.214, Institutional Data Classification Categories and Information Security Guidelines Effective Date: December 2025 Dates Amended: August 2019, January 2018, October 2014, April 2012, April 2009 Responsible Offices: Office of the Vice President for Information Technology Governing Board of Regents Policy: RP 2.202, Duties of the President Review Date: December 2027 I. Purpose
The objective of this executive policy is to organize UH Institutional Data into data classification categories based on different levels of security risk and penalties that may result from the inadvertent exposure and inappropriate disclosure of those data.
II. Definitions
Selected data elements/data records that fall under the sensitive or regulated categories may be subject to federal, state, and local regulations or industry standards. Data protections should follow ITS’ Minimum Security Standards which are based on these regulations and standards. This policy is not intended to supersede those regulations, but to promote and reinforce them. Should a provision in this policy conflict with applicable state, federal, or local regulations, the applicable regulation takes precedence and will govern. III. Executive Policy
Attachment 1 is not intended to be an exhaustive list but is an attempt to capture the more common data elements (and, in some cases, types of data) used by the University to conduct its daily business. Institutional Data that are not listed shall be considered Sensitive until otherwise determined. For guidance on Institutional Data not listed in Attachment 1, email datagov@hawaii.edu. IV. Delegation of Authority
There is no policy-specific delegation of authority.
V. Contact Information
Data Governance Office
Sandra Furuto, 956-7487, yano@hawaii.edu VI. References
Executive Policy EP2.215, Institutional Data Governance, provides the overall structure for the University’s data governance program. It describes the fundamental principles and best practices governing the management and use of Institutional Data and stewardship roles and responsibilities. Executive Policy EP2.214 is a supporting policy on data governance and information security.
These and other University of Hawai‘i executive policies, State of Hawai‘i Revised Statutes, and external regulations that relate to data governance and Institutional Data classification categories are available at: www.hawaii.edu/infosec/policies. VII. Exhibits and Appendices
No Exhibits and Appendices found
Approved Signed Wendy Hensel December 02, 2025 Date TopicsNo Topics found.Attachments |