Data at Rest Policy
Version 2.0
For Students, Faculty, Staff, Guests, Alumni
Purpose
The purpose of this policy is to govern how University data is stored and protected while at rest.
Scope
This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrators, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Policy Statement
- Fordham Protected Data, Fordham Sensitive Data, or Public Data must be stored with the applicable access controls according to the Data Classification Guidelines and Data Classification and Protection Policy.
- University data must be stored only in authorized IT Resources for the applicable data classification and approved University purpose.
- Access to stored Fordham Protected Data and Fordham Sensitive Data must be restricted to authorized users based on a legitimate University purpose and the principle of least privilege.
- Fordham Protected Data and Fordham Sensitive Data at rest must be protected with safeguards appropriate to their classification and risk. University-approved cryptographic mechanisms must be used where encryption is required by University policy or technical requirements, applicable law or regulation, contract, or risk assessment.
- Where cryptographic protection is used for Data at Rest, cryptographic keys and related keying material must be established, managed, protected, and retired using University-approved key-management processes.
- Data at Rest (e.g., backups, archives, replicas, snapshots, removable media, and other copies containing University data) must receive protections appropriate to the applicable data classification.
- Third-party, cloud, Software as a Service (SaaS), or other externally hosted services that store Fordham Protected Data or Fordham Sensitive Data must be University-approved for the applicable use and must comply with applicable University security, privacy, risk, procurement, and contractual requirements.
- Stored University data must be retained and disposed of in accordance with Records Retention and Disposal Policy.
Definitions
Data at Rest is digital information stored on a physical or virtual medium and not actively moving across a network or being processed by an application.
IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and any related materials and services.
NIST SP 800-53 Rev. 5 Alignment
- Access Control: AC-3 Access Enforcement; AC-6 Least Privilege.
- Media Protection: MP-4 Media Storage.
- System and Communications Protection: SC-12 Cryptographic Key Establishment and Management; SC-13 Cryptographic Protection; SC-28 Protection of Information at Rest.
Related Policies and Procedures
- Acceptable Uses of IT Infrastructure and Resources Policy
- Backup Policy
- Data Classification Guidelines
- Data Classification and Protection Policy
- Data in Transit Policy
- Disk Encryption Policy
- Records Retention and Disposal Policy
Implementation Information
| Review Frequency | Triennial |
|---|---|
| Responsible Person | Senior Director of IT Security and Assurance |
| Approved By | CISO |
| Approval Date | May 22, 2018 |
Revision History:
| Version | Date | Description |
|---|---|---|
| 1.0 | 01/23/2017 | Initial policy. |
| 1.0.1 | 02/07/2018 | Minor edits are pointing to existing policies and the renamed Acceptable Uses of IT Infrastructure and Resources Policy. There are no substantial changes to this policy. |
| 1.0.2 | 05/22/2018 | Updated disclaimer statement. |
| 06/09/2020 | Periodic review. No changes. | |
| 07/26/2023 | Periodic review. No changes. | |
| 2.0 | 08/31/2026 | Substantive draft update aligns the policy with NIST SP 800-53 Rev. 5 and NIST CSF 2.0, strengthens data-at-rest requirements, and provides supporting coverage SC-12 and SC-13. |
Policy Disclaimer Statement
Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.