Data Documentation Policy

Version 2.0

For Students, Faculty, Staff, Guests, Alumni

Purpose

The purpose of this policy is to establish requirements for documenting the type, classification, location, processing, and retention of data being stored and processed on IT Resources. 

Scope

This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrators, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.

Policy Statement

  • When deploying a new system, retrofitting, or updating existing systems, or making a material change to how data is processed, data must be classified in accordance with the Data Classification and Protection Policy and Data Classification Guidelines, and the applicable data documentation must be created or updated.
  • At a minimum, data documentation must identify:
    • Name of the system, application, or service (e.g., Banner, PowerFAIDS)
    • Responsible department or Data Owner
    • Location and hosting environment (on-premises, cloud, or third-party service, as applicable)
    • Fordham data classification (Fordham Protected Data, Fordham Sensitive Data, or Public Data)
    • Type of data, where applicable (e.g., FERPA, PCI, PHI, PII)
    • Processing or data actions, including collection, use, access, storage, transmission or sharing, retention, and disposal, as applicable
    • Applicable retention requirement
  • For IT Resources that process Personally Identifiable Information (PII), the processing and retention of that information must be documented, including relevant data flows or data actions sufficient to show where and how the information is processed.
  • The department responsible for the IT Resource or the applicable Data Owner must ensure that data documentation is reviewed and updated when there is a material change to the IT Resource, data classification, data type, processing activity, storage location, data transfer, third-party service provider, retention requirement, or disposal method.
  • Data documentation must be maintained in an accessible, auditable manner and in a University-approved repository or record that is available to authorized personnel for security, privacy, risk, compliance, and operational review.
  • Retention periods and disposal requirements documented must follow Records Retention and Disposal Policy. This policy does not establish or supersede records-retention periods.

Definitions

Data Owner(s) are responsible for the information, security, and use of a particular set of information.

IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and any related materials and services.

NIST SP 800-53 Rev. 5 Alignment

  • Configuration Management: CM-12 Information Location; CM-13 Data Action Mapping.
  • System and Information Integrity: SI-12 Information Management and Retention. 

Related Policies and Procedures

Implementation Information

Review Frequency: Triennial
Responsible Person: Senior Director of IT Security and Assurance
Approved By: AVP/CIO
Approval Date: March 1, 2017

Revision History

Version: Date: Description:
1.0 01/24/2017 Initial document
1.0.1 03/01/2017 Grammatical changes only
1.0.2 05/23/2018 Updated disclaimer, scope, and definitions
1.1 09/11/2020 Updated policy statement
1.2 07/12/2023 Updated policy statement
2.0 08/28/2026 NIST CSF 2.0-aligned revisions; added PII processing and retention documentation requirements. 

Policy Disclaimer Statement

Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.

Need Help?


Walk-In Centers

McShane Center 266 | RH
Leon Lowenstein SL18 | LC

View Our Walk-In Hours