This standard defines permitted and regulated uses of such university-owned data.
Contact the Information Security Office at security@unomaha.edu for questions about this standard. The University of Nebraska Omaha (UNO) engages in research, teaching, clinical, and business activities that encompass a variety of regulated data.
Scope and Authority
This standard applies to all faculty, researchers, staff, students, and contractors of UNO. The Information Security Office, a division of Information Services, is responsible for the maintenance and interpretation of this standard.
Standard
Members of the university community have an individual and shared responsibility to:
- Maintain university-owned regulated data only in the environments permitted by this standard
- Never maintain university-regulated data on personally-owned devices or via personally-maintained services
- Report a violation of this standard, whether intentional or unintentional, as an information security incident per the UNO Information Security Incident Reporting Policy to security@unomaha.edu within twenty-four (24) hours
|
Definitions |
|
|---|---|
| Regulated Data |
Data that requires the university to implement specific privacy and security safeguards as mandated by federal, state, and/or local law, or university policy or agreement. Regulations or categories of data most applicable to UNO include:
The University of Nebraska has defined the following student information as public directory information:
|
| IT Environment | Any IT service directly maintained by the university, under contract or agreement with UNO, or that is personally-owned or maintained but is used for university business. |
| University-owned | Any data that is created or maintained under the auspices of an individual's institutional role as a university employee or affiliate. |
| Personally-owned | Any device or service that is not governed by a university contract or agreement. |