Issue
- I need to store sensitive or restricted data in Box
- How do I classify a file or folder in Box?
- I need to change the classification on a Box file or folder
- I need to remove a classification from a Box file or folder
- How do I protect sensitive University data I share with others in Box?
- I need a retention policy for records stored in Box
Environment
Resolution
Computing and Technology Services (CTS) uses Box Shield and Box Governance to protect Duquesne's most sensitive data when collaborating with internal and external partners. Box Shield lets you classify data stored in Box, which adds security controls and limits sharing and download options.
Data classifications
Data classifications are based on who should have access to institutional data stored in Duquesne's Box environment and help restrict sharing and download capabilities. Information stored in Box falls into one of four classifications: Public, Internal, Restricted and Restricted–Collaborative.
Public
Definition:
Data that is open to the public. The disclosure, alteration or destruction of this data poses little or no risk to the University.
Restrictions:
None
Examples:
- Course catalogs
- Job postings
- Campus maps
- Directory information for faculty, staff, or students (excluding information for which a Family Educational Rights and Privacy Act (FERPA) block has been requested.)
Internal
Definition:
Data that should be protected from general access and restricted to protected groups or individuals. The disclosure, alteration or destruction of this data poses some risk to the University.
Restrictions:
- Shared links cannot be made publicly accessible.
- External collaboration restricted.
- Download restricted on web for external users.
- Download restricted on mobile for external users.
- Download restricted on Box Drive for external users.
Examples:
- Non-Banner information stored in or accessed via the Duquesne Portal
- Non-public contracts
- Unpublished research papers
- Building floor plans
A full list of services that require Duo MFA is available on our Authentication Services page.
Restricted
Definition:
Data that could seriously or adversely impact the University. The disclosure, alteration or destruction of this data could cause a significant level of risk to the University.
Restrictions:
- Shared links allowed for collaborators only.
- External collaboration restricted.
- Download restricted on web, except Owners/Co-Owners/Editors. Also restricted for external users.
- Download restricted on mobile, except Owners/Co-Owners/Editors. Also restricted for external users.
- Download restricted on Box Drive, except Owners/Co-Owners/Editors. Also restricted for external users.
- Some application restrictions apply.
Examples:
- PII (Social Security numbers, driver's license numbers)
- Banking or financial account information
- Credit card information (PCI)
- Student protected data (FERPA)
- Health protected data (HIPAA)
- Human resource data
- University financial data
- Central authentication data
- Intellectual property data
Restricted–Collaborative
Definition:
Restricted data available outside of Duquesne University with security controls applied to restrict access.
Restrictions:
- Download restricted on web, except Owners/Co-Owners. Also restricted for external users.
- Download restricted on mobile, except Owners/Co-Owners. Also restricted for external users.
- Download restricted on Box Drive, except Owners/Co-Owners. Also restricted for external users.
How to Assign Classifications to Data
Open the Classify Menu
- Go to duq.edu/box and sign in with your MultiPass username and password.
- Click More options (...) on the file or folder you want to classify.
- Select Classify.
Add a Classification
- Open the Classify menu (see above).
- Choose the classification level you want to apply.
- Click Apply.
Change a Classification
- Open the Classify menu (see above).
- Choose the new classification level.
- Turn on the Overwrite all existing classifications with this value toggle.
- Click Apply.
- On the Overwrite Existing Classifications alert, click Proceed.
Remove a Classification
- Open the Classify menu (see above).
- Click Remove.
- On the Remove Classification alert, choose whether to remove an individual classification or all classifications.
- Select I understand this cannot be undone and operation may take time based on volume of content.
- Click Remove.
Request a Retention Policy
Box Governance allows CTS to set data retention periods for data with regulatory requirements, such as HIPAA and financial records.
- Email help@duq.edu to request a Box Governance retention policy for you or your department.
Additional Information
In addition to data classifications, Box Shield provides the following protections automatically:
- Malware protection: Scans files uploaded by internal and external users for potential malware.
- Anomalous downloads: Tracks suspicious download activity by Duquesne users that may indicate misuse of University data.
- Suspicious logins and locations: Detects access from untrusted locations or high-risk countries.
- Automatic data classification: Files containing personally identifiable information (PII) are automatically classified as Restricted.