Box: Classify and Store Restricted Data

Issue

  • I need to store sensitive or restricted data in Box
  • How do I classify a file or folder in Box?
  • I need to change the classification on a Box file or folder
  • I need to remove a classification from a Box file or folder
  • How do I protect sensitive University data I share with others in Box?
  • I need a retention policy for records stored in Box

Environment

  • Box

Resolution 

Computing and Technology Services (CTS) uses Box Shield and Box Governance to protect Duquesne's most sensitive data when collaborating with internal and external partners. Box Shield lets you classify data stored in Box, which adds security controls and limits sharing and download options.

Data classifications

Data classifications are based on who should have access to institutional data stored in Duquesne's Box environment and help restrict sharing and download capabilities. Information stored in Box falls into one of four classifications: Public, Internal, Restricted and Restricted–Collaborative.

Public
Internal
Restricted
Restricted–Collaborative

How to Assign Classifications to Data

Open the Classify Menu

  1. Go to duq.edu/box and sign in with your MultiPass username and password.
  2. Click More options (...) on the file or folder you want to classify.
  3. Select Classify.

Add a Classification

  1. Open the Classify menu (see above).
  2. Choose the classification level you want to apply.
  3. Click Apply.

Change a Classification

  1. Open the Classify menu (see above).
  2. Choose the new classification level.
  3. Turn on the Overwrite all existing classifications with this value toggle.
  4. Click Apply.
  5. On the Overwrite Existing Classifications alert, click Proceed.

Remove a Classification

  1. Open the Classify menu (see above).
  2. Click Remove.
  3. On the Remove Classification alert, choose whether to remove an individual classification or all classifications.
  4. Select I understand this cannot be undone and operation may take time based on volume of content.
  5. Click Remove.

Request a Retention Policy

Box Governance allows CTS to set data retention periods for data with regulatory requirements, such as HIPAA and financial records.

  1. Email help@duq.edu to request a Box Governance retention policy for you or your department.

Additional Information

In addition to data classifications, Box Shield provides the following protections automatically:

  • Malware protection: Scans files uploaded by internal and external users for potential malware.
  • Anomalous downloads: Tracks suspicious download activity by Duquesne users that may indicate misuse of University data.
  • Suspicious logins and locations: Detects access from untrusted locations or high-risk countries.
  • Automatic data classification: Files containing personally identifiable information (PII) are automatically classified as Restricted.
Print Article

Related Services / Offerings (1)

Box
Box is a cloud storage service that you can use for file sharing and collaboration across multiple devices.