Minimizing data risk

Data is essential to our daily work at Harvard—from complicated research projects to everyday emails and files, much of what we do requires us to create, use, or store data. 

All data at Harvard carries a risk classification based on a five-tier scale:

  • Data intended to be public—like website posts or video recordings of public events—carries little to no risk and is designated as Level 1.
  • But other types of data—such as notes from a private meeting or files containing personal information—can pose real risk if mishandled or accessed by unauthorized parties and is designated as Level 2 - 5, where 5 reflects the highest risk. 

At a recent IT Stakeholders’ Forum, experts from across the University gathered to discuss how we can all minimize the risk of the data that we use. Here are some takeaways from their discussion.

 

Collect and keep data with purpose. 

Be deliberate about what data you collect and retain by keeping and protecting information that supports Harvard’s mission or serves as a historically valuable record, and deleting, archiving, or de-identifying data that no longer serves a clear need.

Tips:

 

Make data cleanup part of everyday work. 

Files are often forgotten about in older or inherited shared drives or systems. As some systems duplicate and feed data into other downstream systems, this can quickly increase privacy and security risk.

Tips:

 

Use the guidance and resources that are available at Harvard. 

Harvard's records schedules and University-wide Privacy Principles are designed to help you make informed decisions about data in your own work. 

Tip: 

 

You can watch a recording of the full panel discussion here. To sign up for future IT Stakeholder’s Forum events, email it_stakeholders@harvard.edu.