Back

Data Management at Sul Ross State University

The Data Management function at Sul Ross State University ensures the appropriate classification, security, and governance of institutional data in compliance with TAC 202 requirements and Texas State University System (TSUS) policies.

Data Management Officer Role

As required by Texas Government Code Section 2054.137, Sul Ross State University has designated a Data Management Officer (DMO) responsible for:

  • Establishing the university’s data management program using DIR frameworks
  • Coordinating with the Information Security Officer to implement best practices for managing and securing data
  • Ensuring compliance with state privacy laws and data privacy classifications
  • Conducting data maturity assessments
  • Supporting institutional decision-making through data governance

DMO-RMO Collaboration

The Data Management Officer works closely with the Records Management Officer (RMO) to ensure proper governance throughout the data lifecycle, including:

  • Ensuring records management programs cover all data storage media
  • Consistently applying classification, retention, and disposition requirements
  • Aligning information governance practices across physical and digital resources
  • Addressing both data protection and records compliance in risk management

Data Classification Framework

Sul Ross State University has adopted a three-tier data classification system aligned with DIR guidelines. All institutional data must be classified according to this framework to ensure appropriate protection and handling.

Classification Level Description Examples Required Controls
Public Information that can be freely disclosed to the public without consequences. Course catalogs, press releases, marketing materials, public policies, institutional reports Standard backup procedures, integrity checks, public accessibility
Internal Information intended for institutional use that requires basic security controls but isn’t strictly confidential. Directory information (unless restricted), department budgets, meeting minutes, draft policies Authentication required, basic encryption, access logging, internal system storage only
Protected Sensitive information requiring strict controls due to regulatory requirements or significant risk if disclosed. Student records (FERPA), health information (HIPAA), financial data (PCI DSS), personnel records Strong encryption, multi-factor authentication, strict access controls, audit logging, data sharing agreements

Data Sensitivity Labeling

All institutional data should be labeled according to its sensitivity level to enable proper handling and protection. Sensitivity labels help identify the appropriate security controls and handling procedures for each data asset.

Sensitivity labels may be applied through:

  • Visual markings on physical documents
  • Metadata tagging for electronic files
  • Header/footer markings for sensitive documents
  • Email subject line prefixes for sensitive communications
  • Database field and record classification

Policies & Procedures

The following policies and procedures govern data management at Sul Ross State University:

Data Governance Policy

This policy establishes the framework for data governance at Sul Ross State University, including roles, responsibilities, and decision-making authorities.

Data Classification Procedure

This procedure defines the three-tier classification system, criteria for classification decisions, and required protections for each level.

Data Security Controls

This document specifies the security requirements for each classification level, including access controls, encryption requirements, and audit procedures.

Data Sharing Procedure

This procedure outlines requirements for sharing data within the university and with external partners, including required agreements and security measures.

Records Retention Schedule

This schedule defines retention periods for institutional records and data in compliance with state requirements.

Records Management Website – Training and Procedures

Contacts

Data Management Officer

Name: David Mosley

Email: dmo@sulross.edu

Phone: (432) 837-8819

Office: Briscoe Administration Building (BAB), Room 202

 

Records Management Officer

Name: Kayla Waggoner

Email: kayla.waggoner@sulross.edu

Phone: (432) 837-8124

 

Information Security Officer

Name: Darren McIntire

Email: darren.mcintire@sulross.edu

Phone: (432) 555-9012

 

For urgent data security concerns, please contact the Information Security Office immediately.