Data Management at Sul Ross State University
The Data Management function at Sul Ross State University ensures the appropriate classification, security, and governance of institutional data in compliance with TAC 202 requirements and Texas State University System (TSUS) policies.
Data Management Officer Role
As required by Texas Government Code Section 2054.137, Sul Ross State University has designated a Data Management Officer (DMO) responsible for:
- Establishing the university’s data management program using DIR frameworks
- Coordinating with the Information Security Officer to implement best practices for managing and securing data
- Ensuring compliance with state privacy laws and data privacy classifications
- Conducting data maturity assessments
- Supporting institutional decision-making through data governance
DMO-RMO Collaboration
The Data Management Officer works closely with the Records Management Officer (RMO) to ensure proper governance throughout the data lifecycle, including:
- Ensuring records management programs cover all data storage media
- Consistently applying classification, retention, and disposition requirements
- Aligning information governance practices across physical and digital resources
- Addressing both data protection and records compliance in risk management
Data Classification Framework
Sul Ross State University has adopted a three-tier data classification system aligned with DIR guidelines. All institutional data must be classified according to this framework to ensure appropriate protection and handling.
Classification Level | Description | Examples | Required Controls |
Public | Information that can be freely disclosed to the public without consequences. | Course catalogs, press releases, marketing materials, public policies, institutional reports | Standard backup procedures, integrity checks, public accessibility |
Internal | Information intended for institutional use that requires basic security controls but isn’t strictly confidential. | Directory information (unless restricted), department budgets, meeting minutes, draft policies | Authentication required, basic encryption, access logging, internal system storage only |
Protected | Sensitive information requiring strict controls due to regulatory requirements or significant risk if disclosed. | Student records (FERPA), health information (HIPAA), financial data (PCI DSS), personnel records | Strong encryption, multi-factor authentication, strict access controls, audit logging, data sharing agreements |
Data Sensitivity Labeling
All institutional data should be labeled according to its sensitivity level to enable proper handling and protection. Sensitivity labels help identify the appropriate security controls and handling procedures for each data asset.
Sensitivity labels may be applied through:
- Visual markings on physical documents
- Metadata tagging for electronic files
- Header/footer markings for sensitive documents
- Email subject line prefixes for sensitive communications
- Database field and record classification
Policies & Procedures
The following policies and procedures govern data management at Sul Ross State University:
Data Governance Policy
This policy establishes the framework for data governance at Sul Ross State University, including roles, responsibilities, and decision-making authorities.
Data Classification Procedure
This procedure defines the three-tier classification system, criteria for classification decisions, and required protections for each level.
Data Security Controls
This document specifies the security requirements for each classification level, including access controls, encryption requirements, and audit procedures.
Data Sharing Procedure
This procedure outlines requirements for sharing data within the university and with external partners, including required agreements and security measures.
Records Retention Schedule
This schedule defines retention periods for institutional records and data in compliance with state requirements.
Resources & Training
Training Resources
- Data Classification Training (Online Module)
- Security Awareness Training for Data Stewards
- Records Management Training
- TSL Records Management Webinars
Additional Resources
Contacts
Data Management Officer
Name: David Mosley
Email: dmo@sulross.edu
Phone: (432) 837-8819
Office: Briscoe Administration Building (BAB), Room 202
Records Management Officer
Name: Kayla Waggoner
Email: kayla.waggoner@sulross.edu
Phone: (432) 837-8124
Information Security Officer
Name: Darren McIntire
Email: darren.mcintire@sulross.edu
Phone: (432) 555-9012
For urgent data security concerns, please contact the Information Security Office immediately.