Standards Group:
YALE-MSS-1: System Classification
YALE-MSS-1.1: Determine the system type and classify the IT system
Details
All Yale IT systems must meet and maintain the MSS. A Yale IT system is one that uses Yale data and/or operates in support of Yale's mission. Examples include IT systems hosted by Yale or by a third party on Yale's behalf (e.g., Workday, Microsoft OneDrive).
To determine the appropriate MSS for an IT system, the following must be understood.
- What is the IT system type?
- What is the risk classification?
- Is the system internet accessible?
- Does the system create, store, access, or transmit HIPAA or PCI data?
Once these answers are understood, Yale's MSS Calculator will determine a system's relevant MSS requirements.
Ensure a valid policy exception request is filed when a Minimum Security Standard (MSS) cannot be met.
The MSS covers four different IT system types: Endpoint, Server, Mobile Device, Printer.
- Endpoint - any desktop, laptop, or point of sale device.
- Server - a host that provides network-accessible services. Examples include web servers, file servers, databases, print servers, containers, and cloud services.
- Mobile Device - a smartphone or tablet that runs a mobile operating system.
- Network Printer - a printer connected to Yale's network that receives print jobs via a print server.
The MSS covers three different IT system risk classifications: Low, Moderate, High. Risk classification is determined through an IT system's data classification, availability requirements, and external obligations. Additional information on risk classification can be found on the Risk Classification Guideline page.
Internet-accessible systems allow connections from the public internet. This presents more risk to the IT System. Any MSS marked with "Required for IA" is a requirement for Internet Accessible Systems, which are systems that allow connections from the public internet without an additional layer of protection such as a Virtual Private Network (VPN).
HIPAA systems create, store, access, and transmit ePHI and identifiable human subject data.
PCI systems transmit credit card information for processing.
To initiate an exception request, see the Request an Exception page.