SVSU recommends not storing documents with sensitive information in them. Whenever possible, we ask that you delete the file and then be sure to empty the file from the recycle bin.
If removing the file is not possible use Adobe Acrobat Password Protection or MS Purview to encrypt the file.
MS Purview is a service that helps manage and secure data across various platforms, ensuring compliance with privacy regulations and enhancing data protection. Purview uses a system of labels to classify data stored within an email or document. These labels are applied within Adobe Acrobat and Office 365 when data has been scanned and identified.
Sending unencrypted email messages containing sensitive financial data or Personally Identifiable Information is a violation of SVSU policy; whether written in the body or as an attachment. Unencrypted Email is sent in clear text that can easily be intercepted and read by anyone, while in transit.
Examples of Sensitive Data:
- Social Security numbers
- Driver’s License numbers
- Passport numbers
- State-issue ID numbers
- Any bank/financial account numbers
- Credit/debit card numbers
- Protected health information
- Documents protected by attorney-client privilege
- Any passwords or authentication credentials
Select Data Format
Adobe Password Protection - Recommended Method
Password Protect the PDF File
If the document you wish to apply protection to is a PDF,
follow the instructions at this Securing PDFs with Passwords page to add a password/encrypt the file.
You will need Adobe Acrobat to complete these steps. Installation instructions are found in the Related Articles section of this page, under Adobe Creative Cloud Installation Guide.
This is a quick version of how encrypt and assign a password to a PDF file with Adobe Acrobat:
-
Open the PDF in Acrobat, and do one of the following:
- Choose File > Protect Using Password.
-
If you receive a prompt, click Yes to change the security.
-
Decide between allowing Viewing or Editing access, and then type and retype your password. Your password must be at least six characters long.
-
Click Apply. Acrobat displays a confirmation message that the file was successfully protected using password.
Once you assign a password to the file, please call the people you are sharing the file with to let them know the password. DO NOT email the password along with the file or in a separate email. Email is not secure and can be openly read among network traffic.
Redact Portions of Data within a PDF
When documents are shared with other parties or if they are stored on a computer drive, sensitive or private pieces information can redacted from a PDF. Redacting the portions of sensitive data will allow the file to pass information protection and data loss prevention scans because the text or images are permanently removed from the PDF file.
Follow instructions at this Adobe support page on How to Redact a PDF .
ITD Lab How-To Video
Purview within Adobe Acrobat - Secondary Method
MS Purview is a service that helps manage and secure data across various platforms, ensuring compliance with privacy regulations and enhancing data protection. Purview uses a system of labels to classify data stored within an email or document. These labels are applied within Adobe Acrobat and Office 365 when data has been scanned and identified.
If you prefer, you can use Purview, instead of the built in Password protection, to encrypt a PDF file. You will need to enable the PDF preference to make Purview available within Adobe Acrobat.
- Open Adobe Acrobat
- Click Menu or Edit, depending on your version of Adobe Acrobat
- Choose Preferences
- Select the Security Category
- Check the box next to Enable Microsoft Purview Information Protection
- Click OK
- Restart Adobe Acrobat (it may take a couple of restarts)
- You will know MS Purview is available from Adobe Acrobat when you see this option available:
- File -> Protect PDF-> Select a MS Purview Sensitivity Label
- Select one of the Labels explained above
Receiving a PDF Document with Purview Protection
External users, receiving Purview-Encrypted PDF documents, should use the Microsoft Edge Browser to view the PDF files. SVSU users can open the Purview-Encrypted PDF document with Adobe Acrobat. Note that Purview-Encrypted PDFs will not open within an Email Preview window nor browsers, other than MS Edge.
MS Purview is a service that helps manage and secure data across various platforms, ensuring compliance with privacy regulations and enhancing data protection. Purview uses a system of labels to classify data stored within an email or document. These labels are applied within Adobe Acrobat and Office 365 when data has been scanned and identified.
Thank you to Enabling Technologies for the permission to use their Purview training instructions, below.
There are many different labels that can be applied to emails, files, and documents. These are the ones we have implemented, and the GLBA will include items from the other categories, so is the most comprehensive label.
Automatic labeling is applied when the content of a file or message meets a certain confidence level. The confidence level is based on the amount of supporting evidence detected. View this support article from Microsoft regarding Purview Confidence Levels.
Label classifications are listed in order from the lowest to the highest sensitivity:
- General - This will be applied when there is no label specified.
- Personal - This should be applied to non-work-related records.
- Personally Identifiable Information (PII) – Full names, Social Security Numbers, Driver’s License number, financial information, and medical records. This should be encrypted and be defined by the end user who can decrypt.
- Financial Data - Anything related to financial activities and performance of a business or person. This could include data about monetary transactions, assets, income, liabilities, net worth, credit ratings, financial statements, and other indicators of profitability and growth. This should be encrypted and be defined by the end user who can decrypt.
- Gramm-Leach-Bliley Act (GLBA) - Social security numbers, credit card numbers, full names, U.S./U.K. passport numbers, U.S. driver's license numbers and U.S. physical addresses. This may also include items such as Budget proposals, Financial statements and reports. Tax information such as tax planning documents, tax forms, tax filing related documents and tax regulation documents.
- Confidential: Internal Use Only and Recipient Only
- Internal Use Only - Documentation or files that are confidential to the university. Only persons with an @svsu.edu email address will be able to de-crypt the content.
- Recipient Only - Documentation or files that are intended for a specific person only. Recipients will need to verify their identity prior to decrypting.
- When an email contains sensitive information in it, an automatic label will be applied. If the information contained in the email conflicts with our policy, a notification will also appear. To view the reason for the notification, click on Show details.
- After reading the details, if it is still unclear why a specific label was placed on an email, click Learn more to bring up details and Report if the label is incorrect. Learn more about reporting incorrect labels, below.
- If the policy notification is ignored, and the user still tries to send the email to the unauthorized recipient, a notification will appear that the email has been prevented from being sent due to conflicting with the policy.
Report Incorrect Labels
If the email is labeled incorrectly, but it needs to get sent out immediately, please:
1 - Click Report.
2 - Contact IT Support by calling 989-964-4225.
If the email is not urgent please Click Report and then email support@svsu.edu or create a ticket at mysupport.svsuedu.
The automatic sensitivity label can be adjusted. If this conflicts with the actual categorization as well as policy, please do not modify the label. Help keep SVSU data safe!
- While considering data security, follow the instructions above to Report the incorrect label to IT Support.
- Then, click the Sensitivity Icon, then select the appropriate security label.
At the top Outlook on the Web (stamp) or at the right of the Subject in Outlook Desktop Version (shield with lock).
Outlook on the Web View
Outlook Desktop Version View
- When prompted, select the appropriate justification for making the label change. These changes are reviewed by IT system admins.
- If you selected Other, you will be able to type a reason or comment to explain the change. Other is the only option that offers a place to type a reason for changing the label.
- Click Change.
To apply a sensitivity label to an email that was not automatically identified:
- Click Options.
- Click the stamp icon.
- Select the appropriate label option for the email.
- When determining which Confidential option to use:
- Internal Use Only will allow anyone within SVSU to view the information.
- Recipient Only (Do not forward) limits the ability to view the information to the person(s) you are sending the email to. Printing is not available when using this option.
Manually Encrypt an Email Message and Attachments
To skip labeling, but still encrypt email messages and attachments:
- Click Options
- Click on the Encrypt, padlock icon.
- Select the desired permission.
- Encrypt (Encrypt-Only) means that the recipient will need to sign in with their credentials and password for their email account. The email can be forwarded, the recipient can also copy and print the information in the email.
- Do Not Forward means in addition to the sign in prompt for encryption, the recipient also cannot forward the email to anyone, and they cannot print or copy the information from the email.
- The label and encryption will be noted and displayed on the message draft, as well as on the message that stored in the Outlook Sent folder.
Outlook Desktop Version View
Outlook on the Web View
More information on Email Encryption is available at this
Microsoft Support Page. This page also contains information, for the person receiving the message, to un-encrypt the message.
When you send an encrypted email, the recipient will not be able to view the content immediately. Within the body of the message they receive, will be a button to Read the message. This example is from a Gmail account.
The recipient will need to sign in with the credentials for their email account to view the message.
The Gmail account does not need to be tied to a Microsoft account to view the encrypted message.
Once a file is saved to an SVSU network or cloud storage, it will be scanned and a sensitivity label applied. File owners and those it is shared with, will need to be logged in to Office with an associated Microsoft account, like their SVSU account, based on their view or edit permission to the file. This should be noted when using Office on a personally owned computer.
Every new file will be scanned and have a sensitivity label automatically applied. A notification will appear stating which label has been applied. The notification can be dismissed by clicking OK.
To view the sensitivity label on existing files (J drive, OneDrive, and SharePoint within Teams), click on the Sensitivity Label icon.
Hovering over each label option provides a list of what type of information is contained within that category.
Online Office File View
Desktop Version File View
The automatic sensitivity label can be adjusted. If this conflicts with the actual categorization as well as policy, please do not modify the label. Help keep SVSU data safe!
- While considering data security, be sure to create a ticket at mysupport.svsu.edu regarding the mislabeling of a file.
- Click on the Sensitivity Label icon, shown above.
- When prompted, select the appropriate justification for making the label change. These changes are reviewed by IT system admins.
- If you selected Other, you will be able to type a reason or comment to explain the change. Other is the only option that offers a place to type a reason for changing the label.
- Click Change.
For files that are not Office 365 or PDF, it is recommended to use 7-Zip for encryption. Zipping a file is not ideal for files that need editing often since the file cannot simply be opened, edited and re-saved directly to a .ZIP file. Using Adobe Acrobat or Microsoft Purvue is a better encryption method for current files that need editing. 7-Zip can also be used as a more generic method of encrypting files that will be sent via Email.
If using 7-Zip to attach a file to an Email message, after the message is sent, the user receiving the message will download an attached ZIP file and open it using the password you supply to them.
ITD Lab How-To Video
Install 7-Zip
Before installing, check if 7-Zip is already installed on your computer.
- Click on the Start Button on your SVSU computer and Type Software Center (note there is no dialog box, just start typing). You will see a dialog box similar to the one below - click on Software Center.
- Software Center will open and you will see a screen similar to the one below - click on 7-Zip and then click Install in the next dialog box. 7-Zip will be installed.
If you do not see 7-Zip please open a ticket at mysupport.svsu.edu. Ask for assistance with running Configuration Manager with the following at the ticket description. "I'm trying to install 7-Zip and it does not show Software Center. I need assistance running Control Panel > System Security > Configuration Manager > Actions > Machine Policy Retrieval & Evaluation Cycle. Please assign this ticket to Technical Support per the Encrypting eMail Attachments Knowledge Article". A technician will contact you and assist in getting 7-Zip on Software Center for you.
Encrypt Files
- Open File Explorer on your computer.
- Select the files that you want to send as encrypted files by holding down the CTRL button and clicking to select multiple files.
- Release the CTRL button and Right Click within the highlighted, selected files, select 7-Zip, then Add to Archive
- Set the following items in the dialog box to these values (i.e. leave all defaults except those listed below)
- Change the Filename and location of where you want the file to be stored. The ... buttons allow you to select the storage location. The white dialog box is the file name.
- Archive format - zip
- Encryption method - ZipCrypto
- Enter the password
- Reenter the password
- Click OK
- The zipped file will be stored in the location you specified in the first bullet above.
- The encrypted zip file can now be attached to an email.
- If the receiver has an up to date Windows they will be able to decrypt it with windows explorer without needing to have 7-zip installed.
- You will need to provide them the password that you created when you encrypted the file.
- The user will receive the file in their email. They will need to download the file and open it using the password you supplied them.