Arkansas State University logo
Approved Software Directory

Search approved software, compare data-use boundaries, and identify reviewed tools for university work.

This directory records ITS security and accessibility approval; it does not grant purchasing authority or confirm contract status. Software may be purchased by P-Card only with advance approval, and purchases over $20,000 generally require competitive bidding. Review Procurement rules before committing funds.

Data Classification Guidance

This page explains the data classification levels used in the Approved Software Directory. In this directory, the "Approved for" label indicates the highest university data classification a software product is currently approved to handle.

How to read "Approved for" in the directory

The classification shown on a software profile is not just a descriptive label. It is a data allowance boundary. For example, if a tool is marked Approved for: Internal, that means the tool should not be used for Confidential or Regulated data unless a separate review and approval says otherwise.

Public

Information approved for public release with no expectation of confidentiality. Unauthorized disclosure poses no risk to the university, its operations, or individuals. Public data may be shared freely without restriction.

Lowest sensitivity

Typical examples

  • Public websites
  • University regulations
  • Course catalog
  • ASU System directory information
  • Public research

What this means in the directory

If a tool is approved for Public data, it should only be relied on for information already intended for public release. Public approval should not be interpreted as permission to use Internal, Confidential, or Regulated data in that tool.

Internal

Information intended for internal university use only. Unauthorized disclosure could cause minor operational, reputational, or administrative impact. Access is limited to authorized university personnel and affiliates with a legitimate business need.

Moderate sensitivity

Typical examples

  • Internal memos or procedures
  • System security plans
  • Unpublished research results
  • Exams, question banks, and answer keys

What this means in the directory

If a tool is approved for Internal data, it may be appropriate for normal internal university work, but it should not automatically be used for Confidential or Regulated data. Additional review would still be needed for higher-risk data.

Confidential

Sensitive information that requires protection to prevent significant risk to the university or individuals. Unauthorized disclosure could result in financial loss, legal exposure, reputational harm, or disruption of university operations.

High sensitivity

Typical examples

  • Student records
  • Class schedules
  • Transcripts
  • Personally identifiable information
  • Employee data
  • FERPA-protected records

What this means in the directory

If a tool is approved for Confidential data, it may be considered for more sensitive university information, but that does not automatically make it appropriate for legally regulated data such as HIPAA, PCI, CJIS, or GLBA-covered information.

Regulated

Information subject to legal, regulatory, or contractual requirements. Unauthorized disclosure could result in severe financial loss, legal exposure, reputational harm, or major disruption of university operations. This is the highest classification level in the current draft policy.

Highest sensitivity

Typical examples

  • Export-controlled data
  • Credit card cardholder data
  • Social Security numbers
  • Donor financial records
  • Identifiable patient health records
  • HIPAA, PCI, CJIS, and GLBA-related data

What this means in the directory

If a tool is approved for Regulated data, it would need to meet the strongest legal, contractual, and security expectations. This level should be interpreted carefully, because regulated data carries the highest institutional risk.

AI and Data Handling Note

The current draft policy states that data classified as Confidential or Regulated is not permitted for entry into AI tools unless explicitly authorized. It also states that Internal data is permitted only on university-maintained and approved AI platforms.