---
title: "Data Access and Authorization Policy"
canonical: "https://docs.pbs.org/space/DG/81133573/Data%20Access%20and%20Authorization%20Policy"
format: markdown
---
# User authorization, identification, and authentication policy

# (Digital and Marketing)

February 2024

> Macro (toc)

**Document details**

|  |  |
| --- | --- |
| <span style="color: #ffffff">**Document Owner**</span> | Data Governance Office in Digital & Marketing |
| <span style="color: #ffffff">**Storage Location**</span> | [Data Access and Authorization Policy can be found here](https://pbsus-my.sharepoint.com/:b:/g/personal/akaur_pbs_org/EapZ7freXmNEmOlvhRlEyZQBSYWyclx7B0YDr8jC3eBO4w?e=p46h8U) |
| <span style="color: #ffffff">**Related documents/circulars**</span> | [Digital Analytics Services Policy for General Audience Producers](https://docs.pbs.org/space/PX/3576948/Digital+Analytics+Services+Policy+for+General+Audience+Producers),<br>Data Access Request Form |
| <span style="color: #ffffff">**Classification**</span> | For Internal use |
| <span style="color: #ffffff">**Effective date**</span> |  |
| <span style="color: #ffffff">**Last review date**</span> | 03/13/2024 |
| <span style="color: #ffffff">**Next review date **</span><br><span style="color: #ffffff">**(Annual Review)**</span> | 03/13/2025 |

**Policy Approver(s)**

|  |  |  |
| --- | --- | --- |
| <span style="color: #ffffff">**Name**</span> | <span style="color: #ffffff">**Title**</span> | <span style="color: #ffffff">**Date**</span> |
| <span style="color: #000000">Amy Sample</span> | <span style="color: #000000">VP, Business Intelligence</span> | 02/29/2024 |
| <span style="color: #000000">Jen Hinders</span> | <span style="color: #000000">Sr. Director, Video Strategy</span> | 02/29/2024 |
| <span style="color: #000000">Kris Crosby</span> | <span style="color: #000000">Sr. Director, Product Development</span> | 02/29/2024 |

**Document Revision History (**Review to be conducted annually)

|  |  |  |  |
| --- | --- | --- | --- |
| <span style="color: #ffffff">**Version**</span> | <span style="color: #ffffff">**Document Changes Description**</span> | <span style="color: #ffffff">**Changes Made By**</span> | <span style="color: #ffffff">**Date**</span> |
|  |  |  |  |
|  |  |  |  |
|  |  |  |  |

# <u>ACCESS AND AUTHORIZATION POLICY</u> 

## Purpose

PBS maintains a coherent set of policies, standards, procedures, and guidelines to manage risks to its data and systems and to support the business in expanding services, partnerships, and agreements. 

This policy is designed by the Data Governance office in Digital and Marketing Department to help manage and protect data assets while ensuring responsible and compliant use. The purpose of this Data Access and Authorization Policy is to establish guidelines for controlling access to and authorization for the use of data collected, owned, and maintained by the Digital and Marketing Department. This policy ensures that data is accessed, utilized, and shared in a secure, compliant, and efficient manner aligning with data governance objectives. 

For Digital and Marketing Department to effectively manage and safeguard the data assets, procedures must be in place to guide appropriate data access, ensure the security of the data, and provide a means to address procedural exceptions.

## Scope

<span style="color: #000000">Data Access and Authorization Policy applies to all users, information systems and information system components owned, managed, and governed by Digital and Marketing </span>Department<span style="color: #000000">. Specifically, it includes:</span>

- <span style="color: #000000">All employees, whether employed on a full-time or part-time basis by PBS.</span>
- <span style="color: #000000">All contractors and third parties that work on behalf of PBS.</span>
- <span style="color: #000000">All employees of member stations, content producers and clients that access PBS’s non-public information systems.</span>

## Definitions

**Information System** – Any information technology (hardware, software, communication devices, network, and data resources) that processes (including storing, retrieving, transmitting, or otherwise processing) data and information for a specific purpose. 

**Information Asset** – An Information Asset is a definable piece of information (voice, video, or data) stored in any manner. This includes data sets, associated data elements, and attributes. 

**Users** – All PBS employees and independent contractors, and temporary workers, and all other individuals who have access to and use the Information Systems or Information Assets provided by PBS. 

**User responsibilities **– <span style="color: #000000">Defines the responsibilities of users regarding data usage and adherence to data governance practices. </span>

**Controls / Control Objectives **–** **Identify the technical, administrative, and physical protections that are tied to a law, regulation, industry framework or contractual obligation.

**Standards** – Provide PBS-specific, quantifiable requirements for cybersecurity and data protection.

**Procedures **– (Also known as Control Activities) establish the defined practices or steps performed to implement standards and satisfy controls/ control objectives.

**Guidelines **– Are additional guidance recommended but not mandatory. 

**Access Control Log** – Is a formal document that s<span style="color: #000000">pecifies who has access to the data assets and how access is granted.</span>

**Compliance** – <span style="color: #000000">Highlights the importance of complying with applicable laws, regulations, and industry standards.</span>

**Policy Enforcement **– <span style="color: #000000">Explains the consequences of policy violations, including disciplinary actions that may be taken.</span>

**Principle of least privilege** – Means that users be granted the least amount of access rights or permissions required to complete their job responsibilities and no more. 

## Roles and Responsibilities

**System Owner**

<span style="color: #000000">Systems owners include personnel who are system administrators or are otherwise responsible for managing PBS Information systems/technology for their respective department or corporate area.</span> 

**Data Owner **

<span style="color: #000000">Data owners include personnel with authority to decide who has the right to access and use data.</span>

**Data Steward **

<span style="color: #000000">Data steward is the single point of contact and champion of the assigned data and its appropriate use.</span>

**Data Custodian**

<span style="color: #000000">Data Custodian is the personnel that ensures proper use, protection, and adherence to data governance policies. </span>

## Policy 

Digital and Marketing develops access and authorization processes to ensure the confidentiality, integrity, and accessibility of PBS’s systems. Digital and Marketing shall implement and maintain logical access controls to limit access to systems and processes to authorized users. The principle of “least privilege” shall be enforced within logical access control mechanisms, so that only authorized users can gain access to PBS's systems and data. 

Access, Authorization, and Accountability controls are set up to ensure that only authorized users make use of information. Without these controls, the potential exists that information systems could be accessed illicitly, and the security of those systems be compromised.

- All data managed by Digital and Marketing is the property of PBS, and as such, all PBS staff members are responsible for appropriately respecting and protecting these data assets.

### **Access Management **

Establish a formal process for requesting access to data. Describes how access requests will be submitted, reviewed, and approved. 

**Access Request:**

- Data owners will be identified for each data set, and they will collaborate with data custodians to define access controls/permissions.
- <span style="color: #000000">All requests for data access must be submitted through a formal request process. The request shall include a statement indicating the access being sought and the reason for the request. Data owner and Data Steward will review the request before making the decision. If necessary, the requestor's manager will be contacted before access is granted. </span>
- <span style="color: #000000">All access requests must be submitted using PBS's official work email address exclusively. If the request originates from a consultant, third-party, or employee of producers or member stations, they are required to utilize their respective work email addresses. Access will not be granted to personal email accounts.</span>
- <span style="color: #000000">Once the policy is in effect, all existing users who have been granted access using non-work email addresses will be contacted and notified that the access will be revoked in 30 days.</span>
- The access request generated outside PBS email is subject to further inquiry. This might delay the approval.
- For third-party vendors and contractors, access requests must be generated through the associated PBS employee. This employee is responsible for the ethical use of data by that contractor and for promptly informing the Data Owner and Data Custodian of any necessary changes to access requirements.
- Additional details regarding Producer account access can be found in Digital Analytics Services Policy ([Digital Analytics Services Policy for General Audience Producers can be found HERE](https://docs.pbs.org/display/PX/Digital+Analytics+Services+Policy+for+General+Audience+Producers)).

**Access Approval:**

- Access requests shall be reviewed and approved by designated data stewards or data custodians. In most cases, PBS seeks to respond to the request within 7 business days.
- Access requests will be handled in sequential order. <span style="color: #000000">Time-sensitive requests must be initiated by the requestor's manager.</span>

**Access Control and Enforcement:**

- Data will be classified based on sensitivity, confidentiality, and regulatory requirements. Access controls will be determined according to the data classification, ensuring appropriate protection measures are in place.
- Data owners are responsible for ensuring that access permissions align with business needs and data protection requirements.
- Access permissions shall be assigned based on job roles, responsibilities, and the principle of least privilege. The principle of “least privilege” shall be enforced within logical access control mechanisms, so that only authorized users can gain access to PBS's systems and data.
- Access to specific data sets shall be granted only to individuals with a legitimate business need.

### **Authorization Levels **

Specify the levels of access and permissions that individuals or roles may have based on their job responsibilities. 

Distinct levels of authorization are implemented to safeguard data. The table below defines and explains permission/roles.

| **Permission level** | **Role** | **Definition** |
| --- | --- | --- |
| **Read-only** | Viewer | This access gives permission to view and retrieve data but restricted from making any changes or modifications. Users can see all reports and dashboards, explore, and analyze the dataset to discover patterns, trends, or insights without modifying the data. By default, a new user gets Read-only permission. |
| **Write/modify** | Editor | This type of access allows users to make changes to the existing data and/or existing account settings. Users have permission to edit all data elements and settings within the dataset. This level of access requires careful consideration due to the potential impact on data integrity. <span style="color: #000000">This type of access request requires manager validation.</span> |
| **Ownership/full control** | Administrator | This access gives full control over the dataset. Users can read, write, execute, delete, and manage datasets and modify permissions for other users. By default, this role is restricted to PBS employees only. |
| **Temporary Access** | Specialist | Allows users to access data at specific points in time or within defined time ranges. |

- All users will be assigned Read-Only access by default, regardless of their role. If a user requires higher access role, a formal request must be initiated that includes a justification for the elevated access level. A thorough review process will be conducted to assess the request.
- Users with Editor or Administrator access are prohibited from altering the admin settings of the account. Any proposed changes to settings must be communicated to the Data Steward or Business Process Owner for approval. Failure to notify and unauthorized implementation of setting changes will result in the user assuming responsibility for any resulting analytics tracking issues.

### **Accountability***** ***

Auditing and monitoring mechanisms will be implemented to manage user access logs. These access logs will be periodically reviewed to identify and address access activities and issues.

- Shared administrative accounts must be appropriately managed. Active management includes the acts of establishing, activating, modifying, disabling, and removing accounts from systems.
- <span style="color: #000000">There must be a centralized user directory for authorization and authentication (access control log).</span>
- Access to data systems shall be monitored regularly to detect unauthorized access.
- Designated data stewards or data custodians are responsible for auditing and maintaining access logs, which will be reviewed periodically to identify and address unauthorized activities. User access to systems and information must be revoked when no longer required.
- All user access privileges must be regularly reviewed for appropriateness.
- Audits of data access logs shall be conducted periodically to ensure compliance with this policy. Ideally audits must be conducted twice a year, more frequently if the need arises.
- An incident response plan will be in place to address and mitigate unauthorized access. Reporting procedures for suspected incidents will be clearly communicated, and appropriate actions will be taken to resolve incidents promptly.
- Password and other credential sharing are disallowed by this policy.
- <span style="color: #000000">Before individuals will be allowed to access PBS data, training in the use and attributes of the data, functional area data policies, and PBS policies regarding data is mandatory.</span>

## Exceptions

While every exception to a standard potentially weakens protection mechanism for PBS systems and underlying data, occasionally exceptions will be appropriate. Exception to standards must undergo a risk assessment by the Business Process Owner or Data Owner.

<u>*When requesting an exception, users must submit a business justification for deviation from the standard. *</u><u><span style="color: #000000">*Requests for exceptions to the policy must be approved by the requestor’s reporting manager. For member stations and producers, the exception request must be approved by the associated department head.*</span></u>

## Compliance

<span style="color: #000000">Regular compliance assessments shall be conducted to ensure adherence to this policy.</span>

<span style="color: #000000">Each system/data owner is required to document all procedures related to access control. Owners must have that documentation on hand if required for auditing purposes. The following documentation must be available for auditing purposes: demonstration of account approval, termination, and any disabling of accounts.</span>

## Non-Compliance

<span style="color: #000000">Violations of this policy will be treated like other allegations of wrongdoing at PBS. Allegations of misconduct will be adjudicated according to established procedures. Sanctions for non-compliance will result in temporary or permanent revocation of account access, this might affect future access requests.</span>

## Revision<span style="color: #000000"> </span>

<span style="color: #000000">The policy will undergo a comprehensive yearly review to assess its effectiveness, relevance, and alignment with evolving organizational needs, industry standards, and regulatory requirements. This review will be conducted by the designated policy review committee, which will consider feedback from stakeholders, emerging security threats, technological advancements, and changes in the business environment. The goal of the annual policy review is to ensure the continued robustness, applicability, and compliance of the policy, fostering a culture of continuous improvement in data access and authorization practices.</span>