The University’s privacy officer, Laurel Gift, sent a memo out recently about best practices for protecting your privacy when it comes to scheduling meetings through your Outlook calendar.
“As we increasingly rely on these tools to manage external and internal appointments, ensuring the security, privacy, and integrity of these bookings is paramount,” Gift’s memo said. “This is especially true as we engage in confidential work supporting students, staff, and faculty across the University.”
She had some recommendations and best practice reminders for using Outlook and shared bookings technologies.
• Use the University’s preferred clients, Microsoft Outlook and the Outlook mobile app, for your calendaring needs and keep current with Microsoft Office updates.
• Make sure your Outlook calendar is only visible to the people who need to see it. The permission levels in Outlook let you control who sees what on your calendar.
1. Free/Busy Time: This is the default setting and the most basic level. It only shows whether you’re free, busy, tentative or out of the office. No details about your appointments are visible.
2. Free/Busy Time, Subject, Location: This level shows your free/busy status plus the subject and location of your appointments.
3. Full Details: This level shows everything.
• Send an email rather than an appointment if you want to invite people to a meeting and maintain the confidentiality of other participants. All meeting attendees can see who else is invited but cannot see their attendance status. Only the organizer of the meeting can see attendee status.
• Keep private meeting notes separate. Notes included in the body of the appointment details are emailed to all meeting attendees.
• Hide private appointments by clicking on the appointment tab and in the tags group, click “private.”
• Avoid sharing your calendar with users external to the University.
• Avoid publishing your calendar online.
• Regularly review and evaluate any permissions previously set, for example if you have shared your calendar with someone who is no longer with the University.
• Consider color-coding your appointments to visually highlight appointments you need to be extra careful about or to distinguish between private and public events.
• Avoid including personal identifiers in appointment names. Many applications, such as Bookings, allow for the restriction of sharing details with users and the collection of sensitive user information.
• Avoid automatically forwarding your University email to external email accounts. The University uses DMARC (Domain-based Message Authentication, Reporting & Conformance) to enhance protection against phishing and email spoofing. If you forward your Pitt email to an external account, please note that some messages may not be delivered. For example, U.S. government agencies do not deliver email to forwarded addresses in compliance with a federal directive requiring strict DMARC adherence. Forwarding your Pitt email may also reduce your protection against phishing attacks, as forwarded messages may bypass Pitt’s security filters that are designed to detect and block malicious content.