Research Security Roles and Responsibilities
Shared Responsibility
Research security is a shared responsibility across the Stony Brook University research community. Researchers, departments, research administrators, and University offices all play an important role in protecting the integrity and security of research while supporting the openness, collaboration, and academic freedom fundamental to the University's research mission.
The Office of Research Security (ORS) administers the University's Research Security Program and works collaboratively with the University community to help identify applicable research security requirements, provide guidance, and coordinate institutional review and support throughout the research lifecycle.
Responsibilities of the Research Community
Faculty, investigators, research staff, students, and research administrators have responsibilities for understanding and complying with requirements applicable to their research activities.
Transparency & Disclosure
Researchers should:
- Submit complete, accurate, and timely University and sponsor disclosures.
- Disclose external relationships, appointments, affiliations, research support, and other activities as required.
- Update disclosures when circumstances change.
- Seek guidance when University or sponsor disclosure requirements are unclear.
Responsible Research Activities
Researchers should:
- Understand and comply with applicable sponsor requirements, University policies, agreements, and federal regulations.
- Engage ORS early when planning activities that may require research security, international research, export control, or research information protection review.
- Provide complete and accurate information when requesting institutional reviews or determinations.
- Follow any project-specific requirements or safeguards identified for the research activity.
- Work with ORS and other University offices when additional review or coordination is required.
Protecting Research Information & Assets
Researchers should:
- Protect research information, equipment, materials, software, technology, and other research assets from unauthorized access, use, disclosure, loss, or transfer.
- Identify and follow sponsor, contractual, government, export control, privacy, cybersecurity, and other requirements applicable to research information.
- Use University-supported computing, storage, and other resources appropriate for the research information and applicable requirements.
- Implement required administrative, physical, and technical safeguards.
- Contact ORS before receiving, accessing, storing, or using information subject to specialized safeguarding requirements when the applicable requirements are uncertain.
Training & Awareness
Researchers should:
- Complete required research security training.
- Complete additional sponsor-, project-, or activity-specific training when required.
- Remain aware of research security responsibilities applicable to their research activities.
- Seek guidance when circumstances change or new requirements arise.
Responsibilities of the Office of Research Security
ORS administers and coordinates the University's Research Security Program and serves as a resource for faculty, staff, students, research administrators, and institutional leadership.
ORS responsibilities include:
- Providing guidance regarding University and sponsor disclosure requirements.
- Conducting international research reviews and providing international research guidance.
- Administering the University's Export Control Compliance Program.
- Identifying research information protection and cybersecurity requirements applicable to research activities.
- Reviewing government, export-controlled, sponsor-restricted, and other protected research information requirements.
- Identifying sponsor-specific research security requirements.
- Developing and coordinating Data Protection Plans, Technology Control Plans, and other research security safeguards, when required.
- Conducting Restricted Entity Screening and other research security reviews.
- Providing research security training, education, and outreach.
- Coordinating with University offices when additional expertise, review, or implementation support is required.
- Providing guidance throughout the proposal, award, and research lifecycle.
ORS does not replace the responsibilities of investigators, departments, sponsors, or other University offices. Research security requirements are addressed through coordinated institutional processes appropriate to the research activity.
Institutional Coordination
Research security requirements may involve multiple University offices and areas of expertise.
Depending on the research activity, ORS coordinates with offices responsible for sponsored programs, research administration, information technology and cybersecurity, research computing, legal and regulatory matters, conflicts of interest and commitment, intellectual property, international activities, environmental health and safety, and other University functions.
This coordinated approach helps researchers identify and address applicable requirements without requiring investigators to independently determine which University offices may need to be involved.
Reporting Research Security Concerns
Members of the University community who become aware of a potential research security or export control concern should report it promptly.
Potential concerns may include:
- Unauthorized access, use, disclosure, loss, or transfer of protected research information.
- Potential export control or sanctions violations.
- Undisclosed external relationships, appointments, affiliations, support, or activities.
- Requests for research information, technology, software, materials, or access that may be inconsistent with applicable requirements.
- Potential cybersecurity incidents affecting protected research information.
- Suspected noncompliance with a research security requirement or project-specific safeguarding plan.
- Other activities that may present research security or compliance concerns.
EthicsPoint
Concerns may be reported through:
- EthicsPoint: Reports may be submitted via SBU's secure third-party confidential reporting system by web and mobile devices or telephone (see information provided below). Select the "Export Control/Research Security Concern" type. Reports may be submitted anonymously. Mobile & Web Report is available or you may report by phone at (833) 223-7024
OR
- You may e-mail or call (631-632-1954) the Director of Research Security.
Working Together
Research security is most effective when researchers, departments, research administrators, and University offices work together throughout the research lifecycle.
Early engagement allows ORS to identify applicable requirements, coordinate with University partners, and provide guidance before commitments are made, protected information is received, or research activities begin.
ORS is committed to supporting research that is open, collaborative, innovative, and conducted in accordance with applicable sponsor requirements, federal regulations, agreements, and University policies.
REQUEST A RESEARCH SECURITY REVIEW