Research Information Protection
Research Information Protection & Cybersecurity
Overview
Research Information Protection & Cybersecurity is a component of Stony Brook University's Research Security Program that helps faculty, staff, and students identify research information protection and cybersecurity requirements applicable to research activities.
Federal research sponsors increasingly require institutions to protect research information through research security programs, sponsor award terms and conditions, contractual obligations, and other regulatory requirements. These requirements support the federal research security framework established under National Security Presidential Memorandum-33 (NSPM-33) and related federal guidance.
The Office of Research Security (ORS) administers research information protection and cybersecurity activities within the Research Security Program and assists researchers in identifying applicable sponsor, contractual, regulatory, export control, privacy, and institutional requirements affecting research information. ORS provides guidance throughout the research lifecycle and coordinates with the appropriate University offices to support implementation of required safeguards.
CONTACT ORS | VIEW RESEARCH ACTIVITIES & GUIDANCE
How ORS Can Help
Reviews & Determinations
- Research information protection reviews
- Sponsor safeguarding and cybersecurity requirements
- Government information reviews
- Export-controlled information reviews
- Project-specific safeguarding requirements
Research Support
- Data Protection Plans
- Government information guidance
- Research cybersecurity consultations
- International data-sharing guidance
- Secure research computing coordination
- Coordination with University offices
Guidance & Training
- Faculty consultations
- Sponsor-specific guidance
- Educational resources
- Research security training
University Resources
Research information protection and cybersecurity may require support from multiple University offices depending on the research activity and applicable requirements.
ORS serves as the administrative lead and point of contact for research information protection and cybersecurity requirements within the Research Security Program. ORS identifies applicable research-specific requirements and coordinates with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, and other University offices, as appropriate, to support implementation.
University technology resources and services are available to help researchers identify computing, storage, cybersecurity, information security, and other technical solutions appropriate for the requirements applicable to their research.
University RESEARCH DATA PROTECTION & CYBERSECURITY RESOURCES
Sponsor and Institutional Requirements
Research information protection and cybersecurity requirements are project-specific and may arise from sponsor award terms and conditions, federal or state regulations, contractual obligations, export control requirements, privacy requirements, University policies, and other institutional requirements.
Stony Brook University's Sensitive Information Classification Policy establishes the University-wide framework for classifying University Data and determining appropriate information protection requirements. Research information may also be subject to additional or more specific sponsor, contractual, regulatory, export control, privacy, government, or data-provider requirements.
ORS assists researchers in identifying research-specific requirements and coordinates with the appropriate University offices to support implementation throughout the research lifecycle.
Sensitive Information Classification Policy
RESEARCH DATA OWNERSHIP, RETENTION AND ACCESS POLICY
Research Activities & Guidance
ORS has developed activity-based guidance to help researchers identify the research information protection, cybersecurity, sponsor, contractual, export control, privacy, and institutional requirements that may apply to common research activities.
Researchers planning a specific activity should begin with the guidance below.
BROWSE RESEARCH ACTIVITIES & GUIDANCE
Examples include:
| Research Activity | Description |
|---|---|
| Sharing Research Information | Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties. |
| Working with Government Information | Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information. |
| Working with Proprietary & Confidential Research Information | Guidance for research involving sponsor-provided confidential information, Data Use Agreements (DUAs), proprietary information, controlled-access repositories, and other contractually restricted research information. |
| Data Protection Plans | Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans. |
| Secure Research Computing | Guidance for research requiring specialized computing environments, storage, access controls, or sponsor-required cybersecurity safeguards. |
| International Travel | Guidance for international travel involving research, teaching, field work, conferences, or other University activities. |
Research Information Protection & Cybersecurity Reference Guides
ORS maintains reference guides that explain research information protection principles, federal cybersecurity requirements, sponsor expectations, and research security concepts.
These guides provide additional background information and should be used in conjunction with the activity-based guidance above.
BROWSE RESEARCH INFORMATION PROTECTION & CYBERSECURITY REFERENCE GUIDES
Research Information Protection Concepts
Examples include:
| Reference Guide | Description |
|---|---|
| Research Information Classification | Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, data access, and other requirements help determine the appropriate classification and protection of research information. |
| Research Information Protection | Learn common principles for protecting research information throughout the research lifecycle and implementing appropriate safeguards. |
| Research Cybersecurity Baseline | Learn about recommended baseline cybersecurity practices that support the protection of research information and compliance with federal sponsor expectations. |
| Research Physical Security Baseline | Learn about recommended physical security practices for protecting research information, research equipment, and research environments. |
| Sponsor- & Contractually Restricted Information | Learn about research information subject to sponsor, contractual, confidentiality, data use, access, or dissemination requirements. |
Federal Information Protection & Cybersecurity Requirements
Examples include:
| Reference Guide | Description |
|---|---|
| Controlled Unclassified Information (CUI) | Learn about Controlled Unclassified Information and the safeguarding and dissemination requirements that may apply to CUI used in research. |
| Federal Contract Information (FCI) | Learn about Federal Contract Information and the contractual safeguarding requirements that may apply to FCI used in research. |
| Export-Controlled Information | Learn about technical data, technology, software, source code, and other research information subject to U.S. export control requirements and the safeguards that may apply. |
| NIH Controlled-Access Data | Learn about requirements for accessing, using, storing, and protecting controlled-access data obtained through NIH repositories. |
| Covered Telecommunications Equipment & Services | Learn about federal restrictions on certain telecommunications and video surveillance equipment and services that may affect federally funded research and University purchases. |
| Covered Applications | Learn about federal restrictions on certain software applications that may apply to federally funded research activities and devices used to perform covered work. |
| Kaspersky Lab Covered Entities | Learn about federal restrictions on certain hardware, software, and services developed or provided by Kaspersky Lab Covered Entities that may affect federally funded research and other University activities. |
Need Assistance?
Contact ORS if you are uncertain whether research information protection, cybersecurity, sponsor, contractual, export control, privacy, government, data access, or institutional requirements apply to a research activity.
ORS will assist in identifying applicable research-specific requirements and coordinate with the appropriate University offices when additional administrative, physical, or technical safeguards are required.