Research Information Classification

Overview

Research Information Classification is the process of identifying the type of information involved in a research activity and determining the sponsor, contractual, regulatory, export control, privacy, and institutional requirements that may apply to that information.

Different types of research information may require different levels of protection. Correctly identifying the information involved helps researchers determine appropriate administrative, physical, and technical safeguards throughout the research lifecycle.

The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable research information protection requirements, determining when additional safeguards may be required, and coordinating with the appropriate University offices.

CONTACT ORS


Why Classification Matters

Research information is not protected using a single standard. The appropriate level of protection depends on the information involved and applicable sponsor requirements, contracts and agreements, federal regulations, export control requirements, privacy requirements, and University policies.

Proper classification helps researchers:

  • Identify applicable sponsor and contractual requirements.
  • Determine appropriate information protection measures.
  • Protect confidential, controlled, or otherwise sensitive research information.
  • Support responsible research collaboration and information sharing.
  • Meet applicable regulatory, export control, privacy, and institutional requirements.
  • Protect research information throughout the research lifecycle.

Research information may be subject to more than one requirement at the same time.


Classifying Research Information 

Research information should be evaluated based on the characteristics of the information and the requirements that apply rather than assigned to a single institutional classification.

When evaluating research information, researchers should consider:

  • Who created or provided the information?
  • Is the information publicly available or intended for public release?
  • Does a sponsor impose information protection or cybersecurity requirements?
  • Is the information subject to a contract, confidentiality agreement, Data Use Agreement, or other restriction?
  • Does the information contain personal or regulated information?
  • Is the information subject to export control regulations?
  • Is the information provided by or generated for the U.S. Government?
  • Is access to the information controlled by a sponsor, repository, or other data provider?
  • Are there University policies or other requirements governing its access, use, storage, sharing, or dissemination?

Research information may fall into more than one category and may be subject to multiple requirements simultaneously.


Common Types of Research Information

 
Information Type Description Learn More
Publicly Available Research Information Research information that has been lawfully published or otherwise made publicly available without applicable restrictions on further dissemination. Publicly Available Information
Research Records & Working Information Laboratory notebooks, draft manuscripts, unpublished results, working datasets, and other research records requiring appropriate institutional safeguards. Research Information Protection
Sponsor or Contractually Restricted Information Proprietary, confidential, sponsor-provided, controlled-access, or other information subject to award, contract, Data Use Agreement, confidentiality, access, or dissemination restrictions. Sponsor & Contractually Restricted Information
Government Information Information provided by or generated for the U.S. Government, including Controlled Unclassified Information (CUI), Federal Contract Information (FCI), classified information, and other government-controlled information.

 

Government Information

Export-Controlled Information Technical data, technology, software, source code, defense articles, and other information subject to U.S. export control regulations. Export-Controlled Information
Personal Information  Personally Identifiable Information (PII), Protected Health Information (PHI), human subjects research data, education records, and other personal information subject to applicable privacy or institutional requirements. Privacy & Personal Information in Research

Determining Applicable Requirements

Once the types of research information involved have been identified, the requirements applicable to that information should be determined before selecting safeguards or research computing environments.

Depending on the research activity, applicable requirements may arise from:

  • Sponsor award terms and conditions.
  • Contracts and subcontracts.
  • Data Use Agreements and confidentiality agreements.
  • Federal regulations and agency requirements.
  • Export control regulations.
  • Government information requirements.
  • Privacy requirements.
  • Controlled-access repositories or data providers.
  • University policies and procedures.

These requirements may affect how research information may be accessed, stored, processed, transmitted, shared, retained, or disposed of.

Depending on the project, additional measures may include Data Protection Plans, Technology Control Plans, specialized research computing environments, access restrictions, cybersecurity safeguards, or other administrative, physical, and technical controls.


Relationship to Research Cybersecurity

Information classification helps determine the cybersecurity and information protection measures appropriate for a research activity.

The Research Cybersecurity Baseline provides basic cybersecurity practices that support University research. Additional safeguards may be required when research information is subject to sponsor, contractual, regulatory, export control, privacy, government, controlled-access, or other specific requirements.

Researchers should not assume that a particular University storage or computing environment is appropriate for information subject to specific safeguarding requirements.


How ORS Can Help

ORS assists researchers by:

  • Identifying the types of research information involved in a project.
  • Reviewing sponsor, contractual, regulatory, export control, and research information protection requirements.
  • Identifying when additional safeguarding or cybersecurity requirements apply.
  • Identifying when specialized storage or research computing environments may be required.
  • Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, privacy and compliance offices, and other University offices, as appropriate.
  • Supporting the development and implementation of Data Protection Plans, Technology Control Plans, and other project-specific safeguards, when required.
  • Providing guidance throughout the proposal, award, and research lifecycle.

Related Guidance

Reference Guide Description
Research Information Protection Learn how administrative, physical, and technical safeguards are identified for research information.
Research Cybersecurity Baseline Review basic cybersecurity practices that support University research activities.

Need Assistance?

If you are uncertain what type of research information is involved in your project or which sponsor, contractual, regulatory, export control, privacy, or institutional requirements may apply, contact the Office of Research Security.

ORS will assist in identifying applicable research information protection requirements and coordinate with the appropriate University offices to determine and implement required safeguards.

CONTACT ORS