Research Information Classification
Overview
Research Information Classification is the process of identifying the type of information involved in a research activity and determining the sponsor, contractual, regulatory, export control, privacy, and institutional requirements that may apply to that information.
Different types of research information may require different levels of protection. Correctly identifying the information involved helps researchers determine appropriate administrative, physical, and technical safeguards throughout the research lifecycle.
The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable research information protection requirements, determining when additional safeguards may be required, and coordinating with the appropriate University offices.
Why Classification Matters
Research information is not protected using a single standard. The appropriate level of protection depends on the information involved and applicable sponsor requirements, contracts and agreements, federal regulations, export control requirements, privacy requirements, and University policies.
Proper classification helps researchers:
- Identify applicable sponsor and contractual requirements.
- Determine appropriate information protection measures.
- Protect confidential, controlled, or otherwise sensitive research information.
- Support responsible research collaboration and information sharing.
- Meet applicable regulatory, export control, privacy, and institutional requirements.
- Protect research information throughout the research lifecycle.
Research information may be subject to more than one requirement at the same time.
Relationship to the University Sensitive Information Classification Policy
Stony Brook University's Sensitive Information Classification Policy establishes the University-wide framework for classifying University Data according to risk and determining appropriate access, permissions, and security precautions.
Research information that constitutes University Data is subject to the University's classification framework. Depending on the information involved, research data may be classified as Category 1, Category 2, or Category 3 under the University policy.
Research activities may also be subject to additional or more specific requirements arising from sponsors, contracts and agreements, government information requirements, export control regulations, privacy requirements, controlled-access repositories, or other applicable authorities.
The Research Information Classification guidance on this page helps researchers identify additional research-specific requirements that may apply to research information and should be used together with the University's Sensitive Information Classification Policy and other applicable University information protection and cybersecurity requirements.
Sensitive Information Classification Policy
Classifying Research Information
Research information may be subject to multiple requirements simultaneously, and the applicable University classification does not replace additional sponsor, contractual, regulatory, export control, privacy, government, or data-provider requirements.
When evaluating research information, researchers should consider:
- Who created or provided the information?
- Is the information publicly available or intended for public release?
- Does a sponsor impose information protection or cybersecurity requirements?
- Is the information subject to a contract, confidentiality agreement, Data Use Agreement, or other restriction?
- Does the information contain personal or regulated information?
- Is the information subject to export control regulations?
- Is the information provided by or generated for the U.S. Government?
- Is access to the information controlled by a sponsor, repository, or other data provider?
- Are there University policies or other requirements governing its access, use, storage, sharing, or dissemination?
Common Types of Research Information
Research information may take many forms and may be subject to different requirements depending on its source, content, use, and applicable requirements. The examples below are research information types for purposes of identifying applicable requirements; they do not replace the classification categories established by the University's Sensitive Information Classification Policy.
| Information Type | Description | Learn More |
|---|---|---|
| Publicly Available Research Information | Research information that has been lawfully published or otherwise made publicly available without applicable restrictions on further dissemination. | Publicly Available Information |
| Research Records & Working Information | Laboratory notebooks, draft manuscripts, unpublished results, working datasets, and other research records requiring appropriate institutional safeguards. | Research Information Protection |
| Sponsor or Contractually Restricted Information | Proprietary, confidential, sponsor-provided, controlled-access, or other information subject to award, contract, Data Use Agreement, confidentiality, access, or dissemination restrictions. | Sponsor & Contractually Restricted Information |
| Government Information | Information provided by or generated for the U.S. Government, including Controlled Unclassified Information (CUI), Federal Contract Information (FCI), classified information, and other government-controlled information. |
|
| Export-Controlled Information | Technical data, technology, software, source code, defense articles, and other information subject to U.S. export control regulations. | Export-Controlled Information |
| Personal Information | Personally Identifiable Information (PII), Protected Health Information (PHI), human subjects research data, education records, and other personal information subject to applicable privacy or institutional requirements. | Privacy & Personal Information in Research |
Determining Applicable Requirements
Once the types of research information involved have been identified, the requirements applicable to that information should be determined before selecting safeguards or computing, storage, or technical environments.
Depending on the research activity, applicable requirements may arise from:
- Sponsor award terms and conditions.
- Contracts and subcontracts.
- Data Use Agreements and confidentiality agreements.
- Federal regulations and agency requirements.
- Export control regulations.
- Government information requirements.
- Privacy requirements.
- Controlled-access repositories or data providers.
- University policies and procedures.
These requirements may affect how research information may be accessed, stored, processed, transmitted, shared, retained, or disposed of.
Depending on the project, additional measures may include Data Protection Plans, Technology Control Plans, specialized computing, storage, cybersecurity, or other technical safeguards.
Relationship to Research Cybersecurity
Information classification helps determine the cybersecurity and information protection measures appropriate for a research activity.
The Research Cybersecurity Baseline provides basic cybersecurity practices that support University research. Additional safeguards may be required when research information is subject to sponsor, contractual, regulatory, export control, privacy, government, controlled-access, or other specific requirements.
Researchers should not assume that a particular University storage or computing environment is appropriate for information subject to specific safeguarding requirements.
How ORS Can Help
ORS assists researchers by:
- Identifying the types of research information involved in a project.
- Reviewing applicable sponsor, contractual, regulatory, export control, data access, cybersecurity, and research information protection requirements.
- Identifying when additional safeguarding or cybersecurity requirements apply.
- Identifying when specialized computing, storage, cybersecurity, or other technical safeguards may be required.
- Identifying when Data Protection Plans, Technology Control Plans, or other project-specific safeguarding documentation may be required.
- Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, privacy and compliance offices, and other University offices, as appropriate.
- Providing research-specific guidance throughout the proposal, award, and research lifecycle.
Related Guidance
| Reference Guide | Description |
|---|---|
| Sensitive Information Classification Policy | University-wide policy establishing risk-based classification categories and associated information protection requirements for University Data. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified for research information. |
| Research Cybersecurity Baseline | Review basic cybersecurity practices that support University research activities. |
Need Assistance?
If you are uncertain what type of research information is involved in your project or which sponsor, contractual, regulatory, export control, privacy, or institutional requirements may apply, contact the Office of Research Security.
ORS will assist in identifying applicable research-specific requirements and coordinate with the appropriate University offices when additional administrative, physical, technical, or other safeguards are required.