Research Information Protection
Overview
Research information may require different levels of protection depending on the nature of the information and the sponsor, contractual, regulatory, export control, privacy, data access, and institutional requirements that apply to the research activity.
Research information protection includes the administrative, physical, and technical safeguards used to protect research information from unauthorized access, use, disclosure, modification, loss, or destruction.
The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable research information protection requirements and coordinates with the appropriate University offices to support implementation of required safeguards.
Determining Appropriate Safeguards
There is no single set of safeguards that applies to all research information.
The appropriate protections depend on factors such as:
- The type and sensitivity of the research information.
- Who created or provided the information.
- Sponsor or award requirements.
- Contractual, Data Use Agreement, or other data access requirements.
- Government information protection requirements.
- Export control requirements.
- Privacy or confidentiality requirements.
- Restrictions on access, use, sharing, or dissemination.
- The systems, equipment, and environments used to store or process the information.
- Other applicable regulatory or institutional requirements.
Research information may be subject to more than one requirement at the same time.
Researchers who are uncertain what type of research information is involved should review the Research Information Classification guidance or contact ORS.
Research Information Classification
Administrative Safeguards
Administrative safeguards establish how research information is managed and who is authorized to access or use it.
Depending on the project, administrative safeguards may include:
- Identifying personnel authorized to access research information.
- Establishing roles and responsibilities for protecting information.
- Reviewing sponsor, contractual, and regulatory requirements.
- Maintaining appropriate agreements and documentation.
- Providing required training.
- Periodically reviewing personnel access.
- Establishing procedures for sharing or transferring information.
- Developing Data Protection Plans, Technology Control Plans, or other project-specific safeguarding plans when required.
- Establishing procedures for reporting suspected loss, unauthorized access, or disclosure.
The specific administrative safeguards required depend on the research activity and applicable requirements.
Physical Safeguards
Physical safeguards protect research information, equipment, and research spaces from unauthorized physical access, loss, or disclosure.
Depending on the project, physical safeguards may include:
- Limiting access to laboratories, offices, or other research spaces.
- Securing computers, equipment, and physical records.
- Controlling visitor access.
- Protecting portable devices and research equipment.
- Securely storing physical research materials and records.
- Appropriately disposing of physical records or media.
- Implementing additional facility or access controls when required.
Researchers should review the Research Physical Security Baseline for physical security practices supporting University research activities.
Projects involving export-controlled information, government information, or other information subject to specialized safeguarding requirements may require additional physical access controls.
Technical Safeguards
Technical safeguards protect research information stored, processed, accessed, or transmitted electronically.
Depending on applicable requirements, safeguards may include:
- Authentication and access controls.
- Multi-factor authentication.
- Secure research storage.
- Encryption, when required.
- Secure methods for transmitting or sharing information.
- System and software updates.
- Endpoint protection.
- Logging or monitoring, when required.
- Backup and recovery measures.
- Network protections.
- Secure research computing environments.
The appropriate technical environment depends on the information involved and the requirements applicable to the research project.
Researchers should review the Research Cybersecurity Baseline for cybersecurity practices supporting University research activities.
Researchers should not assume that a particular University storage, cloud, computing, or collaboration service is appropriate for all types of research information.
Research Computing & Storage
Research information should be stored, processed, and transmitted using University-supported resources appropriate for the information and applicable requirements.
Different research projects may require different computing, storage, or technical environments. Resources appropriate for ordinary research information may not satisfy requirements applicable to CUI, export-controlled information, sponsor- or contractually restricted information, information subject to Data Use Agreements or controlled-access requirements, or other information subject to specialized safeguarding requirements.
ORS assists researchers in identifying the requirements that apply to research information. Research Computing & Informatics (RCI), the Information Security Office, and other University technology organizations may assist in identifying and implementing computing, storage, and technical solutions that meet those requirements.
Contact ORS before receiving, accessing, storing, or processing information subject to sponsor, contractual, government, export control, controlled-access, or other specialized safeguarding requirements if you are uncertain what requirements apply.
Project-Specific Protection Requirements
Some research activities are subject to sponsor, contractual, regulatory, export control, data access, or other requirements that establish safeguards beyond the University's research cybersecurity and physical security baselines. When additional requirements apply, protections must be appropriate for the research activity and the information involved.
Depending on the project, additional requirements may include:
- Restricted personnel access.
- Specialized research computing or storage environments.
- Additional authentication or access controls.
- Specific storage or transmission requirements.
- Physical access or visitor controls.
- Restrictions on portable devices or media.
- Restrictions on international access or sharing.
- Sponsor-required cybersecurity controls.
- Technology Control Plans (TCPs).
- Data Protection Plans.
- Project-specific training or documentation requirements.
- Other administrative, physical, or technical safeguards required by the applicable sponsor, contract, regulation, agreement, or data provider.
The specific safeguards required depend on the requirements applicable to the research activity.
How ORS Can Help
ORS assists researchers by:
- Identifying research information protection requirements.
- Reviewing sponsor, contractual, regulatory, export control, data access, and other applicable requirements.
- Determining whether baseline safeguards are sufficient and identifying additional administrative, physical, or technical safeguards when required.
- Identifying when Data Protection Plans, Technology Control Plans, or other project-specific safeguards may be necessary.
- Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, and other University offices, as appropriate.
- Providing guidance throughout the proposal, award, and research lifecycle.
Related Guidance
| Reference Guide | Description |
|---|---|
| Research Information Classification | Learn how to identify the type of research information involved and determine the sponsor, contractual, regulatory, export control, privacy, and institutional requirements that may apply. |
| Research Cybersecurity Baseline | Review basic cybersecurity practices that support University research activities. |
| Research Physical Security Baseline | Review basic physical security practices that support protection of research information, equipment, and research environments. |
Need Assistance?
If you are uncertain what safeguards are required for research information or whether baseline safeguards are sufficient for your research activity, contact the Office of Research Security.
ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices when additional safeguards are required.