Research Cybersecurity Baseline

Overview

The Research Cybersecurity Baseline identifies basic cybersecurity practices that support the protection of University research information, systems, and technology.

These practices provide a starting point for research activities that do not have additional cybersecurity or information protection requirements. Some research projects require additional safeguards because of sponsor requirements, contractual obligations, federal regulations, Data Use Agreements, the sensitivity of the information involved, or other applicable requirements.

Examples may include research involving Controlled Unclassified Information (CUI), Federal Contract Information (FCI), export-controlled information, controlled-access data, personal information, proprietary information, or other information subject to specific safeguarding requirements.

The Office of Research Security (ORS) assists researchers in identifying applicable research cybersecurity and information protection requirements and coordinates with the appropriate University offices when additional safeguards are required.

CONTACT ORS


Federal Research Cybersecurity Requirements

Federal research sponsors increasingly require institutions and researchers to implement appropriate cybersecurity safeguards for research information.

For federal grants, cooperative agreements, and other financial assistance awards, 2 CFR § 200.303 requires recipients and subrecipients to take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information and other information considered sensitive.

Federal contracts and other awards may establish additional or more specific cybersecurity requirements through award terms and conditions, contract clauses, agency requirements, Data Use Agreements, or other agreements.

The appropriate safeguards therefore depend on the research activity, information involved, sponsor, award mechanism, and applicable requirements.

Important: The Research Cybersecurity Baseline does not replace project-specific cybersecurity or information protection requirements. Contact ORS when an award, agreement, sponsor, or data source establishes specific safeguarding or cybersecurity requirements.


Use University-Owned & Managed Computers and Equipment

Whenever possible, conduct University research using University-owned and appropriately managed computers, devices, and equipment.

University-managed systems help support:

  • Operating system and software updates.
  • Security patches.
  • Endpoint security protections.
  • University authentication requirements.
  • Appropriate system configuration and technical support.

Researchers should work with the appropriate University offices before purchasing computers, research equipment, information technology, or other systems that will store, process, transmit, or access research information.

Personal devices should not be used for research when sponsor, contractual, regulatory, institutional, or information protection requirements require University-managed or specifically configured systems.

University Resources:


Use University-Provided Accounts & Services

Use University-provided accounts and approved services for University research activities.

Researchers should:

  • Use their University NetID and institutional accounts.
  • Use University email for research-related communications.
  • Use University-supported software and cloud services.
  • Avoid using personal email accounts or personal cloud storage for University research information.
  • Keep personal information and University research information separate.

University-provided services incorporate institutional authentication, security, administration, and support that may not be available through personal accounts.

University Resources:

  • NetID — Information about University NetID accounts and access to University systems.
  • SoftWeb — University-supported and licensed software available to eligible faculty, staff, and students.

Use Multi-Factor Authentication

Use University-required multi-factor authentication to protect accounts and systems.

Multi-factor authentication provides an additional layer of protection when a password or other account credential is compromised.

Researchers should never approve an unexpected authentication request and should report suspicious authentication activity through appropriate University information security channels.

University Resource:


Securely Store & Back Up Research Information

Research information should be stored using University-approved storage and computing resources appropriate for the type and sensitivity of the information.

Researchers should:

  • Store research information in approved University systems.
  • Maintain appropriate backups.
  • Limit storage of research information on local devices when unnecessary.
  • Avoid personal cloud storage services for University research.
  • Use storage environments appropriate for the sensitivity and requirements of the information.
  • Confirm that the selected environment meets applicable sponsor, contractual, regulatory, and Data Use Agreement requirements.

Not every University storage or computing environment is appropriate for every type of research information.

Not every University storage or computing environment is appropriate for every type of research information. Researchers should confirm that the selected environment is appropriate for the information involved and any applicable project requirements.

Contact ORS before storing research information subject to sponsor, contractual, regulatory, export control, government, or other specific safeguarding requirements. ORS will help identify applicable requirements and coordinate with Research Computing & Informatics (RCI) and other University offices, as appropriate, to determine an appropriate storage or computing environment.


Keep Systems & Software Current

Use supported operating systems and software and keep systems current with security updates.

Researchers should:

  • Enable automatic updates when appropriate.
  • Install security patches promptly.
  • Use University-supported software.
  • Remove software that is no longer required.
  • Avoid installing unauthorized or untrusted applications.
  • Confirm whether sponsor or federal restrictions apply before installing software on devices used for federally funded research.

Certain federal awards may restrict the acquisition or use of particular applications, hardware, software, telecommunications equipment, or services.

University Resource:

  • SoftWeb — University-supported and licensed software available to eligible University users.

Protect Accounts & Credentials

Protect University credentials and research system accounts from unauthorized access.

Researchers should:

  • Use strong, unique passwords.
  • Never share passwords or authentication credentials.
  • Use multi-factor authentication where available.
  • Avoid storing passwords in unsecured files or documents.
  • Use University-approved password management tools when appropriate.
  • Immediately report suspected account compromise.

Access credentials should be provided only to individuals authorized to access the applicable research systems or information.


Manage Access to Research Information

Access to research information should be limited to individuals who need access for legitimate research or administrative purposes.

Research teams should:

  • Maintain current lists of project personnel.
  • Provide access based on project responsibilities.
  • Use the minimum level of access necessary.
  • Review access periodically.
  • Remove access when personnel leave a project or no longer require it.
  • Review external collaborators, vendors, service providers, and systems that have access to research information.

Researchers should also periodically reassess whether changes to a project, personnel, sponsor requirements, or the information involved affect existing access permissions.

Projects involving controlled or restricted information may require additional personnel authorization, access controls, or documentation.


Protect Research Laboratories & Equipment

Physical security is an important component of research cybersecurity and information protection.

Researchers should:

  • Limit access to laboratories and research spaces to authorized individuals.
  • Secure computers, devices, equipment, and removable media.
  • Protect research equipment connected to University networks.
  • Review visitor access when research spaces contain sensitive or controlled information or technology.
  • Coordinate with appropriate University offices when specialized network or equipment protections are required.

Physical and electronic access controls should be appropriate for the information, equipment, and research activity involved.


Protect Against Phishing & Other Cybersecurity Threats

Researchers should remain alert to phishing, credential theft, malicious software, social engineering, and other cybersecurity threats.

Research personnel should:

  • Complete required University cybersecurity training.
  • Verify unexpected requests for credentials, payments, data, or system access.
  • Avoid opening suspicious links or attachments.
  • Report suspected phishing attempts.
  • Report lost or stolen University devices.
  • Report suspected unauthorized access to research systems or information.

Research groups may be particularly attractive targets because of the value of research information, intellectual property, technology, and access to specialized systems.

University Resources:


Review External Systems & Services

Researchers should understand where research information is stored, processed, transmitted, and shared.

Before using an external system, vendor, cloud service, collaborator platform, or other third-party resource, consider:

  • What information will be shared.
  • Who will have access.
  • Where the information will be stored or processed.
  • Whether the service is approved for University use.
  • Whether sponsor or contractual requirements apply.
  • Whether international access or storage is involved.
  • Whether additional cybersecurity or information protection requirements apply.

Do not assume that a commercially available service is appropriate for University research simply because it provides security features.

Researchers should consult the appropriate University offices before acquiring or using external technology or services when review or approval is required.


When Additional Safeguards May Be Required

The Research Cybersecurity Baseline is a starting point. Additional safeguards may be required when research involves:

  • Controlled Unclassified Information (CUI).
  • Federal Contract Information (FCI).
  • Export-controlled information.
  • Government information.
  • NIH or other controlled-access data.
  • Personal or regulated information.
  • Proprietary or confidential information.
  • Data Use Agreements.
  • Sponsor-specific cybersecurity requirements.
  • Federal contract cybersecurity requirements.
  • International research or data sharing.
  • Other information subject to regulatory, contractual, sponsor, or institutional requirements.

Depending on the project, additional requirements may include specialized research computing environments, access restrictions, encryption, logging, monitoring, Data Protection Plans, Technology Control Plans, or other administrative, physical, and technical safeguards.

Researchers should contact ORS before receiving or accessing information subject to requirements they are uncertain how to implement.


How ORS Can Help

ORS assists researchers by:

  • Identifying applicable sponsor, contractual, regulatory, and research information protection requirements.
  • Determining whether baseline cybersecurity practices are sufficient for a research activity.
  • Identifying when additional safeguards are required.
  • Reviewing sponsor cybersecurity and information protection requirements.
  • Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, and other University offices, as appropriate.
  • Supporting the development and implementation of project-specific Data Protection Plans, Technology Control Plans, or other safeguards when required.
  • Providing guidance throughout the research lifecycle.

Related Guidance

Reference Guide Description
Research Information Protection Learn how administrative, physical, and technical safeguards are identified for different types of research information.
Government Information Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply.
Controlled Unclassified Information (CUI) Learn about federal safeguarding requirements applicable to Controlled Unclassified Information used in research.
Federal Contract Information (FCI) Learn about Federal Contract Information and associated safeguarding requirements.
Export-Controlled Information Learn about protecting technical data, technology, software, source code, and other information subject to U.S. export control regulations.
Privacy & Personal Information in Research Learn about research involving personal information and overlapping privacy, sponsor, contractual, cybersecurity, and research information protection requirements.

Additional University Resources

Additional information about University offices and services supporting research data protection, cybersecurity, privacy, and research computing is available on the University Research Data Protection & Cybersecurity Resources page.

University Research Data Protection & Cybersecurity Resources


Need Assistance?

If you are uncertain what cybersecurity or information protection requirements apply to your research, contact the Office of Research Security.

ORS will assist in identifying applicable requirements, determining whether additional safeguards are needed, and coordinating with the appropriate University offices to support secure and compliant research.

CONTACT ORS