Secure Research Computing
Overview
Most research at Stony Brook University can be conducted using standard University-supported research computing and information technology resources. Some research projects, however, are subject to sponsor, contractual, regulatory, data access, export control, or institutional requirements that require enhanced cybersecurity, storage, access, or other technical safeguards.
These requirements may apply to research involving government information, Federal Contract Information (FCI), Controlled Unclassified Information (CUI), export-controlled information, NIH controlled-access data, sponsor- or contractually restricted information, or other research information subject to specialized safeguarding requirements.
The Office of Research Security (ORS) assists researchers in identifying the research-specific information protection and cybersecurity requirements that apply. When specialized computing, storage, or technical safeguards are required, ORS coordinates with Research Computing & Informatics (RCI), DoIT, and other appropriate University technology offices to support identification and implementation of resources appropriate for those requirements.
Contact ORS Before You
Contact ORS before receiving, accessing, storing, or processing research information if:
- A sponsor, agreement, data provider, or government agency requires specific cybersecurity, computing, storage, or information protection safeguards.
- The research involves CUI, FCI, export-controlled information, or other government information subject to specialized safeguarding requirements.
- Access to controlled-access data or another restricted repository requires institutional review or specific security safeguards.
- A Data Protection Plan, Technology Control Plan, System Security Plan, or other project-specific safeguarding documentation is required.
- Sponsor or contractual requirements specify particular cybersecurity standards, controls, certifications, or computing environments.
- You are uncertain whether standard University-supported research computing resources satisfy the requirements applicable to the research.
Key Considerations
Secure or specialized research computing may be required when the requirements applicable to a research project exceed the safeguards provided by standard University-supported computing, storage, or collaboration resources.
Requirements may arise from:
- Sponsor solicitations, awards, or terms and conditions.
- Research agreements or contracts.
- Government information requirements.
- Export control requirements.
- Data Use Agreements or data-provider requirements.
- Controlled-access repositories.
- Cybersecurity standards or frameworks incorporated into an award or agreement.
- University policies or other institutional requirements.
The need for specialized computing should be based on the requirements applicable to the research and the information involved.
Secure research computing requirements are established by the applicable sponsor, contract, agreement, regulation, or institutional requirement—not by ORS.
Depending on the project, these requirements may govern:
- Who may access research information.
- Where research information may be stored.
- How research information may be processed.
- How research information may be shared.
- Other project-specific information protection requirements.
Researchers should identify these requirements before research begins whenever possible.
Before selecting a computing, storage, or collaboration environment, researchers should understand the information involved and the requirements that apply to it.
Consider:
- What type of research information will be received, generated, stored, processed, or transmitted?
- Who is providing the information?
- Are there restrictions on who may access it?
- Are there requirements governing storage, transmission, encryption, authentication, logging, or other technical safeguards?
- Are there restrictions on international or remote access?
- Are specific cybersecurity standards or controls required?
- Does the sponsor, agreement, or data provider require approval of the computing environment?
- Is a Data Protection Plan, Technology Control Plan, System Security Plan, or other safeguarding documentation required?
Researchers should not assume that a particular University storage, cloud, computing, or collaboration service is appropriate for every type of research information.
Research information should be stored, processed, and transmitted using University-supported resources appropriate for the information and applicable requirements.
Different research projects may require different computing, storage, or technical environments. A resource suitable for ordinary research information may not satisfy requirements applicable to CUI, FCI, export-controlled information, controlled-access data, sponsor- or contractually restricted information, or other information requiring specialized safeguards.
ORS assists researchers in identifying applicable research-specific requirements. Research Computing & Informatics (RCI) and the Division of Information Technology (DoIT) provide research computing, information technology, cybersecurity, information security, and related resources and services within their respective areas of responsibility.
When specialized safeguards or technical environments are required, ORS coordinates
with RCI, DoIT, and other appropriate University technology offices to support implementation
of the applicable research requirements.
Secure research computing is not a single environment or standard set of controls. The safeguards required depend on the requirements applicable to the particular research activity.
Depending on the project, requirements may include:
- Restricted or role-based access.
- Multi-factor authentication.
- Encryption.
- Specialized storage or computing environments.
- Restrictions on downloading or local storage.
- Restrictions on portable devices or removable media.
- Restrictions on remote or international access.
- Logging or monitoring.
- Specific backup or recovery requirements.
- Network or endpoint security controls.
- Project-specific cybersecurity standards or controls.
- Additional documentation, training, or access procedures.
Researchers should follow the safeguards established for their specific project and should not move research information to another system or service without confirming that the alternative resource satisfies applicable requirements.
ORS assists researchers with the research-specific requirements associated with secure research computing by:
- Identifying applicable sponsor, contractual, regulatory, export control, government, data access, and institutional requirements.
- Determining whether project-specific requirements establish safeguards beyond applicable University baselines.
- Reviewing sponsor and agreement requirements related to research information protection and cybersecurity.
- Identifying when a Data Protection Plan, Technology Control Plan, System Security Plan, or other project-specific safeguarding documentation may be required.
- Coordinating with RCI, DoIT, and other appropriate University offices when specialized computing, storage, cybersecurity, or technical safeguards are required.
- Providing research-specific guidance throughout the proposal, award, and research lifecycle.
Related Guidance
| Related Guidance | Description |
|---|---|
| Research Information Classification | Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, data access, and other requirements help determine the appropriate classification and protection of research information. |
| Data Protection Plans | Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans. |
| Working with Government Information | Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information. |
| Working with NIH Controlled-Access Data | Guidance for requesting, receiving, storing, sharing, and using NIH controlled-access data and other sponsor-controlled research repositories. |
| Working with Proprietary & Confidential Research Information | Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations. |
| Sharing Research Information | Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties. |
Frequently Asked Questions
Does every research project require secure research computing?
No. Most research can be conducted using standard University-supported research computing and information technology resources. Specialized or secure research computing may be required when sponsor, contractual, regulatory, data access, export control, government, or institutional requirements establish safeguards beyond those provided by standard resources.
Who determines whether my project requires secure research computing?
The need for secure or specialized research computing is driven by the requirements applicable to the research activity and information involved.
ORS assists researchers in identifying applicable research-specific requirements. When specialized technical safeguards are required, ORS coordinates with RCI, DoIT, and other appropriate University technology offices to support identification and implementation of an appropriate technical environment.
Can I choose a University storage or computing service myself?
Researchers should use University-supported resources appropriate for the information and applicable requirements. However, not every University computing, storage, cloud, or collaboration service is appropriate for every type of research information.
If your project is subject to specialized safeguarding requirements and you are uncertain whether a resource is appropriate, contact ORS before storing or processing the information.
Is secure research computing the same as a Data Protection Plan?
No. A Data Protection Plan documents project-specific information protection requirements and safeguards. A secure or specialized computing environment may be one of the safeguards used to satisfy those requirements.
Can project requirements change during the research lifecycle?
Yes. Requirements may change if the project receives new information, adds collaborators, changes sponsors or agreements, begins using a new data source, changes the computing environment, or becomes subject to additional sponsor or contractual requirements.
Researchers should contact ORS when a material change may affect the information protection or cybersecurity requirements applicable to the project.
Need Assistance?
Contact ORS if your research is subject to specialized information protection or cybersecurity requirements or if you are uncertain whether standard University-supported resources are appropriate.
ORS will help identify the applicable research-specific requirements and coordinate with RCI, DoIT, and other appropriate University offices when specialized computing, storage, cybersecurity, or technical safeguards are required.