Secure Research Computing

Overview

Most research at Stony Brook University is conducted using the University's standard research computing and information technology resources. However, some research projects are subject to sponsor, contractual, regulatory, or institutional requirements that require researchers to use University-approved secure research computing resources.

These requirements may apply to projects involving Federal Contract Information (FCI), government-controlled information, NIH controlled-access data, proprietary or confidential research information, or other research information requiring enhanced safeguards.

The Office of Research Security (ORS) serves as the administrative lead for coordinating researcher access to approved secure research computing resources when required and works with the appropriate University offices to support projects with enhanced information protection requirements.

SCHEDULE A CONSULTATION

CONTACT ORS


Contact ORS Before You

Contact ORS if your research project:

  • Requires use of University-approved secure research computing resources.
  • Involves Federal Contract Information (FCI).
  • Involves government-controlled information.
  • Involves NIH controlled-access data.
  • Involves proprietary or confidential research information subject to enhanced information protection requirements.
  • Requires a Data Protection Plan that includes enhanced computing, storage, access, or information protection requirements.
  • Includes sponsor, contractual, or regulatory requirements governing how research information must be stored, processed, accessed, or protected.
  • Requires assistance determining whether secure research computing is required.

Key Considerations

Not all research projects require secure research computing.

Projects may require University-approved secure research computing resources when sponsors, contracts, regulations, or institutional requirements establish information protection standards beyond the University's standard research computing environment.

Examples include projects involving:

  • Federal Contract Information (FCI).
  • Government-controlled information.
  • NIH controlled-access data.
  • Proprietary or confidential research information subject to enhanced safeguarding requirements.
  • Sponsor-required secure computing environments.
  • Research projects with Data Protection Plans requiring enhanced computing or information protection safeguards.
  • Other research activities requiring enhanced information protection.

Secure research computing requirements are established by the applicable sponsor, contract, agreement, regulation, or institutional requirement—not by ORS.

Depending on the project, these requirements may govern:

  • Who may access research information.
  • Where research information may be stored.
  • How research information may be processed.
  • How research information may be shared.
  • Other project-specific information protection requirements.

Researchers should identify these requirements before research begins whenever possible.

Researchers should contact ORS as early as possible when a project may require secure research computing.

ORS supports these projects by:

  • Reviewing applicable sponsor, contractual, regulatory, and institutional requirements.
  • Determining whether University-approved secure research computing resources are required.
  • Coordinating researcher onboarding and access with the appropriate University offices.
  • Assisting with project-specific information protection requirements.
  • Evaluating changes that may affect computing, access, or information protection requirements.

Researchers should contact ORS before research information requiring secure computing is received, stored, or processed.


Related Guidance

Related Guidance Description
Data Protection Plans Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans.
Working with Government Information Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information.
Working with NIH Controlled-Access Data Guidance for requesting, receiving, storing, sharing, and using NIH controlled-access data and other sponsor-controlled research repositories.
Working with Proprietary & Confidential Research Information Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations.
Sharing Research Information Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties.

Frequently Asked Questions

Does every research project require secure research computing?

No. Most research projects can be conducted using the University's standard research computing resources. Secure research computing may be required when sponsor, contractual, regulatory, or institutional requirements call for enhanced information protection or cybersecurity safeguards.


Who determines whether my project requires secure research computing?

The need for secure research computing is generally driven by sponsor, contractual, regulatory, or institutional requirements. ORS assists researchers in identifying applicable requirements and determining whether University-approved secure research computing resources are needed.


 

Is secure research computing the same as a Data Protection Plan?

No.

A Data Protection Plan documents the project-specific information protection requirements and safeguards applicable to a research project. Secure research computing may be one of the safeguards used to satisfy those requirements.


Need Assistance?

Some research projects require information protection measures beyond the University's standard research computing and information security practices. Early consultation with ORS helps researchers identify these requirements, determine whether secure research computing resources are needed, and coordinate access with the appropriate University offices before research begins.

SCHEDULE A CONSULTATION

CONTACT ORS