Research Information Protection

Overview

Research information may require different levels of protection depending on the nature of the information and the sponsor, contractual, regulatory, export control, privacy, data access, and institutional requirements that apply to the research activity.

Research information protection includes the administrative, physical, and technical safeguards used to protect research information from unauthorized access, use, disclosure, modification, loss, or destruction.

The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable research information protection requirements and coordinates with the appropriate University offices to support implementation of required safeguards.

CONTACT ORS


Determining Appropriate Safeguards

There is no single set of safeguards that applies to all research information.

The appropriate protections depend on factors such as:

  • The type and sensitivity of the research information.
  • Who created or provided the information.
  • Sponsor or award requirements.
  • Contractual, Data Use Agreement, or other data access requirements.
  • Government information protection requirements.
  • Export control requirements.
  • Privacy or confidentiality requirements.
  • Restrictions on access, use, sharing, or dissemination.
  • The systems, equipment, and environments used to store or process the information.
  • Other applicable regulatory or institutional requirements.

Research information may be subject to more than one requirement at the same time.

Stony Brook University's Sensitive Information Classification Policy establishes the University-wide framework for classifying University Data and associated information protection requirements. The Research Data Ownership, Retention and Access Policy establishes additional responsibilities for the management, sharing, retention, security, disposition, access, and transfer of Research Data.

Research information may also be subject to additional or more specific sponsor, contractual, regulatory, export control, privacy, government, data access, or other requirements.

Researchers who are uncertain what type of research information is involved should review the Research Information Classification guidance or contact ORS.

Research Information Classification

Sensitive Information Classification Policy

Research Data Ownership, Retention and Access Policy


Administrative Safeguards

Administrative safeguards establish how research information is managed and who is authorized to access or use it.

Depending on the project, administrative safeguards may include:

  • Identifying personnel authorized to access research information.
  • Establishing roles and responsibilities for protecting information.
  • Reviewing sponsor, contractual, and regulatory requirements.
  • Managing research information in accordance with applicable requirements for access, sharing, retention, security, disposition, and transfer.
  • Maintaining appropriate agreements and documentation.
  • Providing required training.
  • Periodically reviewing personnel access.
  • Establishing procedures for sharing or transferring information.
  • Developing Data Protection Plans, Technology Control Plans, or other project-specific safeguarding plans when required.
  • Establishing procedures for reporting suspected loss, unauthorized access, or disclosure.

The specific administrative safeguards required depend on the research activity and applicable requirements.


Physical Safeguards

Physical safeguards protect research information, equipment, and research spaces from unauthorized physical access, loss, or disclosure.

Depending on the project, physical safeguards may include:

  • Limiting access to laboratories, offices, or other research spaces.
  • Securing computers, equipment, and physical records.
  • Controlling visitor access.
  • Protecting portable devices and research equipment.
  • Securely storing physical research materials and records.
  • Appropriately disposing of physical records or media.
  • Implementing additional facility or access controls when required.

Researchers should review the Research Physical Security Baseline for physical security practices supporting University research activities.

Projects involving export-controlled information, government information, or other information subject to specialized safeguarding requirements may require additional physical access controls.


Technical Safeguards

Technical safeguards protect research information stored, processed, accessed, or transmitted electronically.

Depending on applicable requirements, safeguards may include:

  • Authentication and access controls.
  • Multi-factor authentication.
  • Computing and storage resources appropriate for applicable requirements.
  • Encryption, when required.
  • Secure methods for transmitting or sharing information.
  • System and software updates.
  • Endpoint protection.
  • Logging or monitoring, when required.
  • Backup and recovery measures.
  • Network protections.
  • Specialized computing, storage, or technical environments, when required.

The appropriate technical environment depends on the information involved and the requirements applicable to the research project.

Researchers should review the Research Cybersecurity Baseline for cybersecurity practices supporting University research activities.

Researchers should not assume that a particular University storage, cloud, computing, or collaboration service is appropriate for all types of research information.


Research Computing & Storage

Research information should be stored, processed, and transmitted using University-supported resources appropriate for the information and applicable requirements.

Different research projects may require different computing, storage, or technical environments. Resources appropriate for ordinary research information may not satisfy requirements applicable to CUI, export-controlled information, sponsor- or contractually restricted information, information subject to Data Use Agreements or controlled-access requirements, or other information subject to specialized safeguarding requirements.

ORS assists researchers in identifying the research-specific information protection and cybersecurity requirements that apply. Research Computing & Informatics (RCI) and the Division of Information Technology (DoIT) provide University research computing, information technology, cybersecurity, information security, and related resources and services within their respective areas of responsibility.

ORS coordinates with RCI, DoIT, and other appropriate University offices when research activities require specialized safeguards or technical environments.

Researchers should consult available University computing and information technology resources when selecting systems, storage, or other technologies for research. Contact ORS before receiving, accessing, storing, or processing information subject to sponsor, contractual, government, export control, controlled-access, or other specialized safeguarding requirements if you are uncertain what requirements apply or whether a proposed resource is appropriate.

RESEARCH COMPUTING & INFORMATICS (RCI)
DIVISION OF INFORMATION TECHNOLOGY (DoIT)


Project-Specific Protection Requirements

Some research activities are subject to sponsor, contractual, regulatory, export control, data access, or other requirements that establish safeguards beyond the University's research cybersecurity and physical security baselines. When additional requirements apply, protections must be appropriate for the research activity and the information involved.

Depending on the project, additional requirements may include:

  • Restricted personnel access.
  • Specialized computing, storage, cybersecurity, or other technical environments.
  • Additional authentication or access controls.
  • Specific storage or transmission requirements.
  • Physical access or visitor controls.
  • Restrictions on portable devices or media.
  • Restrictions on international access or sharing.
  • Sponsor-required cybersecurity controls.
  • Technology Control Plans (TCPs).
  • Data Protection Plans.
  • Project-specific training or documentation requirements.
  • Other administrative, physical, or technical safeguards required by the applicable sponsor, contract, regulation, agreement, or data provider.

The specific safeguards required depend on the requirements applicable to the research activity.


How ORS Can Help

ORS assists researchers by:

  • Identifying research information protection requirements.
  • Reviewing sponsor, contractual, regulatory, export control, data access, and other applicable requirements.
  • Assessing whether baseline safeguards are sufficient based on applicable research-specific requirements and identifying when additional administrative, physical, or technical safeguards may be required.
  • Identifying when Data Protection Plans, Technology Control Plans, or other project-specific safeguards may be necessary.
  • Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, and other University offices, as appropriate, to support implementation of applicable requirements.
  • Providing guidance throughout the proposal, award, and research lifecycle.

Related Guidance 

Reference Guide Description
Research Information Classification Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, government, data access, and other requirements help determine the appropriate classification and protection of research information.
Sensitive Information Classification Policy Review the University-wide framework for classifying University Data and associated information protection requirements.
Research Data Ownership, Retention and Access Policy Research Data Ownership, Retention and Access Policy
Research Cybersecurity Baseline Review basic cybersecurity practices that support University research activities.
Research Physical Security Baseline Review basic physical security practices that support protection of research information, equipment, and research environments.

Need Assistance?

If you are uncertain what safeguards are required for research information or whether baseline safeguards are sufficient for your research activity, contact the Office of Research Security.

ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices when additional safeguards are required.

CONTACT ORS