Researcher Cybersecurity Checklist
Researcher Cybersecurity Checklist
A short set of good habits to confirm before you start working with research data, and how to figure out what applies to your project.
The protections required for your project depend on the type of data and research activities involved. Research data may be subject to institutional policies, sponsor requirements, federal regulations, data use agreements (DUAs), export control regulations, IRB requirements, or other legal and contractual obligations. Use this checklist as a starting point, when in doubt, consult Research IT.
Before you begin, confirm the following
- I have classified the data according to institutional policy.
- I understand the sponsor, regulatory, contractual, IRB, DUA, and institutional requirements that apply to the project.
- I am using approved storage, computing, and collaboration tools.
- Multi-Factor Authentication (MFA) is enabled where available.
- Access is limited to authorized project personnel.
- My devices are encrypted, patched, and protected.
- Required research security and cybersecurity training has been completed.
- I understand any export control, international collaboration, or foreign travel requirements.
- I know how to report a cybersecurity incident.
- I understand any additional requirements for HIPAA, CUI, PII, IRB, or DUA-governed data.
Before you start
-
Classify your data
Before collecting, receiving, storing, or sharing research data, classify it according to institutional policy. Common categories include:
- Public Data
- Internal Data
- PII
- PHI / HIPAA
- CUI
- Export-Controlled
- Human Subjects (IRB)
- DUA-Governed
Unsure how to classify your data? Submit a ticket and we'll help.
-
Identify applicable requirements
Determine whether your project is subject to any of the following:
- Sponsor requirements
- Contractual obligations
- Data Use Agreements (DUAs)
- IRB requirements
- HIPAA requirements
- Export control requirements
- Federal cybersecurity requirements
- Institutional policies and standards
-
Use approved systems
Store, process, analyze, and share research data only through approved university systems and services. See Storage & Survey Tools and Compute & Servers for approved options, or the Cybersecurity Cookbook for everyday habits.
Different data types carry different obligations. Once you’ve classified your data, see Data‑Type Guidance for specific recommendations, and NIH Genomic Data if you work with controlled‑access genomic repositories.