Researcher Cybersecurity Checklist

Researcher Cybersecurity Checklist

Researcher Cybersecurity Checklist

A short set of good habits to confirm before you start working with research data, and how to figure out what applies to your project.

Submit a Ticket


The protections required for your project depend on the type of data and research activities involved. Research data may be subject to institutional policies, sponsor requirements, federal regulations, data use agreements (DUAs), export control regulations, IRB requirements, or other legal and contractual obligations. Use this checklist as a starting point, when in doubt, consult Research IT.

Before you begin, confirm the following

  • I have classified the data according to institutional policy.
  • I understand the sponsor, regulatory, contractual, IRB, DUA, and institutional requirements that apply to the project.
  • I am using approved storage, computing, and collaboration tools.
  • Multi-Factor Authentication (MFA) is enabled where available.
  • Access is limited to authorized project personnel.
  • My devices are encrypted, patched, and protected.
  • Required research security and cybersecurity training has been completed.
  • I understand any export control, international collaboration, or foreign travel requirements.
  • I know how to report a cybersecurity incident.
  • I understand any additional requirements for HIPAA, CUI, PII, IRB, or DUA-governed data.

Before you start

  1. Classify your data

    Before collecting, receiving, storing, or sharing research data, classify it according to institutional policy. Common categories include:

    • Public Data
    • Internal Data
    • PII
    • PHI / HIPAA
    • CUI
    • Export-Controlled
    • Human Subjects (IRB)
    • DUA-Governed

    Unsure how to classify your data? Submit a ticket and we'll help.

  2. Identify applicable requirements

    Determine whether your project is subject to any of the following:

    • Sponsor requirements
    • Contractual obligations
    • Data Use Agreements (DUAs)
    • IRB requirements
    • HIPAA requirements
    • Export control requirements
    • Federal cybersecurity requirements
    • Institutional policies and standards
  3. Use approved systems

    Store, process, analyze, and share research data only through approved university systems and services. See Storage & Survey Tools and Compute & Servers for approved options, or the Cybersecurity Cookbook for everyday habits.