Cybersecurity Cookbook
Cybersecurity Cookbook
Practical, everyday habits to protect research data, grouped by topic. Adopt what applies to your project; check data‑type guidance for anything regulated.
These are recommended practices, not a substitute for project‑specific requirements. If your data is governed by HIPAA, CUI, a DUA, or an IRB protocol, follow those requirements first, and reach out to Research IT if you’re unsure.
Recipes By Topic
- Use your own university account.
- Never share accounts, passwords, or credentials.
- Enable Multi-Factor Authentication (MFA) whenever available.
- Use Single Sign-On (SSO) or Active Directory (AD) authentication whenever possible.
- Grant access only to personnel with a legitimate project need.
- Review access periodically and remove users who no longer require it.
- Keep operating systems and applications up to date.
- Apply security patches promptly.
- Use university-managed devices whenever possible.
- Ensure antivirus or endpoint protection software is active.
- Lock devices when unattended.
- Encrypt laptops, desktops, and removable media used to store research data.
- Use approved encrypted methods to transmit sensitive information.
- Store research data only in approved locations.
- Use approved collaboration and file-sharing platforms.
- Verify recipients before sharing sensitive information.
- Do not use personal cloud storage services for sensitive research data unless specifically approved.
- Collect only the information necessary for the project.
- Use de-identified data whenever possible.
- Remove identifiers when no longer needed.
- Follow approved retention and disposal requirements.
Researchers are responsible for complying with applicable research security requirements.
- Complete required research security training.
- Complete required cybersecurity awareness training.
- Understand sponsor-specific research security requirements.
- Consult the Export Controls Office before sharing controlled information internationally.
- Review international collaboration requirements when working with foreign entities or institutions.
- Review foreign travel requirements before project-related international travel.
Report suspected or confirmed incidents immediately, including:
- Lost or stolen devices
- Unauthorized access
- Accidental disclosure
- Malware infections
- Phishing incidents
- Suspected compromise of research data
- Violations of sponsor security requirements
If something looks wrong, report it right away. Quick reporting limits the impact of an incident. When in doubt, submit a ticket or contact the IT Help Desk, it’s always better to ask.