Cybersecurity for Research

Cybersecurity is a core component of research security and research compliance. Some sponsored projects, data use agreements, federal contracts, export-controlled activities, health data projects, and collaborations involving regulated information may require specific cybersecurity controls before research begins.

This page helps researchers identify when a cybersecurity review may be required and where to find additional guidance.

Important: Do not store, download, process, transmit, or share regulated research data until the appropriate SDSU computing environment and cybersecurity requirements have been reviewed.

When Cybersecurity Review May Be Required

Research sponsors, data providers, federal agencies, and collaborators increasingly require institutions to demonstrate that appropriate cybersecurity controls are in place before they can receive or use regulated research data. Cybersecurity requirements may need to be addressed:

  • During proposal development;
  • Before a data use agreement, contract, subcontract, or award is signed;
  • Before regulated data are received or accessed;
  • Before a research computing environment is approved for use, or
  • Before a PI, department, or university official submits a cybersecurity attestation.