Research Cybersecurity

Does my project need a cybersecurity review?

Some projects require review before SDSU can sign an agreement, accept an award, receive regulated data, or begin research activities.

Request a Cybersecurity Review Review Requirements & Terms

Before you receive regulated data
Do not receive, download, store, process, transmit, or share regulated research data until the project's requirements and computing environment have been reviewed.

Do I need a cybersecurity review?

Request a review when any of the following applies. When uncertain, submit the project for review rather than trying to interpret the requirement yourself.

Security language appears in project documents

A solicitation, contract, award, subcontract, grant, or data use agreement includes cybersecurity or data-security requirements.

The project uses regulated or sensitive data

Examples include controlled, health, genomic, student, government, export-controlled, or proprietary data.

You are asked to certify compliance

A sponsor requests a security questionnaire, attestation, certification, or system-security statement.

An external or unmanaged system will be used

This includes cloud services, vendors, collaborator systems, lab-managed servers, or personally owned devices.

Important: Institutional Review Required

Do not sign cybersecurity attestations or compliance statements on behalf of SDSU without institutional review. These statements may create legal, contractual, technical, financial, or reporting obligations.

Common terms that may trigger review

Researchers are not expected to interpret these requirements independently.

  • CUI or FCI
  • NIST SP 800-171
  • CMMC
  • DFARS or FAR
  • FedRAMP or FISMA
  • HIPAA or ePHI
  • NIH controlled-access data
  • Encryption or MFA
  • Audit logging
  • System Security Plan

Contact Research Security for help determining which requirements apply to your project.

When should I engage Research Cybersecurity?

Early coordination can prevent delays in proposal submission, award acceptance, contract execution, data access, and the start of research.

Engage early

  • During proposal development
  • Before SDSU signs an agreement or certification
  • Before regulated data are received or accessed

Return for review when something changes

  • New users or collaborators are added
  • A new system, vendor, or transfer method is proposed
  • The data, scope, or sponsor requirements change

Request a Research Cybersecurity Review

The Principal Investigator or an authorized project representative should submit a request as early as possible. Incomplete information should not prevent an early consultation.

Include what is currently available

  • Solicitation, contract, award, subcontract, or data use agreement
  • Security questionnaire, attestation, or certification
  • IRB, privacy, or controlled-access documentation
  • Description of the data, users, collaborators, systems, storage, and transfers
  • Expected project start or data-access date

Research Cybersecurity Review Request

  • A formal intake form will be added here. Until then, use the SDSU service portal to begin the review.

What happens after I submit?

1

Initial review

SDSU reviews the sponsor, agreement, data, and security requirements.

2

Project scoping

The data, users, collaborators, systems, and workflows are identified.

3

Environment determination

SDSU determines whether an existing approved environment can support the project.

4

Requirements and responsibilities

The PI receives applicable safeguards, documentation, costs, restrictions, and responsibilities.

5

Authorization before use

Regulated data may be received or accessed after applicable requirements and approvals are complete.

Secure Research Computing

SDSU maintains computing environments designed to support research with specific cybersecurity requirements.

NIST SP 800-171 Research Environment

SDSU has an environment designed to support certain projects subject to NIST SP 800-171 requirements. Approval remains project-specific. A platform approved for one project should not be assumed to be approved for another project or data type.

Planning Timeline

Some projects can use an existing approved service. Others may require technical configuration, documentation, procurement, legal review, or a new environment.

Review or project type Typical planning estimate
Initial review of complete documents 3–5 business days
Standard consultation using an existing approved SDSU service 1–3 weeks
NIH, HIPAA, or other regulated-data onboarding 2–6+ weeks
NIST SP 800-171 project using an existing approved SDSU environment 4–8+ weeks
New or highly specialized regulated environment Several months

Report a Research Security Incident

Immediately report suspected or confirmed loss, unauthorized access, accidental disclosure, compromised accounts, malware, or unapproved storage or transfer of research data. Regulated projects may have short reporting deadlines. Report the incident to SDSU immediately and do not independently notify external parties unless directed through the university's incident-response process.

Questions or unsure whether review is required?

Researchers do not need to determine which cybersecurity framework applies before requesting assistance.

Contact the Information Security Office