Research Computing, Incident Reporting & Resources
Cybersecurity approval is project-specific. Approval may depend on the data type, users, system architecture, access model, contract language, sponsor requirements, and data workflow.
A system, platform, or storage location should not be assumed to be approved for regulated research data unless it has been reviewed for the specific project and requirement.
Researchers should use SDSU-approved environments for regulated research data when required. Examples may include:
- Secure research computing environment;
- HIPAA-capable research environment;
- Approved NIH controlled-access data environment;
- Approved secure storage or file transfer service;
- Approved encryption or secure communication tool;
- Approved cloud or vendor platform, if authorized for the specific data and use case
Incident Reporting
Researchers must promptly report suspected or confirmed security incidents involving research data, systems, accounts, devices, or collaborators. Examples include:
- Lost or stolen devices containing research data;
- Accidental sharing with unauthorized individuals;
- Suspicious account access;
- Malware, ransomware, or compromised systems;
- Data sent to the wrong recipient;
- Unapproved storage or transfer of regulated data;
- Any notification from a sponsor, collaborator, or data provider of a possible security issue.
For projects with sponsors, federal, HIPAA, CUI, CMMC, NIH, DUA, or contract requirements, incident reporting timelines may be short and may require institutional coordination before external notification.
Additional Resources
- Research Cybersecurity Review Request
- SDSU Research Cybersecurity Services
- SDSU Secure Research Computing Environment
- SDSU NIH Controlled-Access Genomic Data / dbGaP Guidance
- SDSU HIPAA / ePHI Research Guidance
- SDSU CUI Policy
- SDSU Data Classification and Handling Guidance
- SDSU Information Security Policies and Standards
- SDSU Incident Reporting
- SDSU Export Control Guidance
- SDSU FERPA / Student Data Guidance
- CSU Information Security Policies and Standards
- CSU Data Classification / Data Protection Guidance
- Link to CSU / SDSU cybersecurity policies?
NIST and Federal Cybersecurity Frameworks
- NIST SP 800-171 Revision 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-171A Revision 3: Assessing Security Requirements for Controlled Unclassified Information
- NIST SP 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations
- NIST Cybersecurity Framework 2.0
- NIST Risk Management Framework / FISMA Background
- FedRAMP Program
CUI, CMMC, and DoD Contracting
- NARA Controlled Unclassified Information Program
- CUI Registry: Categories and Subcategories
- 32 CFR Part 2002: Controlled Unclassified Information
- DoD CMMC Resources and Documentation
- DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7020: NIST SP 800-171 DoD Assessment Requirements
NIH Controlled-Access Data
- NIH Requirements for Controlled-Access Data Repositories and Users
- NIH Security Best Practices for Users of Controlled-Access Data
Health, Student, Financial, and Export-Controlled Data
- HHS Summary of the HIPAA Security Rule
- NIST SP 800-66 Revision 2: Implementing the HIPAA Security Rule
- U.S. Department of Education FERPA Resources
- FTC Gramm-Leach-Bliley Act Overview
- U.S. Department of Education GLBA Cybersecurity Requirements for Institutions
- Bureau of Industry and Security: Export Administration Regulations
- Department of State / DDTC: ITAR Technical Data Definition
