Review Process
Do I need a cybersecurity review?
A cybersecurity review may be required if your project involves any of the following:
- Sponsor, contract, grant, RFP, subcontract, or DUA language requiring NIST SP Sponsor, contract, grant, RFP, subcontract, or data use agreement language requiring NIST SP 800-171, CMMC, NIST SP 800-53, FedRAMP, FISMA, FIPS, encryption, audit logging, multifactor authentication, incident reporting, access restrictions, or a written security plan.
- Controlled Unclassified Information (CUI), Covered Defense Information, Federal Contract Information (FCI), or other federally controlled data.
- NIH controlled-access data, including dbGaP or other NIH Controlled-Access Data Repositories.
- Identifiable health information, electronic protected health information, HIPAA-related data, or health-system data.
- Export-controlled technical data, ITAR/EAR concerns, foreign national access restrictions, publication restrictions, or sponsor-imposed access limitations.
- Sensitive human subjects data, student education records, government data, proprietary sponsor data, or large regulated datasets.
- Use of non-SDSU cloud services, external collaborators’ systems, lab-managed servers, personally owned devices, third-party platforms, or vendor-hosted environments.
- Any request for a PI, department, college, or university official to sign a cybersecurity attestation, data security certification, system security representation, or compliance statement.
What should I do next?
If your proposal, award, contract, data use agreement, or data access request includes cybersecurity requirements, submit a Research Cybersecurity Review Request as early as possible.
Before submitting the request, gather any available documents, including:
- Sponsor solicitation, RFP, grant terms, or award notice;
- Contract, subcontract, data use agreement, or data security addendum;
- NIH Data Use Certification or controlled-access data request;
- Security questionnaire, attestation, or compliance certification;
- IRB protocol or privacy documentation, if applicable;
- Description of the data, users, collaborators, systems, storage, computing, and transfer methods.
Do not sign cybersecurity attestations or compliance statements on behalf of SDSU without institutional review. These statements may create university obligations and may require review by Sponsored Research Administration, Information Security, Legal/Contracts, Privacy, Export Control, or other offices.
What Happens After I Submit a Request?
The team reviews sponsor language, contract terms, data use agreements, data access requirements, and applicable laws or frameworks.
The team determines whether the project involves regulated, restricted, confidential, controlled, health, student, export-controlled, proprietary, or otherwise sensitive data.
The review considers where data will be stored, processed, analyzed, transmitted, shared, backed up, and destroyed.
Some projects may be supported by an existing secure research computing environment. Others may require additional planning, configuration, documentation, procurement, or risk review.
Depending on the project, documentation may include a risk assessment, a System Security Plan, a Plan of Action and Milestones, a data flow diagram, an access control plan, or a sponsor-specific security response.
Regulated data should not be received or used until the required environment, access controls, agreements, and approvals are in place.
Compliance Process and Timeline
Projects that require cybersecurity compliance often need additional planning and coordination before research can begin. Depending on the sponsor's requirements, the university may need to establish a secure computing environment, conduct a risk assessment, develop a System Security Plan (SSP), implement required security controls, and document compliance before it can receive or access regulated data.
This process is a collaborative effort involving the Principal Investigator, Research Cyberinfrastructure, Information Security Office, Sponsored Research Administration, and other campus partners as appropriate. The time required depends on the project’s complexity, the sensitivity of the data, and whether an approved secure research environment already exists.
Researchers are strongly encouraged to engage the IT Security Office during proposal development or immediately after learning that cybersecurity requirements apply. Beginning this process early helps ensure that security requirements are identified, documentation is completed, technical controls are implemented, and any required approvals are obtained before the project start date.
While some projects can be accommodated using existing compliant research environments, others may require several weeks—or, in more complex cases, several months—to design, implement, validate, and document the required safeguards. Early planning helps avoid delays in award acceptance, contract execution, and the start of research activities.
An example timeline is listed below:
| Scenario | Typical timing | Notes |
| Initial triage of sponsor/DUA/security language | 3–5 business days | Requires complete documents. |
| Standard research cybersecurity consultation | 1–3 weeks | For known data types and approved SDSU services. |
| NIH controlled-access data onboarding | 2–6+ weeks | Depends on the repository, agreement, environment, and users. |
| HIPAA/ePHI research environment review | 2–6+ weeks | Depends on IRB, privacy, DUA, and storage/compute design. |
| CUI/NIST SP 800-171 project using existing approved environment | 4–8+ weeks | Requires scoping, SSP/control inheritance, and access model. |
| New CUI/CMMC/FedRAMP/FISMA-like environment | Several months | May require architecture, procurement, vendor review, POA&M, legal review, and cost approval. |
