Skip to main content

Research Cybersecurity

Our goal is to treat cybersecurity as a research enablement function, using risk-based controls, strong support services, and targeted enforcement to improve compliance without disrupting research.

Below, you can find more information on research cybersecurity at UA.

The University's Information Security Office has thoughtfully established cybersecurity policies that have not only been mapped to NIST 800-53 but play a significant role in protecting research data. Under the University's Information Resource Classification Standard, most UA research data is likely Internal Information that must be stored on University Information Systems that meet the minimum requirements defined by University policy unless it is made public. Information is public once published (peer-reviewed) or presented at a conference.

Research Investigators are encouraged to utilize UITS-managed systems for storing, processing, and transmitting research data whenever feasible. These services are accessible via the IT Service Portal.

In accordance with the University's Research Security Policy, Information Owners and Information System Owners (collectively, Information Resource Owner) of research data must, at a minimum:

  1. Complete the Information Security Annual Refresher Training in EDGE Learning at least annually and ensure all users complete this training annually. (ISO-500(A)(2)(a))
  2. Limit system access to authorized users. (ISO-300(B)(1)(b))
  3. Authenticate users before granting access to electronically stored data by using UA NetIDs. (ISO-300(A)(1)(a))
  4. Ensure remote access is only through approved methods (e.g., UA Virtual Private Network). (ISO-1200(B)(1)(c))
  5. Verify, control and/or limit connections to and use of external information systems. (ISO-1200(B)(1)(c))
  6. Ensure non-public information is not posted to or processed on publicly available systems. (ISO-300(B)(1)(h))
  7. Address system vulnerabilities and apply security patches in accordance with ISO-1600 Vulnerability and Patch Management Standard, as it is currently written or may be amended in the future. If a patch cannot be applied because it will interfere with functionality, develop and implement a compensation plan.
  8. Ensure third-party agreements require research data is deleted, destroyed, or returned to the University at the end of the agreement term. (ISO-1500(A)(1))
  9. Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. (ISO-1200(A)(1)(a))
  10. Principal Investigators and Co-Principal Investigators must submit attestation of compliance to the Research Security Program at least annually. These attestations can be maintained by ISO for those who utilize UITS-managed systems for storing, processing, and transmitting research data.
  11. Report Information Security Incidents to the Information Security Office in accordance with the Information Security Incident Reporting and Response Policy. (An Information Security Incident is “any irregular, adverse, or uncontrolled event that threatens the confidentiality, integrity, or availability of any University of Arizona information asset, system, network or storage media, or any violation or imminent threat of violation of any University of Arizona computer security policies, acceptable use policies, or standard security practices.” Unsuccessful security incidents (e.g., pings on a firewall, unsuccessful attempts to log onto a system with an invalid password or user name, unsuccessful attempts to load malware, denial-of-service attacks that do not result in a server being taken off-line) are foreseeable and expected, are not required to be reported, but may be reported if any uncertainty exists.)

 

For researchers who utilize non-UITS-managed systems, or who need assistance ensuring they meet the University's minimum research security requirements,, the Research Security Program and Information Security Office recommend completing the Research Cybersecurity Assurance Process through the Information Security Office.