In order to operate in a regulated world, researchers need to ensure compliance with ever-evolving landscape of information security regulations and best practices. This work explains the concept of Controlled Unclassified Information (CUI) and the challenges it brings to the research institutions. Survey from the user perceptions showed that most researchers and IT administrators lack a good understanding of CUI and how it is related to other regulations, such as HIPAA, ITAR, GLBA, and FERPA. A managed research ecosystem is introduced in this work. The workflow of this efficient and cost effective framework is elaborated to demonstrate how controlled research data are processed to be compliant with one of the highest level of cybersecurity in a campus environment. Issues beyond the framework itself is also discussed. The framework serves as a reference model for other institutions to support CUI research. The awareness and training program developed from this work will be shared with other institutions to build a bigger CUI ecosystem.
翻译:为了在受监管的世界中运作,研究人员需要确保遵守不断变化的信息安全条例和最佳做法,这项工作解释了控制下非机密信息的概念及其给研究机构带来的挑战,用户的看法调查表明,大多数研究人员和信息技术管理员对统一信息及其与HIPAA、ITAR、GLBA和FERPA等其他条例的关系缺乏很好的了解。在这项工作中引入了管理下的研究生态系统。这一高效和成本效益高的框架的工作流程旨在说明如何处理受控研究数据,使其符合校园环境中最高的网络安全水平之一。还讨论了框架之外的问题。框架作为其他机构支持统一信息股研究的参考模式。从这项工作中制定的意识和培训方案将与其他机构共享,以建立一个更大的统一信息股生态系统。