Faculty & Research Cybersecurity Framework (Aligned to NIST CSF)

Purpose: To help faculty and researchers protect research data, grants, and intellectual property while maintaining flexibility in research methods using a risk-based approach aligned with NIST CSF.

Table of Content

Scope

This framework defines institutional security principles for research applications and data, aligned with NIST CSF. It does not prescribe specific technical implementations or resolve all research workflow challenges. Operational support models and consultation outcomes are documented separately to allow flexibility as research needs evolve.

Framework Overview

NIST CSF Function What It Means for Faculty & Researchers Core Research Responsibility
IDENTIFY Understand what data and risks exist Know your research data type
PROTECT Safeguard research data and systems Use approved storage and access
DETECT Spot suspicious activity early Be alert to unusual behavior
RESPOND Act quickly if something goes wrong Report incidents immediately
RECOVER Restore research and prevent repeat issues Rely on IT recovery processes

This framework is implemented through current Research IT support practices, which are described in faculty-facing guidance focused on consultation outcomes, limitations, and next steps.

IDENTIFY — Know Your Research Risk

Faculty should understand what kind of data they are working with. Security requirements apply to the data and project—not the person.

Research Risk Tiers

Tier Data Type Examples
Low Risk Public / Open data Publications, public datasets
Moderate Risk Internal / Proprietary Grant drafts, unpublished data
High Risk Regulated / Restricted Human subjects, CUI, HIPAA, FERPA

Faculty Responsibility: Identify which tier your project falls into.

PROTECT — Safeguard Research Data

Protection measures scale with risk and are supported by IT—not self-managed by faculty.

Core Protections

    • Store data in approved university or research environments.
    • Use access controls and MFA where required.
    • Encrypt sensitive research data, with IT assistance.
    • Avoid personal email or consumer cloud storage for restricted research.

Faculty Responsibility: Use approved tools; ask IT when unsure.

DETECT — Notice When Something Is Wrong

Early detection protects research continuity and funding.

What to Watch For

    • Unexpected system slowdowns or pop-ups.
    • Unknown login alerts.
    • Unusual file changes or access issues.

IT uses centralized monitoring for institution-managed systems; faculty act as human sensors.

    • Trust your instincts—report anomalies.

RESPOND — Report Quickly, No Penalties

Faculty are not expected to investigate or remediate incidents themselves.

If You Suspect an Incident

    1. Stop using the system if possible.
    2. Disconnect from the network, if safe.
    3. Report immediately to IT Security.

Early reporting protects grants, publications, and collaborators.

Faculty Responsibility: Report first—no negative consequences for good-faith reporting.

RECOVER — Restore Research & Improve

IT leads recovery activities:

    • System restoration.
    • Data validation.
    • Root-cause review.
    • Prevention improvements.

Faculty focus on research continuity, not technical cleanup.

Faculty Responsibility: Work with IT to safely resume research.

Shared Responsibility Model

This framework is intentionally collaborative, not enforcement-driven.

Role Responsibility
Faculty & Researchers Research decisions, awareness, reporting
IT Security Controls, monitoring, response, recovery
Research Compliance Sponsor and regulatory alignment

Certain research workflows inherently challenge standard security controls, including highly customized development environments or instrument-integrated systems. In these cases, compensating controls, alternative approaches, or leadership review may be required. These scenarios are evaluated collaboratively and may involve external expertise.

One-Sentence Faculty Guidance

“Know your data, store it safely, control access, report concerns early—IT handles the rest.”

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.