Purpose: To help faculty and researchers protect research data, grants, and intellectual property while maintaining flexibility in research methods using a risk-based approach aligned with NIST CSF.
Table of Content
Scope
This framework defines institutional security principles for research applications and data, aligned with NIST CSF. It does not prescribe specific technical implementations or resolve all research workflow challenges. Operational support models and consultation outcomes are documented separately to allow flexibility as research needs evolve.
Framework Overview
| NIST CSF Function | What It Means for Faculty & Researchers | Core Research Responsibility |
|---|---|---|
| IDENTIFY | Understand what data and risks exist | Know your research data type |
| PROTECT | Safeguard research data and systems | Use approved storage and access |
| DETECT | Spot suspicious activity early | Be alert to unusual behavior |
| RESPOND | Act quickly if something goes wrong | Report incidents immediately |
| RECOVER | Restore research and prevent repeat issues | Rely on IT recovery processes |
This framework is implemented through current Research IT support practices, which are described in faculty-facing guidance focused on consultation outcomes, limitations, and next steps.
IDENTIFY — Know Your Research Risk
NIST CSF Function: Identify (ID)
Faculty should understand what kind of data they are working with. Security requirements apply to the data and project—not the person.
Research Risk Tiers
| Tier | Data Type | Examples |
|---|---|---|
| Low Risk | Public / Open data | Publications, public datasets |
| Moderate Risk | Internal / Proprietary | Grant drafts, unpublished data |
| High Risk | Regulated / Restricted | Human subjects, CUI, HIPAA, FERPA |
Faculty Responsibility: Identify which tier your project falls into.
PROTECT — Safeguard Research Data
NIST CSF Function: Protect (PR)
Protection measures scale with risk and are supported by IT—not self-managed by faculty.
Core Protections
- Store data in approved university or research environments.
- Use access controls and MFA where required.
- Encrypt sensitive research data, with IT assistance.
- Avoid personal email or consumer cloud storage for restricted research.
Faculty Responsibility: Use approved tools; ask IT when unsure.
DETECT — Notice When Something Is Wrong
NIST CSF Function: Detect (DE)
Early detection protects research continuity and funding.
What to Watch For
- Unexpected system slowdowns or pop-ups.
- Unknown login alerts.
- Unusual file changes or access issues.
IT uses centralized monitoring for institution-managed systems; faculty act as human sensors.
- Trust your instincts—report anomalies.
RESPOND — Report Quickly, No Penalties
NIST CSF Function: Respond (RS)
Faculty are not expected to investigate or remediate incidents themselves.
If You Suspect an Incident
- Stop using the system if possible.
- Disconnect from the network, if safe.
- Report immediately to IT Security.
Early reporting protects grants, publications, and collaborators.
Faculty Responsibility: Report first—no negative consequences for good-faith reporting.
RECOVER — Restore Research & Improve
NIST CSF Function: Recover (RC)
IT leads recovery activities:
- System restoration.
- Data validation.
- Root-cause review.
- Prevention improvements.
Faculty focus on research continuity, not technical cleanup.
Faculty Responsibility: Work with IT to safely resume research.
One-Sentence Faculty Guidance
“Know your data, store it safely, control access, report concerns early—IT handles the rest.”