University of Northern Colorado Data Security for Research Projects Policy
Purpose of Having a Data Research Policy Protection For human subjects For researchers For the institution
Purpose of Having a Data Research Policy Awareness and Education for Researchers This applies not only to the data they are handling for the research project, but carries over into their daily work activities and personal lives.
Purpose of Having a Data Research Policy Accountability Individuals involved in the grant writing/funding/research/reporting
Important Items to Document Specific means for identifying sensitivity of data Specific controls and safeguards for handling the data at each severity of sensitivity Specific individuals responsible for specific actionable items/tasks Identification of accountability and consequences for non-compliance
Important Items to Document Specific means for identifying sensitivity of data Specific controls and safeguards for handling the data at each severity of sensitivity Specific individuals responsible for specific actionable items/tasks Identification of accountability and consequences for non-compliance Signature of understanding and compliance with specifications
Our Experience So Far A need for a consistent, technical resource to sit on the IRB committee for consultation purposes Technical requirements are, “too technical,” for most non-IT staff, thus the same technical resource is required to assist in ensuring the technical controls are in place Historically, non-technical people would give their best stab at controls without reaching out for assistance Miscellaneous IT technicians were signing their names to legal forms in regards to these projects and controls holding themselves personally accountable for the security of the systems and data.
Questions?
Jessica Behunin jessica.behunin@unco.edu (970)351-1420
References