Security Best Practices and Minimum Expectations
Introduction
The following guidelines outline the security baselines and minimum expectations for users of the Regulated Data (ReD) Environment. These standards are derived from the ReD Environment Rules of Behavior and HUIT's Information Security and Data Privacy guidelines. They represent essential practices to safeguard sensitive data and systems against unauthorized access, loss, and misuse. While this list is not exhaustive, it provides a foundational framework for maintaining compliance and upholding security within the ReD Environment. All users are encouraged to familiarize themselves with these baselines and adhere to them rigorously.
From the ReD Environment Rules of Behavior
- Safeguard Resources: Protect all resources against unauthorized access, waste, loss, abuse, and misappropriation.
- Authorized Access Only: Access only information you are authorized to view. Unauthorized access will result in regulatory action.
- Use Authorized Interfaces: Access regulated data solely through approved, secured workstations with updated security features.
- Report Security Incidents Immediately: Notify the system owner of any security incidents by emailing regulated_data_environment@harvard.edu.
- Secure Your Workstation: Lock or log out of your workstation if inactive for more than 15 minutes or before leaving your workspace.
- Intended Use Only: Use the ReD Environment exclusively for its intended purposes. Unapproved external connections are strictly prohibited.
- Data Transmission Restrictions: Do not move or transmit regulated data outside the approved environment without explicit authorization.
- Authorized Software Only: Install only approved software. Even if a misconfiguration permits unauthorized installations, it is prohibited by policy.
- Share Data Responsibly: Regulated data may only be shared with authorized personnel.
- Avoid Public Exposure: Never post regulated data on social media or public websites. Violations will result in regulatory action.
- Adhere to Security Policies: Do not circumvent established security measures. Promptly report any potential misconfigurations or vulnerabilities.
From HUIT Information Security and Data Privacy Guidelines
-
Awareness and Training: Stay informed about applicable policies and updates; participate in regular security training sessions to remain aware of best practices; there are annual training requirements to maintain access to the ReD Environment.
-
Data Management: Properly manage the lifecycle of regulated data, including secure storage, authorized sharing, and compliant disposal practices.
-
Access Control: Ensure proper access control over your workstation used to access the ReD Environment.
-
Security Practices: Use strong passwords that meet complexity requirements and avoid reuse across systems; keep systems and software up to date with the latest security patches; and leverage encryption for data both in transit and at rest, as applicable.
-
Incident Response: Promptly report any suspected or confirmed security incidents, breaches, or vulnerabilities by filing a ServiceNow ticket addressed to regulated_data_environment@harvard.edu.
By following these baselines, users contribute to a secure, compliant, and reliable research environment. For additional guidance or clarification, contact the ReD team at regulated_data_environment@harvard.edu.