Restrictions and Regulations
Compliance Obligations and Associated Restrictions
The Regulated Data (ReD) Environment is designed to ensure compliance with a variety of policies, regulations, and contractual obligations. These obligations arise from three primary sources:
- Harvard University Policies
- Security Standards for Data Providers
- Ad Hoc Contractual Terms
This section provides a detailed overview of our compliance framework and the restrictions these obligations entail.
Please see Rules of Behavior for specific requirements for researchers.
Context
The many datasets used by researchers at Harvard originate from government sources. Over the past decade, significant legislative developments have focused on enhancing cybersecurity compliance, particularly for datasets containing Personally Identifiable Information (PII) or Protected Health Information (PHI). Beginning in 2020, federal and state data providers started embedding cybersecurity requirements in their data use agreements (DUAs), often mandating compliance with standards such as NIST SP 800-53 and NIST SP 800-171.
Federal agencies such as the Centers for Medicare & Medicaid Services (CMS) and the National Institutes of Health (NIH) have implemented consistent and rigorous security policies. At the same time, state-level legislation has introduced diverse but equally significant requirements. Additionally, Cybersecurity Maturity Model Certification (CMMC) compliance will become mandatory for Department of Defense (DoD) awarded grants starting in Q3 2025.
The Regulated Data (ReD) Environment serves as Harvard's centralized response to these evolving compliance requirements, offering a robust solution for managing regulatory adherence while enabling world-class research. By providing "compliance-as-a-service," the ReD Environment mitigates legal and financial risks while fostering innovation.
Harvard University Policies
Users of the Regulated Data Environment must adhere to several Harvard-specific policies, including:
- Harvard Research Data Security Policy
- Harvard Enterprise Information Security Policy
- Harvard Genomic Data Sharing Policy
- Harvard Research Data Ownership Policy
Familiarity with these policies is essential for researchers, data managers, and principal investigators (PIs) utilizing this system. Compliance is a shared responsibility, with the principal burden resting on the PI. Users are strongly encouraged to review these policies thoroughly using the provided links.
Security Standards for Data Providers
The Regulated Data Environment adheres to security standards required by data use agreements and funding terms. Key standards include:
- NIST SP 800-53: This standard outlines controls for managing access, configuration, supply chain security, and authorization boundaries. At the FISMA-moderate level, specific controls include:
- Role-based access control (RBAC) and multifactor authentication (MFA)
- Regular access reviews to ensure authorized access only
- Use of FIPS 140-2 validated encryption modules
- Implementation of CIS-hardened AMIs
- Restricted outbound internet access
- Continuous monitoring and external audits
-
Supply chain security procedures and clearly defined system boundaries
-
NIST SP 800-171: This framework focuses on protecting Controlled Unclassified Information (CUI). Key controls include:
- Encryption of data in transit and at rest using FIPS 140-2 compliant modules
- Logical data segmentation to maintain integrity and prevent unauthorized access
- Comprehensive logging of system activities with anomaly detection
- Advanced malware protection, including automated updates and regular scans
-
Incident response plans with documented and tested procedures
-
CMMC Level-2: The University is working toward compliance with CMMC Level-2, aiming for a first self-assessment or audit by October 2025. This certification will be required for specific DoD grants.
-
HDSL Level 4: The ReD Environment fully complies with HDSL Level 4 requirements, meeting Harvard's standards for handling sensitive and regulated data.
These controls ensure the secure handling of sensitive data while maintaining compliance with provider-specific agreements.
Ad Hoc Contractual Terms
In addition to established policies and standards, the Regulated Data Environment must comply with ad hoc contractual terms defined on a case-by-case basis. These terms vary depending on individual agreements and may impose additional security or procedural requirements for your research.
Support and Guidance
By adhering to these policies, standards, and terms, the Regulated Data Environment ensures a secure and compliant infrastructure that supports Harvard’s research community. For further guidance or questions about compliance obligations, please consult your data use agreement, research administration, or contact us at regulated_data_environment@harvard.edu.