Skip to content

Rules of Behavior for Internal Non-Privileged Users

NOTE: Every user should have signed this document as provided by ReD Team. This online copy is for you to easily refer back to

As an Internal Non-Privileged User, you have general user privileges to the Regulated Data (ReD) Environment and are required to minimally follow the security controls assigned to the ReD Environment, acting in this general capacity. The “Computer Systems Owner” of the ReD Environment is the University Research Computing Officer, who can select a designee within University Research Computing and Data services to provide explicit authorization as needed. Please contact the Computer Systems Owner with any issues: regulated_data_environment@harvard.edu

Additionally, when acting in this role:

  1. You must access regulated data information only through authorized interfaces. An authorized interface is defined as a workstation/laptop that: is current with operating system patching, has active anti-virus and anti-malware software installed and running, utilizes TLS 1.2 or higher encryption for network communications, has an activated firewall, and requires a strong password from users to log into.
  2. You must report all security incidents or suspected incidents (e.g., lost passwords, lost tokens, improper or suspicious acts) related to Regulated Data Environment components and networks to the Computer Systems Owner.
  3. Before you leave your workstation/laptop, you must lock your screen and/or you must log out (terminate your interactive session(s)) of the ReD Environment when inactivity is anticipated to exceed thirty (30) minutes and/or at the end of your normal work period.
  4. You must ensure that your use of the Regulated Data Environment is for the purposes for which it is intended, and you will not attempt to make external connections to services or applications unless such connections are explicitly approved by the Harvard University Research Computing System Owner.
  5. You must not move, migrate, export or otherwise transmit regulated data information from inside the ReD Environment to outside the ReD Environment without explicit authorization from the Computing System Owner.
  6. You must not install unapproved software onto this system. All software must be explicitly approved by the Computing System Owner.
  7. You must not share regulated data with someone who does not have authority to access that regulated data.
  8. You must not post any regulated data to social media platforms, social networking platforms, or external sites/applications (e.g. LinkedIn, Facebook, Twitter, Public Code Repositories such as GitHub) and websites classified as public.
  9. You must ensure that you will not circumvent the security policies set up within the ReD Environment. If you determine there might be a misconfiguration, you will inform the Computer Systems Owner immediately.
  10. In the event that regulated data is shipped via physical media or you are responsible for uploading regulated data to the Red Environment, you must ensure both electronic and hardcopy official records (e.g. hard disks) are stored and disposed of according to ReD Environment policies and standards.
  11. You must ensure that sensitive information processed and stored in ReD Environment and data transfer devices and components is restricted to team members via least privilege access and separation of duties. Any access controls not configured properly should be reported to the Computer Systems Owner.
  12. You must not add additional hardware or peripheral devices to this system. Only designated personnel can direct the installation of hardware and peripheral devices on this system.
  13. You must not remove computer resources (e.g., hard disks or USB drives) from a secure physical storage facility at Harvard University without prior approval.
  14. Reconfiguration of hardware, software, and firmware on any Regulated Data Environment components is forbidden, and you must report this as a finding to Computer Systems Owner if reconfiguration or manipulation is in any way possible.
  15. You must safeguard all resources for which you are responsible against waste, loss, abuse, unauthorized users, and misappropriation. Thus ensure the confidentiality, integrity, availability, and security of all system components commensurate with the Regulated Data Environment requirements for storing, processing, and transmitting all federal data.
  16. You must only access or obtain information from data sources for which you’ve been authorized. If you access or obtain information to which you are unauthorized and do so in a manner that breaches this Rules of Behavior or Harvard policies on computer use, you may be violating the Computer Fraud and Abuse Act