Data Categories
Common data sources and types are discussed below, including best practices and regulatory requirements for data protection specific to research contexts for UNC Charlotte. *Some excerpts of this page are from the National Archives
Federal Compliance Standards (FCI, CUI, CMMC, Classified)
This data, when identified by the federal government, is required to be protected to specific standards.
Federal Contract Information (FCI)
What is Federal Contract Information (FCI)?
Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as information necessary to process payments.
What are the federal regulations for FCI?
The Federal Acquisition Regulations (FAR) provide the standards for security controls for FCI. FAR clause 52.204-21 Basic Safeguarding of Covered Contractor Information Systems. There are fifteen (15) requirements included in this clause that provide for cyber and physical security for systems that store, use, or create FCI.
How may a researcher receive and / or create FCI?
If your contract is with a federal sponsor or a subaward with a federal sponsor prime, your agreement may contain the following clause in the terms and conditions: 52.204-21 Basic Safeguarding of Covered Contractor Information Systems. The presence of this clause signifies that FCI may be involved.
Controlled Unclassified Information (CUI)
What is Controlled Unclassified Information (CUI)?
Controlled Unclassified Information is described in Executive Order 13556 as information possessed by or created for the federal government that necessitates protection or dissemination restrictions in accordance with relevant laws, regulations, and government-wide policies, which is not classified under Executive Order 13526 or the amended Atomic Energy Act. Federal CUI is categorized into multiple categories and subcategories, which are documented in the CUI registry overseen by the National Archives and Records Administration (NARA).
CUI Basic
CUI Basic is the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls (32 CFR 2002)
CUI Specified
CUI Specified is the subset of CUI for which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic.
Protecting CUI
The baseline requirement for electronic protection of CUI in Non-federal systems, the category that Charlotte computer systems typically belong to, is the NIST Special Publication 800-171, Safeguarding Controlled Unclassified Information in Non-Federal Systems. Typically, Charlotte projects that include Controlled Unclassified Information (CUI) will utilize the Secure Research Enclave (SeRE).
What isn’t considered CUI?
- Proprietary research not funded by the federal government, even if it falls under US export control regulations, does not qualify as CUI. Projects containing controlled information that is not CUI can certainly be managed with the same protective standards, but should not be labeled as CUI.
- Controlled Research Data that is Non-contextualized – data produced from a project with CUI protection mandates remains controlled and must be managed following the appropriate TCP, yet it does not qualify as CUI. PIs and researchers ought to consult the appropriate TCP for protection needs.
- Data that is otherwise available to the public
What are the federal regulations for CUI?
- Code of Federal Regulations (CFR) Part 2002, Controlled Unclassified Information Program
- Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
- NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- DFARS 252.204-7021, Cybersecurity Maturity Model Certification (CMMC) Requirements
How could a researcher receive CUI?
A researcher may receive CUI from the federal government or a federal government prime contractor when conducting contract work for the federal government. However, it should not be accessed, used, etc. outside of the secure research enclave.
The Department of Defense has enacted specific guidelines for the protection of CUI. Other federal agencies are expected to follow the Department of War in adopting federal acquisition clauses specific to the protection of CUI.
Before project funds are released for a UNC Charlotte project that uses CUI, the Export Controls Office, in coordination with OneIT, will work with the PI to make sure that the relevant Technology Control Plan (TCP) satisfies all safeguarding requirements listed.
Note: When a document is encrypted for protection, the title of the document remains unencrypted. Consequently, always refrain from adding CUI information in the title of an electronic document.
CUI must be transmitted using a secure method. Every TCP containing CUI data will encompass guidance for secure transmission. For further information on transmission methods, please refer to the appropriate TCP.
Covered Defense Information (CDI)
What is CDI?
Covered Defense Information (CDI) is a term defined in DFARS Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, as unclassified controlled technical information, or other information, as described in the CUI registry that requires safeguarding or dissemination controls.
Are Charlotte’s systems compliant with the NIST 800-171, CMMC standards?
Charlotte’s entire network currently does not comply with this requirement. However, we do have a cloud service that is compliant. Any potential projects will need to be thoroughly reviewed, and additional costs may need to be included in the applications.
What does a researcher need to do if they want to apply for DoD contracts or subcontracts?
Applications for contracts and subcontracts and any agreements that contain (or could potentially contain) DFARS Clause 252.204-7012 require a detailed review by the ORS in close collaboration with the ORPI.
What storage is available for CUI data?
Charlotte’s cloud service (SeRE) is CMMC 1 & 2 and NIST 800-171 compliant and available. This Secure Enclave utilizes NIST 800-171 controls to meet the required FAR 52.204-21 and DFARS 252.204.71012 regulations.
Cybersecurity Maturity Model Certification (CMMC): This framework is primarily required for Department of Defense (DoD) funded research and verifies that appropriate cybersecurity standards are met to protect CUI and Federal Contract Information (FCI). Guidance and resources for handling Controlled Unclassified Information and meeting CMMC requirements for relevant DoD-funded projects are provided by the Charlotte ORPI in collaboration with OneIT.
What storage is available for CMMC data?
Charlotte’s cloud service (SeRE) is CMMC 1 & 2 and NIST 800-171 compliant and available. This Secure Enclave utilizes NIST 800-171 controls to meet the required FAR 52.204-21 and DFARS 252.204.71012 regulations.
Classified Information
What is Classified Information?
Classified national security information is information created or received by an agency of the federal government or a government contractor that would damage national security if improperly released. The President of the U.S. manages the system of classifying information by executive order (E.O.); the most recent order concerning classified national security information is E.O. 13526, signed by President Obama on December 29, 2009.
How is information determined to be classified?
Information can only be classified if an official determination is made that its unauthorized release would damage national security. Levels of classification correspond to levels of supposed damage. E.O. 13526 specifies that information whose release would cause “exceptionally grave damage to the national security” is classified TOP SECRET; information whose release would cause “serious damage” is classified SECRET; CONFIDENTIAL is the lowest category of classified information currently in use. RESTRICTED is an obsolete category that was discontinued in 1953.
Is all Classified Information in writing?
Classified information may take any form. Though paper documents are most common, there are classified photographs, maps, motion pictures, videotapes, databases, microfilms, hard drives, CDs, etc. Regardless of medium, classified information requires protection until it is formally declassified.
How could a researcher receive Classified Information?
A researcher may receive Classified Information from the federal government or a federal government prime contractor when conducting contract work for the federal government or when conducting work at a government or federal government prime contractor facility. Clearance (from the federal government) is required to receive classified information, E.O. 13526: Part 4 -Safeguarding.
Bringing Classified Information to Campus
Classified Information cannot be stored on campus IT systems. Classified Information requires a TCP to ensure compliance with federal regulations.
Export Controlled Data
What is Export Controlled Data?
Specific technical data, technology, software, and/or information that isn’t publicly available (or able to be published freely) and is prohibited from being exported from the United States to other countries or foreign individuals (even domestically) without explicit permission.
What are the applicable regulations for export-controlled data?
The following set of regulations is designed to protect national security, prevent the proliferation of weapons of mass destruction, safeguard U.S. intellectual property, and enforce economic and trade sanctions.
- International Traffic in Arms Regulations (ITAR)
- Export Administration Regulations (EAR)
- Department of Energy (DoE) Regulations
How could a researcher receive export-controlled data?
From Industry: Whenever a researcher is involved in any type of confidentiality agreement with industry (e.g., a Non-Disclosure Agreement), export-controlled information may be transferred to Charlotte. Depending on the industry of the industrial partner, the technical and proprietary information they might want to share with Charlotte researchers could be governed by export control regulations. The ORS collaborates closely with ORPI to determine which agreements might result in the transfer of such data to Charlotte and will assist affected researchers in ensuring proper safeguards.
From the Government: When performing CONTRACT work for the federal government, a researcher might obtain export-controlled data from either the federal government or a primary contractor of the federal government. Such information will almost certainly be designated or otherwise recognized as Controlled Unclassified Information (CUI).
What must a researcher do if they receive export-controlled data?
Contact ORPI as soon as you believe you may need to access such data. All export-controlled data to be received at Charlotte must be managed and safeguarded appropriately to ensure:
- It is not inadvertently disclosed to or accessed by non-authorized individuals who are not U.S. persons, and
- Any applicable cyber/IT security standards required by law, regulation, or contract can be adhered to institutionally
ORPI will work with you and other Charlotte stakeholders to implement a Technology Control Plan (TCP) to accomplish the above and remain compliant with applicable regulations.
Proprietary & Sensitive Non-Government Data
What is proprietary data?
Data that an organization, company, or individual owns and controls, which is not generally known or easily accessible to the public. This can be intellectual property, confidential business information, or other data that is not generally available to the public.
A common example is a company holding data that provides it with a competitive advantage. However, Charlotte may also possess proprietary research data, algorithms, software, and intellectual property in its research and development efforts.
What are the applicable regulations for proprietary data?
While there are federal and state laws and regulations that address cybersecurity requirements for protecting proprietary data, most of these relate to personally identifiable information.
Most organizations/companies adopt industry standards to protect their proprietary data.
How could a researcher receive proprietary data?
Whenever a researcher is a party to any kind of confidentiality agreement, they are likely to receive proprietary information (or data). Researchers may also receive proprietary data under a research agreement, such as collaborations, sponsored research, or testing.
What must a researcher do if they receive proprietary data?
Proprietary data received needs to be protected according to the standards stipulated in the agreement for the exchange of proprietary information.
Charlotte standards should be used in the absence of a formal written agreement and/or stipulated standards.
Human Subjects, PII, and Public Health Information (PHI)
Personally Identifiable Information (PII)
What is Personally Identifiable Information (PII)?
According to the National Institute of Standards and Technology (NIST), Personally Identifiable Information (PII) is defined as “any information about an individual maintained by an agency, including:
- any information that can be used to distinguish or trace an individual‘s identity, such as name, Social Security number, date and place of birth, mother‘s maiden name, or biometric records; and
- any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.”
What are the federal regulations for PII?
There is not one U.S. law that regulates personally identifiable information. Instead, some laws protect and/or regulate the use of PII. Notable PII regulations:
- Health Insurance Portability and Accountability Act (HIPAA) – regulates protected health information (PHI).
- Children’s Online Privacy Protection Act (COPPA) – regulates data collection from children 13 and younger.
- Gramm-Leach-Bliley Act (GLBA) – regulates how financial institutions handle customer data.
- Privacy Act of 1974 – regulates how US federal agencies handle personal information.
- Family Educational Rights and Privacy Act – regulates the privacy of student education records and the PII contained within them.
What does a researcher need to do if they want to create or use PII?
- Contact the ORPI – IRB to ensure that they have the appropriate human subjects approvals for their research.
- De-identify data wherever possible
Public Health Information
What is Public Health Information (PHI)?
According to the Health Insurance Portability and Accountability Act (HIPAA), protected health information (PHI) is any information that can be used to identify an individual, which personally relates to their past, present, or future health. PHI is generated as part of a healthcare related operation (treatment, testing, payment, insurance filing) covered under the Health Insurance Portability and Accountability Act (HIPAA).
PHI is a subset of Personally Identifiable Information (PII)
What are the federal regulations for PHI?
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule established national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity.
The Security Rule is located at 45 CFR Part 160 and Subparts A and C of Part 164
What does a researcher need to do if they want to create or use PHI?
Researchers who want to create or use PHI should:
- Contact the ORPI – IRB to ensure that they have the appropriate human subjects approvals for their research.
- De-identify data wherever possible
Personal Data and International Laws
What is Personal Data?
Many countries have laws that are similar to the European Union’s General Data Protection Regulation (GDPR). International personal data is personal data that is transferred or accessed across international borders.
GDPR definition of personal data
Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
What are the international laws for personal data?
Personal data regulations (also known as privacy and data protection laws) are country-specific. More than 160 countries have enacted laws governing the protection of personal data.
These laws provide requirements for:
- Privacy: how to use and share data for legitimate research and other purposes, while protecting personally identifiable information; and
- Security: how to secure personal data to prevent unintentional disclosures, access by unauthorized persons, or improper use by unauthorized persons.
How could a researcher receive and / or create data subject to international laws?
Data collected, recorded, stored, and/or used by researchers may be regulated by international data protection laws.
Examples of data that may be subject to international laws:
- Data repositories, such as the UK Biobank
- Research project with data collection in an international location
- Research project with data collection in the U.S. using surveys distributed internationally
What does a researcher need to do if they want to collect personal data from international participants?
A researcher must notify Export Control if they plan to collect, record, store, and/or use data from international participants. The application allows the ORPI and other administrative areas to review the application and implement required rights and security measures.
NIH Controlled-Access Data
What is the NIH Controlled-Access Data Subject to the NIH Genomic Data Sharing (GDS) Policy?
A list of these Repositories can be found here. NIH will update the list as needed.
What are the security requirements for using these data sets?
All users in possession of NIH controlled-access data must protect this data in accordance with National Institute of Standards and Technology (NIST) SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”.
Are Charlotte systems compliant with NIST 800-171?
Charlotte’s physical network is not compliant with NIST 800-171. However, we have a cloud service that is.
What is Charlotte doing to meet this requirement?
Charlotte has contracted with a third party provider to offer researchers a secure research enclave to store, analyze, and access NIH-controlled-access data. There may be additional costs associated with its use.
What should I do if I want to access NIH-controlled-access data?
Contact ORPI – Research Data Compliance to complete an intake form to discuss how to best manage the controlled-access data you will be using. A collaborative effort between ORPI and OneIT will verify with ORS that data will be in an environment that meets the NIST 800-171 requirements before signing your data use agreement.