Secure Research Enclave (SeRE)
UNC Charlotte is committed to supporting faculty engaged in research involving Controlled Unclassified Information (CUI), Federal Controlled Information (FCI), sensitive data, and federally funded projects, including those under DoD and other federal agencies. To ensure compliance with NIST SP 800-171, CMMC, and NSPM-33 guidelines, UNC Charlotte has established Compliance Island — a secure virtual research enclave.
FAQ
Who can use Compliance Island?
Compliance Island is available to UNC Charlotte researchers and sponsored project personnel who require a compliant NIST 800-171, CMMC 1 & 2 computing environment and/or for federally regulated data (e.g., CUI, ITAR, DFARS projects). Access must be approved by both the ORPI and OneIT.
How do I request access or a new project space in Compliance Island?
Project Eligibility: The ORPI will assess whether your project qualifies to use Compliance Island based on the language and requirements outlined in the grant, contract, Data Use Certificate/Data Use Agreement (DUC/DUA), or other agreements as part of our onboarding process. This evaluation will also take into account the classification of the data level. ORPI may be notified of a project that requires Compliance Island through other departments within the Division of Research, such as Sponsored Research Administration or the Institutional Review Board (IRB), even if they are not contacted directly. Additionally, your college’s DSO can inform ORPI about these requirements as well.
User Eligibility: If your project qualifies, the PI and the research team will be subject to screenings, 3-year background checks for research security, and required to complete mandated information security training.
Upon completion, approved users and projects, along with DSP and TCP (if applicable), will gain access to Compliance Island.
Is there a cost associated with using Compliance Island?
Yes, Compliance Island is a pay-as-you-go cloud platform. The use of Compliance Island incurs a cost, and PI must collaborate with DSOs to plan and develop a budget. Cost includes:
- Virtual desktop licensing (Microsoft E5 – GCC High)
- Storage and compute usage
- Ongoing system support and maintenance is currently covered by the Division of Research
A detailed estimate will be provided during the onboarding process. For reference: Cost-planning template.
What kinds of data can be stored in Compliance Island?
Compliance Island can be used for:
- Other covered data
- Controlled Unclassified Information (CUI)
- Data subject to DFARS, ITAR, or CMMC regulations
- Research involving federal contracts with cybersecurity clauses
- Genomic Controlled Data from specific repositories
Limitations
- Please note that the application required to access Compliance Island is not compatible with Apple computers.
- Printing capabilities are currently not available.
- External storage devices (for example, USB flash drives and external hard drives) are prohibited.
- External hardware access (for example, equipment and devices) is not currently available.
- Data transmissions cannot be received without prior approval from Export Control/OneIT.
- Charlotte-hosted VoIP and Zoom conferencing cannot be used when sharing CUI.
- SeRE must be accessed from a Charlotte-owned and managed computer.
- Once data is transmitted to a third party (sponsor, subcontractor, vendor, etc.), the data is outside SeRE’s scope.
- Gmail and Google Shared Drive do not meet the security standards required for file sharing or other collaboration involving CUI.
Report Concerns about Research Security
If, after reviewing the information provided on this website or any other resource on research data security, and it is believed that a violation may have occurred, use the resources below:
EthicsPoint: Reports may be submitted via Charlotte’s secure third-party confidential reporting system by web and mobile devices or telephone. Reports may be submitted anonymously. Mobile & Web Report is available, or you may report by phone at (833) 223-7024
OR
You may email Saul Sotolongo or call (704) 687-1878, the Director of Research Security.