-
Notifications
You must be signed in to change notification settings - Fork 15
Article on data access authorization and responsibility #897
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
49419ae
first draft on data access authorization
bdu-birhanu a15fa53
reorder tables colmun and row
bdu-birhanu 8768c03
renamed to data resoonsibilities
bdu-birhanu a9313b8
added data archival and buckup section
bdu-birhanu 7a316df
added security exceptions content
bdu-birhanu 1a67af4
formatting the csv table
bdu-birhanu 25ad739
formatting tables and update buckup and it policies section
bdu-birhanu 0a688ec
added contents under security exception section
bdu-birhanu 89cf603
fix typo under security exception section
bdu-birhanu 36cd08c
Merge branch 'main' into feat-data-access
bdu-birhanu 0024bb0
addressing issues with content formatting and typos
bdu-birhanu 5b376ca
Merge branch 'main' into feat-data-access
bdu-birhanu 732bfca
including comments in csv table and data responsibility section
bdu-birhanu File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| Responsibilities,User,Supervisor,Research Computing | ||
| Sponsor external collaborator,Yes ✔️,Yes ✔️,Yes ✔️ | ||
| Create personal Cheaha account,Yes ✔️,, | ||
| Move unused data to LTS or archive,Yes ✔️,, | ||
| Manage backup plans,Yes ✔️,, | ||
| "Data Security Control <br> Administrative (authorization and access)",Yes ✔️,[With Security Exception](#security-exceptions-for-accessing-former-uab-personnel-data), | ||
| "Data Security Controls: <br> Technical (encryption, firewall, etc.)" ,,,Yes ✔️ | ||
| "Data Security Controls: <br> Physical (locks, cameras, sign-ins, etc.)" ,,,Yes ✔️ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,17 @@ | ||
| Responsibilities,PI,Manager,Members,Research Computing | ||
| Move unused shared data to LTS/archive,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Manage backup and recovery,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Ensure proper usage of shared storage,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Add/remove member to/from the project space,Yes ✔️,Yes ✔️,,Must be approved by PI/Manager | ||
| Hardware capital expenses,beyond default quota,,,up to default quota | ||
| "Data center hosting expenses <br> (until end of vendor service contract)",,,,Yes ✔️ | ||
| Periodically check group membership,Yes ✔️,Yes ✔️,, | ||
| Grant access to users to a specific folder,Yes ✔️,Yes ✔️,, | ||
| Oversee and update access controls,Yes ✔️,Yes ✔️,, | ||
| "Data Security Controls: <br> Administrative (authorization and access)",Yes ✔️,,, | ||
| "Data Security Controls: <br> Technical (encryption, firewall, etc.)" ,,,,Yes ✔️ | ||
| "Data Security Controls: <br> Physical (locks, cameras, sign-ins, etc.)" ,,,,Yes ✔️ | ||
| Request a project directory,Yes ✔️,,, | ||
| Obtaining security exceptions when required,Yes ✔️,,, | ||
| Creating and maintaining metadata,Yes ✔️,,, | ||
| Creating a project directory,,,,Upon PI's request | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| # Research Data Responsibilities | ||
|
|
||
| Data access responsibilities are a critical part of managing and securing research data and resources. These responsibilities ensure only authorized individuals have access to specified data, and maintain security, compliance, and operational efficiency. | ||
|
|
||
| Data access responsibilities come from applicable laws and regulations, grant funding agency requirements, and UAB institutional policies. If you have questions, concerns, or wish to discuss, please [Contact Us](../help/support.md). | ||
|
|
||
| ## Shared Allocation | ||
|
|
||
| A shared allocation is owned by a PI of a Lab or director of Core facility. It is designed for sharing research data among staff, and collaborators where permissions and access control are typically managed by the PI/director or designated administrators/manager. | ||
|
|
||
| Shared storage owners, staff and students are responsible for overseeing and managing the allocations, including granting access to specific folders. However, Research Computing may provide support in certain cases. For example, if a folder becomes "locked" (i.e., no group members can change its permissions or access it), the owner of the allocation or the folder should submit a request for us to fix the issue. In addition, if you need assistance configuring or reconfiguring permissions, we can provide support as a convenience. Simply send us a request via <support@listserv.uab.edu>. | ||
|
|
||
| {{ read_csv('data_management/res/cheaha_project_directory.csv', keep_default_na=False) }} | ||
|
|
||
| ## Individual Allocation | ||
|
|
||
| Individual allocations are intended for personal or individual use and are available to all UAB affiliated individuals or UAB employee's sponsored Collaborator. It is tied to the individual’s email and provide 5 TB of home/user directory on Cheaha and additional 5 TB of LTS allocation. | ||
|
|
||
| {{ read_csv('data_management/res/cheaha_individual_account.csv', keep_default_na=False) }} | ||
|
|
||
| ## Data Archival and Backup Procedures | ||
|
|
||
| Researchers and users of Cheaha are responsible to organize data, archive inactive files, and back up critical data. For backup and archival solutions, please review our [Data Responsibilities and Procedures](./index.md#data-responsibilities-and-procedures) page. If you need backup and Archival assistance, we can discuss options based on your use cases. Please send us a support ticket via <support@listserv.uab.edu>. | ||
|
|
||
| ## Security Exceptions for Accessing Former UAB Personnel Data | ||
|
|
||
| UAB IT has a process for granting access to data of former researchers or collaborators who are no longer with the institution. This process ensures compliance with regulatory protocols. | ||
|
|
||
| To request access to data of former UAB user, the first step is to fill out the [Third-Party Data Access form](https://uabprod.service-now.com/service_portal?id=sc_cat_item&sys_id=bd3721e2374c27c0daa253b543990e5d). In the “justification/description” field specify that you are requesting access to data for `<BlazerId>` on GPFS at the Research Computing System. Once submitted this form, a ticket is created and routed to the appropriate reviewers for authorization. | ||
|
|
||
| If the owner of the data was your student or staff in your lab, then the first choice is probably best (two-levels up supervisor). If the data owner was in a different department or special approval is required (for example a professor in the dept of medicine wanting access to data from a student in the school of engineering), select "Dean, C-level, or Trusted Designee" for the "Approval Type" field. If written approval can be provided directly by the former personnel, you can bypassed completing the form for request. | ||
|
|
||
| To simplify data access and management, it is recommended to store critical research data in shared storage areas that are accessible to or owned by the responsible PI, with ownership transfer initiated as needed. If you need help with data management processes, please send us a support ticket via <support@listserv.uab.edu>, and we will guide you through these steps. | ||
|
|
||
| ## User responsibilities with UAB-IT policies | ||
|
|
||
| All PIs, Core directors, researchers, students, users of UAB-owned computer systems, including Research Computing system, are responsible for adhering to the data and computing infrastructure policies set by UAB-IT. | ||
|
|
||
| - [Overall IT policy page](https://www.uab.edu/it/home/policies). | ||
| - [Acceptable Use Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=300). | ||
| - [Data Protection and Security Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=302). | ||
| - [Data Access Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=301). | ||
| - [Data Classification](https://www.uab.edu/it/home/policies/data-classification/classification-overview). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.