-
Notifications
You must be signed in to change notification settings - Fork 15
Article on data access authorization and responsibility #897
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 9 commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
49419ae
first draft on data access authorization
bdu-birhanu a15fa53
reorder tables colmun and row
bdu-birhanu 8768c03
renamed to data resoonsibilities
bdu-birhanu a9313b8
added data archival and buckup section
bdu-birhanu 7a316df
added security exceptions content
bdu-birhanu 1a67af4
formatting the csv table
bdu-birhanu 25ad739
formatting tables and update buckup and it policies section
bdu-birhanu 0a688ec
added contents under security exception section
bdu-birhanu 89cf603
fix typo under security exception section
bdu-birhanu 36cd08c
Merge branch 'main' into feat-data-access
bdu-birhanu 0024bb0
addressing issues with content formatting and typos
bdu-birhanu 5b376ca
Merge branch 'main' into feat-data-access
bdu-birhanu 732bfca
including comments in csv table and data responsibility section
bdu-birhanu File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,78 @@ | ||
| # Data Access Authorization and Responsibility | ||
|
|
||
| Data access authorization and responsibility are critical aspect of managing and securing research data and resources. It ensures that only authorized individuals have access to specific data, maintaining security, compliance, and operational efficiency. | ||
|
wwarriner marked this conversation as resolved.
Outdated
|
||
|
|
||
| ## Shared Allocation | ||
|
|
||
| A shared allocation is owned by a PI of a Lab or director of core facility. It is designed for sharing research data among lab members, and collaborators where permissions and access control are typically managed by the PI/director or designated administrators/manager. | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
|
|
||
| PIs/Core directors and their Lab members are responsible for overseeing and managing the allocations, including granting access to specific folders. However, Research Computing may provide support in certain cases. For example, if a folder becomes "locked" (i.e., no group members can change its permissions or access it), the the owner of the allocation or the folder should submit a request for us to fix the issue. In addition, if you need assistance configuring or reconfiguring permissions, we can provide support as a convenience. Simply send us a request via <support@listserv.uab.edu>. | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
|
|
||
| {{ read_csv('data_management/res/cheaha_project_directory.csv', keep_default_na=False) }} | ||
|
|
||
| ## Individual Allocation | ||
|
|
||
| An individual allocations is intended for personal or individual use and is available to all UAB affiliated individuals or UAB employee's sponsored Collaborator. It is tied to the individual’s email and provide 5 TB of home/user directory on Cheaha and additional 5 TB of LTS allocation. | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
|
|
||
| {{ read_csv('data_management/res/cheaha_individual_account.csv', keep_default_na=False) }} | ||
|
|
||
| ## Data Archival and Backup Procedures | ||
|
|
||
| Proper data archival and backup practices ensure efficient storage utilization and data protection. IT is the responsibility of researchers and users of Cheaha to organize data, archive inactive files, and back up critical data. | ||
|
|
||
| ### Archival | ||
|
|
||
| <!-- markdownlint-disable MD046 --> | ||
| !!! important | ||
|
|
||
| Archival of data is the responsibility of researchers using Cheaha. | ||
| <!-- markdownlint-enable MD046 --> | ||
|
|
||
| At this time, Research Computing does not offer a method of archival. If you have need for archival, please feel free to contact [Support](../help/support.md) to start a conversation. | ||
|
|
||
| A possible external resource for archival is available through University of Oklahoma (OU) Supercomputing Center for Education and Research (OSCER). Please see the following link for details: <https://www.ou.edu/oscer/resources/ourrstore--ou---regional-research-store>. | ||
|
|
||
| ### Backups | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
|
|
||
| <!-- markdownlint-disable MD046 --> | ||
| !!! important | ||
|
|
||
| Backups of data are the responsibility of researchers using Cheaha. | ||
| <!-- markdownlint-enable MD046 --> | ||
|
|
||
| A good practice for backing up data is to use the 3-2-1 rule, as [recommended by US-CERT](https://www.cisa.gov/sites/default/files/publications/data_backup_options.pdf): | ||
|
|
||
| - **3**: Keep **3** copies of important data. 1 primary copy for use, 2 backup copies. | ||
| - **2**: Store backup copies on **2** different media types to protect from media-specific hazards. | ||
| - **1**: Store **1** backup copy offsite, located geographically distant from the primary copy. | ||
|
|
||
| What hazards can cause data loss? | ||
|
|
||
| - Accidental file deletion. | ||
| - Example: mistakenly deleting the wrong files when using the [shell command](../workflow_solutions/shell.md#delete-files-and-directories-rm-rmdir) `rm`. | ||
| - Files deleted with `rm` or any similar command can not be recovered by us under any circumstances. | ||
| - Natural disasters. | ||
| - Examples: tornado; hurricane. | ||
| - All of our data sits in one geographical location at the UAB Technology Innovation Center (TIC). | ||
| - Plans to add geographical data redundancy are being considered. | ||
| If you have backup needs, we can discuss options based on your use case. Please send us a support ticket via <support@listserv.uab.edu>. | ||
|
|
||
| ## Security Exceptions for Accessing Former UAB Personnel Data | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
|
|
||
| UAB IT has a process for granting access to data of former researchers or collaborators who are no longer with the institution. This process ensures compliance with regulatory protocols. | ||
|
|
||
| To request access to data of former UAB user, the first step is to fill out the [Third-Party Data Access form](https://uabprod.service-now.com/service_portal?id=sc_cat_item&sys_id=bd3721e2374c27c0daa253b543990e5d). In the “justification/description” field specify that you are requesting access to data for `<BlazerId>` on GPFS at the Research Computing System. Once submitted this form, a ticket is created and routed to the appropriate reviewers for authorization. | ||
|
|
||
| If the owner of the data was your student or staff in your lab, then the first choice is probably best (two-levels up supervisor). If the data owner was in a different department or special approval is required (for example a professor in the dept of medicine wanting access to data from a student in the school of engineering), select "Dean, C-level, or Trusted Designee" for the "Approval Type" field. If written approval can be provided directly by the former personnel, you can bypassed completing the form for request. | ||
|
|
||
| To simplify data access and management, it is recommended to store critical research data in shared storage areas that are accessible to or owned by the responsible PI, with ownership transfer initiated as needed. If you need help with data management processes, please send us a support ticket via <support@listserv.uab.edu>, and we will guide you through these steps. | ||
|
|
||
| ## User responsibilities with UAB-IT policies | ||
|
|
||
| All PIs, Core directors, researchers, students, users of UAB-owned computer systems, including Research Computing system, are responsible for adhering to the data and computing infrastructure policies set by UAB-IT. | ||
|
|
||
| - [Overall IT policy page](https://www.uab.edu/it/home/policies). | ||
| - [Acceptable Use Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=300). | ||
| - [Data Protection and Security Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=302). | ||
| - [Data Access Policy](https://secure4.compliancebridge.com/uab/portal/getdoc.php?file=301). | ||
| - [Data Classification](https://www.uab.edu/it/home/policies/data-classification/classification-overview). | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| Responsibilities,User, Storage Owner's Supervisor,Research Computing | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
| Sponsor external collaborator,Yes ✔️,Yes ✔️,Yes ✔️ | ||
| Create personal Cheaha account,Yes ✔️,, | ||
| Move unused data to LTS or archive,Yes ✔️,, | ||
| Manage backup plans,Yes ✔️,, | ||
| Data and access control,,[With Security Exception](#security-exceptions-for-accessing-former-uab-personnel-data), | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,16 @@ | ||
| Responsibilities,PI,Manager,Members,Research Computing | ||
| Move unused shared data to LTS/archive,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Manage backup and recovery,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Ensure proper usage of shared storage,Yes ✔️,Yes ✔️,Yes ✔️, | ||
| Add/remove member to/from the project space,Yes ✔️,Yes ✔️,,Upon PI/Manager request | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
| Hardware capital expenses,beyond default quota,,,up to default quota | ||
|
bdu-birhanu marked this conversation as resolved.
|
||
| Periodically check group membership,Yes ✔️,Yes ✔️,, | ||
| Grant access to users to a specific folder,Yes ✔️,Yes ✔️,, | ||
| Oversee and update access controls,Yes ✔️,Yes ✔️,, | ||
| "Data Management and Storage: <br> Administrative (authorization and access)",Yes ✔️,,, | ||
|
bdu-birhanu marked this conversation as resolved.
Outdated
|
||
| "Data Management and Storage: <br> Technical (encryption, firewall, etc.)" ,,,,Yes ✔️ | ||
| "Data Management and Storage: <br> Physical (locks, cameras, sign-ins, etc.)" ,,,,Yes ✔️ | ||
| Request a project directory,Yes ✔️,,, | ||
| Obtaining security exceptions when required,Yes ✔️,,, | ||
| Creating and maintaining metadata,Yes ✔️,,, | ||
| Creating a project directory,,,,Upon PI's request | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.