uabrc / uabrc/uabrc.github.io

Upcoming: RCS-wide security attestation

Open
#1,068 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

style: article/section 📝 style: news-item 📢 system: cheaha 🖧 system: cloud.rc ☁️ system: data-mgmt 🗃️ system: k8s 🐳 system: security 🔐 system: storage 🛢
Dominant language
Python
Stars
24
Forks
15
Avg merge
10d 3h
Merged PRs (30d)
1

Description

What would you like to see added?

Research Computing Systems (RCS) are aligned with HIPAA and NIST 800-171 requirements. We completed an external third part security review assessment to document our System Security Plan (SSP) and Plan of Action and Milestones (POAM) in place. With these in place, we can attest to compliance:

NIST 800-171:

NIH Grants and Projects Only: All RCS services are compliant with NIST 800-171. Computers and devices not part of RCS (personal computers, phones, laptops, servers, workstations, etc.) are NOT in scope and not compliant. Data Use Agreements (DUAs) with NIH must go through and be signed by the UAB Office of Sponsored Programs (OSP). Researchers should work with their assigned OSP department specialist. See the OSP DUA page and the OSP DUA checklist for more information.

ALL other purposes: We are self-attesting and have implemented a continuous improvement/continuous deployment security operation for Research Computing.

HIPAA:

We are self-attesting in collaboration with the UAB Internal Security Office (ISO) and with HSIS.

External third party audits were completed in 2019 and 2023. The next one is scheduled in 2027.

UAB is also developing a commercial cloud-based CMMC environment with a November 2026 rollout date.

When we have any of the attestations, we will need info and/or cross-links at the following:

  • Add a blurb on the news page
  • Announcement on the front page
  • (external) Article through IT Communications team
  • Update downloadable facilities document
  • Add to grants page
  • Add to index pages:
    • Cheaha
    • Cloud.rc
    • Kubernetes
    • Data Management
    • Long Term Storage
    • Cheaha Storage

OSP Links

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the news page, front page, downloadable facilities document, grants page, and the Cheaha, Cloud.rc, Kubernetes, Data Management, Long Term Storage, and Cheaha Storage index pages. Confirm the available attestation language and OSP links, then update the listed pages and coordinate the external IT Communications article. Done means all requested locations contain the approved information or cross-links.

Written by the indexing model from the issue text.

Assessment

Domain
content, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.