Upcoming: RCS-wide security attestation
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 24
- Forks
- 15
- Avg merge
- 10d 3h
- Merged PRs (30d)
- 1
Description
What would you like to see added?
Research Computing Systems (RCS) are aligned with HIPAA and NIST 800-171 requirements. We completed an external third part security review assessment to document our System Security Plan (SSP) and Plan of Action and Milestones (POAM) in place. With these in place, we can attest to compliance:
NIST 800-171:
NIH Grants and Projects Only: All RCS services are compliant with NIST 800-171. Computers and devices not part of RCS (personal computers, phones, laptops, servers, workstations, etc.) are NOT in scope and not compliant. Data Use Agreements (DUAs) with NIH must go through and be signed by the UAB Office of Sponsored Programs (OSP). Researchers should work with their assigned OSP department specialist. See the OSP DUA page and the OSP DUA checklist for more information.
ALL other purposes: We are self-attesting and have implemented a continuous improvement/continuous deployment security operation for Research Computing.
HIPAA:
We are self-attesting in collaboration with the UAB Internal Security Office (ISO) and with HSIS.
External third party audits were completed in 2019 and 2023. The next one is scheduled in 2027.
UAB is also developing a commercial cloud-based CMMC environment with a November 2026 rollout date.
When we have any of the attestations, we will need info and/or cross-links at the following:
- Add a blurb on the news page
- Announcement on the front page
- (external) Article through IT Communications team
- Update downloadable facilities document
- Add to grants page
- Add to index pages:
- Cheaha
- Cloud.rc
- Kubernetes
- Data Management
- Long Term Storage
- Cheaha Storage
OSP Links
- Find your Specialist: https://www.uab.edu/research/home/osp-about/find-your-officer
- This is who researchers should contact with questions about DUAs.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the news page, front page, downloadable facilities document, grants page, and the Cheaha, Cloud.rc, Kubernetes, Data Management, Long Term Storage, and Cheaha Storage index pages. Confirm the available attestation language and OSP links, then update the listed pages and coordinate the external IT Communications article. Done means all requested locations contain the approved information or cross-links.
Written by the indexing model from the issue text.
Assessment
- Domain
- content, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100