Secure My Research
Consulting, tools, and guidance to help TC researchers protect data, meet compliance requirements, and build security into every stage of their research.
The TCIT Information Security team partners with faculty, staff, and student researchers to reduce cybersecurity burdens - so you can focus on what matters most: your research. Whether you are just arriving at TC, launching a new project, or supporting a research initiative as a student, we have resources tailored to your needs. Select your role below to get started.
- Request a security consultation. Meet with the Information Security team to review your research data types, compliance obligations (FERPA, HIPAA, DOE, federal grant requirements), and recommended tools.
- Review data classification guidelines. Understand how TC classifies data (Public, Internal, Confidential, Restricted) so you can store and share research data appropriately.
- Check out our templates. The Information Security team has prepared templates for the most common research security needs, including data use agreements and data security plans.
- All devices used for research must be TC-managed, encrypted, and meet TCIT's data security standards. Contact the Service Desk for more information.
- Need to add an external collaborator or a recently graduated student to your project? This includes researchers from outside TC (including Barnard and Columbia). Submit the Affiliate Request Form to HR to get them a TC-specific account and access to the resources they need.
- See it all in one place. Check out the Researcher Pathway to see how these steps fit together - what to do, who to talk to, and in what order.
One-on-One Security Consultation
Schedule a private meeting with the Information Security team to discuss your specific research data and compliance needs.
Request a consultation →Grant & Sponsor Cybersecurity Requirements
Federal sponsors like NIH, NSF, and DoD increasingly include specific cybersecurity clauses in awards. We can help you interpret and fulfill those requirements before and after award.
Talk to InfoSec →Security Awareness Training
Complete your required annual training and explore additional modules on phishing, secure data handling, and remote work security.
Access training →Applications Approved for Research
The Information Security team has conducted data security reviews on all applications listed here.
View Approved Applications →AI Security for Research
Using AI tools in your research? Learn how to protect your data, choose approved tools, and meet compliance requirements when AI is part of your workflow.
View AI guidance →Research Data Storage Options
Not sure where to store your research data? See our guide to TC-approved storage platforms organized by data sensitivity level - including Google Drive, Dropbox, and secure file server options.
View storage options →Federal Research Security Training
If you hold or plan to apply for federal funding, research security training may be required. NSF now mandates training for all PIs and senior personnel on awards made on or after May 20, 2024. DOE has similar requirements.
Talk to InfoSec →Adding External Collaborators or Research Affiliates
Need to give a collaborator from outside TC (including Barnard or Columbia) access to TC resources? Or does a recently graduated student still need access to finish their research? Submit the Affiliate Request Form to HR to get them set up.
Submit the Affiliate Request Form →- Identify your data types and sensitivity. Will your project involve human subjects data, health information, federal data, or other regulated content? This determines your compliance obligations.
- Review grant or contract cybersecurity clauses. Many federal sponsors (NIH, NSF, DoD, DoE) include specific cybersecurity requirements. The Information Security team can help you interpret and fulfill these.
- Request a data security plan review. For IRB submissions and grant applications, we can review or co-develop the data security section of your protocol or proposal.
- Design a secure workflow. Before data collection begins, work with us to design storage, access control, sharing, and retention workflows that comply with your data use agreement or sponsor requirements.
- Document your compliance posture. We can help you generate documentation of the security controls in place - essential for audits, IRB renewals, and sponsor reporting.
Data Security Plan Review
Submit your IRB protocol or grant data management plan for a confidential security review before submission.
Request a review →Compliance Guidance
Get help interpreting cybersecurity language in grants, contracts, and data use agreements - including HIPAA, FERPA, CUI, and FISMA requirements.
Ask a question →Secure Workflow Design
Work with our team to design data collection, storage, sharing, and disposal processes that meet your regulatory and sponsor requirements.
Start a conversation →Applications Approved for Research
The Information Security team has conducted security reviews on all applications listed here, so you can focus on your research with confidence.
View Approved Applications →AI Security for Research
Incorporating AI into your project? Our guidance covers approved tools, data handling requirements, and what to disclose in your IRB protocol when AI is involved.
View AI guidance →Research Data Storage Options
Not sure where to store your research data? See our guide to TC-approved storage platforms organized by data sensitivity level - including Google Drive, Dropbox, and secure file server options.
View storage options →- Understand what data you are working with. Talk with your faculty advisor about the sensitivity classification of your project's data and your specific access and handling obligations.
- Complete required training. If your project involves human subjects, you likely need CITI training through the IRB. You may also be required to complete TC's security awareness training for data security best practices.
- Use only approved tools and storage. Do not store research data on personal cloud services (Google Drive personal, Dropbox, etc.). Ask your advisor or the TCIT Service Desk about approved platforms.
- Protect your devices. All devices used for research must be TC-managed, encrypted, and meet TCIT's data security standards. Report lost or stolen devices to the Service Desk immediately.
- Know how to report an incident. If you suspect a data breach or security incident, contact the TCIT Service Desk right away.
Security Awareness Training
Access TC's required security awareness training and learn how to recognize phishing, handle data safely, and protect your accounts.
Access training →Applications Approved for Research
The Information Security team has conducted security reviews on all applications listed here.
View Approved Applications →Working Remotely or in the Field?
Collecting data off-campus - whether at home, abroad, or in the field - introduces unique risks. Learn how to protect your data and devices when working outside the TC network.
Talk to InfoSec →Device Security Guidance
Learn how to encrypt your laptop, set up remote wipe, and configure secure settings on devices used for research.
Get device help →- Recently graduated and lost access to TC Google Drive? If you are still working on a research project after graduation, your faculty sponsor can request continued access for you through the Affiliate Request Form. Default access is 4 months, with extensions up to 12 months available with InfoSec approval.
- External researcher or collaborator from another institution? This includes researchers from Barnard, Columbia, or any other outside organization. Even if you have a Columbia UNI, you are not automatically in TC's domain. Your TC faculty contact will need to submit the Affiliate Request Form to HR to get you a TC-specific account.
- Faculty: need to add an external team member? Either you or the collaborator can initiate the request. Submit the Affiliate Request Form to HR first - InfoSec will review and approve access after HR processes the request. Feel free to copy InfoSec on any communications with HR so we can help move things along.
- Once the form is submitted, your team member will be added to TC's system and provisioned with the access they need - including TC Google Workspace, lab server access, or other resources specified in the request.
- Before access is granted, the affiliate should sign a Research Confidentiality Agreement confirming they will handle TC research data according to TC's security policies.
Affiliate Request Form
The starting point for all external collaborator and research affiliate access requests. Submitted to HR first - InfoSec provides final approval. Either the faculty sponsor or the affiliate can initiate.
Submit the Affiliate Request Form →Researcher Pathway
See the full step-by-step process for temporary research affiliates, including what happens after HR approves the request and what to plan for when the access period ends.
View the Researcher Pathway →Research Confidentiality Agreement
Affiliates who will access sensitive research data should sign this agreement before access is granted. Download the template from the Research Security Templates page.
Get the template →Research Security FAQ
See the "Temporary Research Affiliates" section of the FAQ for answers to the most common affiliate access questions.
View the FAQ →- Can you help me design a secure data workflow for my project?
- Can I use AI tools to analyze or process my research data?
- Can TC support the cybersecurity requirements in my contract or data sharing agreement?
- Can you review my proposal or IRB protocol for security compliance?
- Are there new data security regulations coming that may affect my research area?
- How do I report a potential data breach or security incident involving research data?
- I collaborate with researchers outside TC - how can we share data securely?
- A member of my research team is from outside TC (including Barnard or Columbia) - how do I get them access to TC resources?
- My student recently graduated but is still working on our research project and lost access to their TC Google Drive - what do we do?
Email the InfoSec Team
Send your question directly to the TC Information Security team. We respond to all research security inquiries.
infosec@tc.columbia.edu →Submit a Support Ticket
Open a ticket through ServiceNow for any IT or security-related request. Our team monitors all incoming tickets.
Open a ticket →Call the Service Desk
Reach the TCIT Service Desk by phone for urgent security concerns: 212-678-3300, Option 2.
Visit TCIT →Research Security FAQ
Answers to the most common research security questions - covering data storage, IRB compliance, AI tools, incident reporting, and more.
View the FAQ →TCIT Home
Explore the full range of IT services, teams, and resources available at Teachers College.
Go to TCIT →Questions? We're here to help.
TCIT Service Desk · 212-678-3300 · servicedesk@tc.columbia.edu