Secure My Research

Secure My Research

Consulting, tools, and guidance to help TC researchers protect data, meet compliance requirements, and build security into every stage of their research.

The TCIT Information Security team partners with faculty, staff, and student researchers to reduce cybersecurity burdens - so you can focus on what matters most: your research. Whether you are just arriving at TC, launching a new project, or supporting a research initiative as a student, we have resources tailored to your needs. Select your role below to get started.

📢 What's New: NSF now requires all principal investigators and senior/key personnel on federal awards to complete research security training before submitting new proposals, effective October 10, 2025. NSF also requires annual certification that covered individuals are not party to a Malign Foreign Talent Recruitment Program (MFTRP). Other federal agencies are expected to follow. Contact InfoSec or your Office of Sponsored Programs for guidance.
Welcome to TC - Let's Secure Your Research
Starting a new faculty position? The first few months are the right time to establish secure research practices. The TCIT Information Security team is here to help you set up compliantly from day one.
  1. Request a security consultation. Meet with the Information Security team to review your research data types, compliance obligations (FERPA, HIPAA, DOE, federal grant requirements), and recommended tools.
  2. Review data classification guidelines. Understand how TC classifies data (Public, Internal, Confidential, Restricted) so you can store and share research data appropriately.
  3. Check out our templates. The Information Security team has prepared templates for the most common research security needs, including data use agreements and data security plans.
  4. All devices used for research must be TC-managed, encrypted, and meet TCIT's data security standards. Contact the Service Desk for more information.
  5. Need to add an external collaborator or a recently graduated student to your project? This includes researchers from outside TC (including Barnard and Columbia). Submit the Affiliate Request Form to HR to get them a TC-specific account and access to the resources they need.
  6. See it all in one place. Check out the Researcher Pathway to see how these steps fit together - what to do, who to talk to, and in what order.
🔒

One-on-One Security Consultation

Schedule a private meeting with the Information Security team to discuss your specific research data and compliance needs.

Request a consultation →
🏛️

Grant & Sponsor Cybersecurity Requirements

Federal sponsors like NIH, NSF, and DoD increasingly include specific cybersecurity clauses in awards. We can help you interpret and fulfill those requirements before and after award.

Talk to InfoSec →
🎓

Security Awareness Training

Complete your required annual training and explore additional modules on phishing, secure data handling, and remote work security.

Access training →
💾

Applications Approved for Research

The Information Security team has conducted data security reviews on all applications listed here.

View Approved Applications →
🤖

AI Security for Research

Using AI tools in your research? Learn how to protect your data, choose approved tools, and meet compliance requirements when AI is part of your workflow.

View AI guidance →
🗄️

Research Data Storage Options

Not sure where to store your research data? See our guide to TC-approved storage platforms organized by data sensitivity level - including Google Drive, Dropbox, and secure file server options.

View storage options →
🏛️

Federal Research Security Training

If you hold or plan to apply for federal funding, research security training may be required. NSF now mandates training for all PIs and senior personnel on awards made on or after May 20, 2024. DOE has similar requirements.

Talk to InfoSec →
🤝

Adding External Collaborators or Research Affiliates

Need to give a collaborator from outside TC (including Barnard or Columbia) access to TC resources? Or does a recently graduated student still need access to finish their research? Submit the Affiliate Request Form to HR to get them set up.

Submit the Affiliate Request Form →
Schedule a security consultation Submit a support ticket
Starting a Research Project? Build Security In Early.
Grant proposals, data use agreements, and IRB protocols increasingly include cybersecurity requirements. Engaging the Information Security team early helps you meet those requirements and avoid costly changes later.
  1. Identify your data types and sensitivity. Will your project involve human subjects data, health information, federal data, or other regulated content? This determines your compliance obligations.
  2. Review grant or contract cybersecurity clauses. Many federal sponsors (NIH, NSF, DoD, DoE) include specific cybersecurity requirements. The Information Security team can help you interpret and fulfill these.
  3. Request a data security plan review. For IRB submissions and grant applications, we can review or co-develop the data security section of your protocol or proposal.
  4. Design a secure workflow. Before data collection begins, work with us to design storage, access control, sharing, and retention workflows that comply with your data use agreement or sponsor requirements.
  5. Document your compliance posture. We can help you generate documentation of the security controls in place - essential for audits, IRB renewals, and sponsor reporting.
📝

Data Security Plan Review

Submit your IRB protocol or grant data management plan for a confidential security review before submission.

Request a review →
⚖️

Compliance Guidance

Get help interpreting cybersecurity language in grants, contracts, and data use agreements - including HIPAA, FERPA, CUI, and FISMA requirements.

Ask a question →
🔐

Secure Workflow Design

Work with our team to design data collection, storage, sharing, and disposal processes that meet your regulatory and sponsor requirements.

Start a conversation →
📊

Applications Approved for Research

The Information Security team has conducted security reviews on all applications listed here, so you can focus on your research with confidence.

View Approved Applications →
🤖

AI Security for Research

Incorporating AI into your project? Our guidance covers approved tools, data handling requirements, and what to disclose in your IRB protocol when AI is involved.

View AI guidance →
🗄️

Research Data Storage Options

Not sure where to store your research data? See our guide to TC-approved storage platforms organized by data sensitivity level - including Google Drive, Dropbox, and secure file server options.

View storage options →
Contact the InfoSec team Submit a support ticket
Student Researcher Resources
Working on a faculty research project or your own dissertation data? Research data is often highly sensitive. These resources will help you understand your responsibilities and work securely.
  1. Understand what data you are working with. Talk with your faculty advisor about the sensitivity classification of your project's data and your specific access and handling obligations.
  2. Complete required training. If your project involves human subjects, you likely need CITI training through the IRB. You may also be required to complete TC's security awareness training for data security best practices.
  3. Use only approved tools and storage. Do not store research data on personal cloud services (Google Drive personal, Dropbox, etc.). Ask your advisor or the TCIT Service Desk about approved platforms.
  4. Protect your devices. All devices used for research must be TC-managed, encrypted, and meet TCIT's data security standards. Report lost or stolen devices to the Service Desk immediately.
  5. Know how to report an incident. If you suspect a data breach or security incident, contact the TCIT Service Desk right away.
🎓

Security Awareness Training

Access TC's required security awareness training and learn how to recognize phishing, handle data safely, and protect your accounts.

Access training →
💻

Applications Approved for Research

The Information Security team has conducted security reviews on all applications listed here.

View Approved Applications →
🌐

Working Remotely or in the Field?

Collecting data off-campus - whether at home, abroad, or in the field - introduces unique risks. Learn how to protect your data and devices when working outside the TC network.

Talk to InfoSec →
🛡️

Device Security Guidance

Learn how to encrypt your laptop, set up remote wipe, and configure secure settings on devices used for research.

Get device help →
Contact Information Security Submit a support ticket
External Collaborators & Research Affiliates
This comes up a lot. Whether you are an external researcher collaborating with TC faculty, a recently graduated student who lost access to TC resources, or a collaborator from a partner institution like Barnard or Columbia - you can get TC-specific access through the Affiliate Request Form. This applies even if you already have a Columbia UNI, since Barnard and Columbia accounts are not automatically in TC's domain.
  1. Recently graduated and lost access to TC Google Drive? If you are still working on a research project after graduation, your faculty sponsor can request continued access for you through the Affiliate Request Form. Default access is 4 months, with extensions up to 12 months available with InfoSec approval.
  2. External researcher or collaborator from another institution? This includes researchers from Barnard, Columbia, or any other outside organization. Even if you have a Columbia UNI, you are not automatically in TC's domain. Your TC faculty contact will need to submit the Affiliate Request Form to HR to get you a TC-specific account.
  3. Faculty: need to add an external team member? Either you or the collaborator can initiate the request. Submit the Affiliate Request Form to HR first - InfoSec will review and approve access after HR processes the request. Feel free to copy InfoSec on any communications with HR so we can help move things along.
  4. Once the form is submitted, your team member will be added to TC's system and provisioned with the access they need - including TC Google Workspace, lab server access, or other resources specified in the request.
  5. Before access is granted, the affiliate should sign a Research Confidentiality Agreement confirming they will handle TC research data according to TC's security policies.
📋

Affiliate Request Form

The starting point for all external collaborator and research affiliate access requests. Submitted to HR first - InfoSec provides final approval. Either the faculty sponsor or the affiliate can initiate.

Submit the Affiliate Request Form →
🗺️

Researcher Pathway

See the full step-by-step process for temporary research affiliates, including what happens after HR approves the request and what to plan for when the access period ends.

View the Researcher Pathway →
📄

Research Confidentiality Agreement

Affiliates who will access sensitive research data should sign this agreement before access is granted. Download the template from the Research Security Templates page.

Get the template →

Research Security FAQ

See the "Temporary Research Affiliates" section of the FAQ for answers to the most common affiliate access questions.

View the FAQ →
Submit the Affiliate Request Form Contact InfoSec
Other Research Security Questions
Not sure where to start? The Information Security team is happy to help with any research-related security or compliance question - regardless of your role. Reach out and we'll connect you with the right resource.
  1. Can you help me design a secure data workflow for my project?
  2. Can I use AI tools to analyze or process my research data?
  3. Can TC support the cybersecurity requirements in my contract or data sharing agreement?
  4. Can you review my proposal or IRB protocol for security compliance?
  5. Are there new data security regulations coming that may affect my research area?
  6. How do I report a potential data breach or security incident involving research data?
  7. I collaborate with researchers outside TC - how can we share data securely?
  8. A member of my research team is from outside TC (including Barnard or Columbia) - how do I get them access to TC resources?
  9. My student recently graduated but is still working on our research project and lost access to their TC Google Drive - what do we do?
📬

Email the InfoSec Team

Send your question directly to the TC Information Security team. We respond to all research security inquiries.

infosec@tc.columbia.edu →
🎫

Submit a Support Ticket

Open a ticket through ServiceNow for any IT or security-related request. Our team monitors all incoming tickets.

Open a ticket →
📞

Call the Service Desk

Reach the TCIT Service Desk by phone for urgent security concerns: 212-678-3300, Option 2.

Visit TCIT →

Research Security FAQ

Answers to the most common research security questions - covering data storage, IRB compliance, AI tools, incident reporting, and more.

View the FAQ →
🏛️

TCIT Home

Explore the full range of IT services, teams, and resources available at Teachers College.

Go to TCIT →
Get in touch Submit a support ticket
Back to skip to quick links