Information security

It is vital that everyone on our team understands the principles of information security and how to keep our data safe. Everyone should, for any new project or new data get access to, quickly think about what type of data it is and how it needs to be protected.

The term “confidential” refers to data that has some specific legal requirement to be protected (think things like personal data or data under contractual non-disclosure agreement). For this type of data, you must only use systems which are properly approved, since there must be a proper chain of control all the way.

Unfortunately, as in many places, these information security policies are not well adapted to the realities of research. Research and in general most of what our team does have many more types of data than can be represented in four simple categories. We, and researchers in general, can’t efficiently function based only on this. When you see something that doesn’t work, don’t act alone but bring it to your supervisor for advice. If we need to adjust things to reality, that should be done collectively at a team meeting.

One of our team’s values is “radical openness”. We still have to protect our data, and this means making sure to separate out what needs to be confidential from what can be opened early, when it is created.

More can be read in Security.