2019/08/23 by Diego Arenas, Arenas, Diego, Jon Atkins +54 · 1 voice
Computer Science · Decision Sciences · #Cryptography and Security (cs.CR) #Data Quality and Management #FOS: Computer and information sciences #Privacy-Preserving Technologies in Data #Scientific Computing and Data Management #cs.CR
paper · pdf · doi:10.48550/arxiv.1908.08737
openalex publication_date 2019/08/23 · arxiv published 2019/08/23 · arxiv created 2019/09/15 · arxiv updated 2019/09/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
We present a policy and process framework for secure environments for productive data science research projects at scale, by combining prevailing data security threat and risk profiles into five sensitivity tiers, and, at each tier, specifying recommended policies for data classification, data ingress, software ingress, data egress, user access, user device control, and analysis environments. By presenting design patterns for security choices for each tier, and using software defined infrastructure so that a different, independent, secure research environment can be instantiated for each project appropriate to its classification, we hope to maximise researcher productivity and minimise risk, allowing research organisations to operate with confidence.