Managing research data is increasingly expected to meet stringent information security controls. Many of these controls are based on NIST Special Publication 800-171, or have requirements that map well to these controls. These include not only controlled unclassified information (CUI), but various clinical and human subjects research data.
Department of Defense contracts are beginning to require information systems to have been certified through Cybersecurity Maturity Model Certification (CMMC).
As of January, 2025, NIH has specified that NIST SP 800-171 shall be used as a standard for systems with various genomic data, notably including those from database of Genotypes and Phenotypes (dbGaP), a common data source for research at GW.