User Agreements and Policies

You can use our service desk portal for getting RIS support. RIS also offers 15 min. virtual office hours session Mon-Thru..

User Agreements and Policies

User Agreements

User Policy

The use of research storage is primarily for research data, which may include information classified as confidential and protected. Users of the storage who are unsure of the sensitivity of the data they intend to store should refer to the University’s information classification policies (see the Information Classification Policy) or contact the Information Security Office at infosec@wustl.edu for guidance.

Agency regulation and university policy require information in the protected class to be encrypted in transit and at rest. Sensitive information in the Research Storage should not be removed to unprotected networks and computing resources. It is required to be encrypted if it is not in an approved university data center, on a mobile device, or another computing system. See the Encryption policy.

It is the responsibility of the storage user to always ensure adequate protection of the information when using
this service.

Users of this service:

  • Agree to store only data that pertains to official business and is authorized to be stored within the service.

  • Agree to ensure that sensitive information stored within the service is restricted to authorized team members on a need-to-know basis.

  • Agree to ensure that access to sensitive data is based on your role or research.

  • Agree not to retrieve information for someone who does not have authorization to access that information.

  • Agree to ensure that all Protected Data is encrypted in transit and at rest, and strongly recommend encryption of Confidential Data. Data in transit refers to data actively moving from one location to another (e.g., from local storage to the cloud, sent via email). Data at rest refers to data in storage (e.g., on a server, hard drive, or in the cloud). Protecting data in transit and at rest may involve encrypting emails, files, systems, and/or devices. (See the Encryption policy.)

  • Agree to coordinate your user access requirements and user access parameters with the Research Infrastructure Services (RIS) WashU IT group.

  • Agree to notify the service provider (RIS) if access to the storage resources is beyond that which you or they have authorized.

  • Agree to report all security incidents or suspected incidents to the RIS (ris@wustl.edu) and/or INFOSEC. (infosec@wustl.edu)

  • Agree to discontinue use of the service from any resources that show signs of being infected by a virus or other malware and report the suspected incident.

  • Agree to safeguard storage resources against waste, loss, abuse, unauthorized users, and misappropriation.

  • Agree to ensure that hard or electronic copies of Confidential and Protected information are destroyed after it is no longer needed. (See the Media Policy.)

  • Agree not to store U.S. classified national security information or Controlled Unclassified Information (CUI) on the service.

  • Agree to the monitoring of your use of this service for any violations of the above.

An unprotected network or networks with insufficient protection include any network other than WUCON or a High Trust Domain. Consult with the RIS or INFOSEC groups if you do not know what network you are on or where the data will reside.

Any device that stores protected information but does not encrypt the information and does not have a
password/passcode is considered unsafe and in violation of policy.

Separation Policy

Users of this service:

  • Agree upon departure from the university, their data management falls under the associated department, including decisions regarding storage within Research Infrastructure Services (RIS) and other computational services.

  • Agree upon departure from the university, they will retain access to services as long as their WashU Key remains in an active (student, employee, or contingent employee) status.
    Please note: Alumni status is not considered an active status.

  • Agree in the absence of specific instructions from the department, data and access to data will be retained for the benefit of other researchers.

  • Agree that a request to transfer, reassign ownership to another sponsor, or to delete their data can be made.

 


In addition to above usage agreements, the users of RIS also recognize and adhere to the usage policies of our compute and storage platforms as listed under:

Compute Platform Policies

Data/Storage Platform Policies


Other Usage Guidelines

Comments