Scientific Computing and Data / High Performance Computing / NIST SP 800-171
What You Need to Know About Accessing Restricted Federal Research Data
Some research datasets—particularly genomic and other sensitive datasets provided by the federal government—have additional security requirements. If you plan to bring this type of data into Mount Sinai, you may be required to use a specially secured computing environment and complete an institutional approval process before you can access the data.
What is NIST SP 800-171?
NIST SP 800-171 is a set of cybersecurity requirements developed by the National Institute of Standards and Technology (NIST). It describes how organizations should protect certain sensitive federal information when that information is stored, processed, or transmitted on systems outside the federal government. (NIST Computer Security Resource Center)
Think of it as a security checklist for protecting sensitive federal data. It covers areas such as:
-
Access control — making sure only authorized people can access the data
-
Identification and authentication — securely verifying who users are
-
Audit and accountability — keeping records of access and activity
-
Configuration management — maintaining secure system configurations
-
Incident response — detecting and responding to security incidents
-
Media protection — protecting data stored on devices and other media
-
System and communications protection — securing data while it is being transmitted
-
Personnel security — addressing risks associated with people who have access to the information
NIST SP 800-171 Rev. 3, published in 2024, contains the current set of requirements and supersedes the earlier Rev. 2. (NIST Computer Security Resource Center)
What does this mean for researchers?
If you receive restricted data from a federal data repository, you cannot necessarily download it to your normal computer, Mount Sinai server, or standard research environment.
Instead, the data may need to be:
-
Approved for use by Mount Sinai
-
Transferred through an approved process
-
Stored and analyzed in a NIST SP 800-171-compliant environment
-
Accessed only by appropriately authorized researchers
For Mount Sinai, Minerva-Res is the designated environment for research requiring this level of security.
What is a federal genomic data repository?
A federal genomic data repository is a government-controlled database that stores genomic or other sensitive research data. One example is NIH dbGaP (Database of Genotypes and Phenotypes).
These repositories may contain highly sensitive information, including genetic information and associated clinical or research data. Access is therefore subject to additional security and data-use requirements.
What is NIH Notice NOT-OD-24-157?
NOT-OD-24-157 is an NIH policy notice concerning security requirements for certain controlled-access data obtained from NIH repositories. In practical terms, it means that researchers and institutions need to make sure that the environment used to store and work with certain NIH-controlled data meets the required security standards.
What is a Data Use Certification (DUC)?
A Data Use Certification (DUC) is a formal certification that describes how researchers will use and protect controlled-access data.
In simple terms, it says:
“We agree to use this data only for the approved research purpose and to protect it according to the applicable requirements.”
What is a Data Use Agreement (DUA)?
A Data Use Agreement (DUA) is a formal agreement governing how data can be accessed, used, stored, and shared.
It typically specifies things such as:
-
Who may access the data
-
What the data may be used for
-
How the data must be protected
-
Whether the data can be shared
-
How long the data may be retained
-
What happens if the terms of the agreement are violated
What is a Data Transfer Use Agreement (DTUA)?
A Data Transfer Use Agreement (DTUA) governs the transfer of data from one organization to another.
It establishes the conditions under which the data can be transferred and the responsibilities of the organizations receiving and protecting it.
What is a Data Provision Agreement (DPA)?
A Data Provision Agreement (DPA) is an agreement that establishes the conditions under which data is provided to the researcher or institution.
The exact agreement required depends on the source of the data and the circumstances under which it is being provided.
What should I do if I want to use this type of data?
Do not transfer or download the data into a standard research environment before obtaining approval.
Instead:
- To obtain institutional approval to access data from NIH-controlled repositories, you will need to go to this document and follow the required steps: GCO Requirements for Restricted Access to Incoming Data from a Federal Genomic Data Repository or a Data Repository Subject to NIST SP 800-171.
- These steps include information on Data Use Certifications, Data Use Agreements, Data Transfer Use Agreements (DTUAs), and/or Data Provision Agreements (DPAs).
-
Determine what agreements or certifications are required for your dataset.
-
Work with your GCO Contracts Specialist or AOR (Authorized Organizational Representative) to complete the institutional approval process.
-
Once approved, work with the appropriate Mount Sinai research computing team to use Minerva-Res, the designated NIST SP 800-171 environment.
-
Keep the data within the approved environment and follow all requirements of the applicable data-use agreement.
Summary
If your research involves restricted federal data, the important point is:
Get institutional approval first and use the appropriate secure computing environment. For NIST SP 800-171–controlled data at Mount Sinai, that environment is Minerva-Res.
The security requirements are not simply an IT preference—they are part of the conditions under which certain federal data may be accessed and used. NIST describes SP 800-171 as requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. (NIST Computer Security Resource Center)
One terminology note: NIST SP 800-171 is the name of the NIST publication; NIST stands for National Institute of Standards and Technology, and SP stands for Special Publication.
