Repository navigation
🚀 Release Announcement: First Steps toward Data Security Classification and Settings in the TigerData Web Portal
We are excited to begin rolling out a new project-level metadata field called “Data Security,” which will be mandatory for all new project requests moving forward. In this initial iteration, the only options are the two lowest classifications, “Level 0 - Public” and “Level 1 - Internal,” and neither selection will change our standard setup for new projects at this time. As our secure infrastructure matures, we will add options for “Level 2 - Confidential” and “Level 3 - Restricted” (see Classify Your Information | Protect Our Info).
No action is required for pre-existing projects at this time.
Why are we doing this now?
TigerData is designed to align with Princeton University policies for data security and information classification. Our systems have been suitable for non-sensitive open data and internal use data from the beginning, but we have so far not made any explicit distinctions between classification levels. The next step toward our vision for enhanced data security options is to introduce the “Data Security” field with only the two lowest classification levels enabled. At this stage, your selection will be for internal recordkeeping only.
Who is this for?
- New project requesters are now able to declare their desired Data Security classification level
- System Administrators will start tracking projects by Data Security classification level
- Users of all types can see their project’s Data Security classification level after approval
What’s new?
Data Security Options for New Project Requests
- The Data Security field is added to the Basic Details step in the request wizard
- The wizard includes a link to the Princeton Data Security Classification Guide
- This field is now required for all new project requests
- System Administrators will ensure this field is complete and confirm the selection with the Data Sponsor before approving any new request
- At this time, the Data Security field is meant for classification purposes only
- Your selection will not change the standard security settings for all TigerData projects
- TigerData does not have a way to publish projects at this time
- The only available options at this iteration are:
Data Security Setting on the Project Page
- The Data Security field is shown under the Details tab in the Basic Details section
- Projects that were approved before this release will show a blank value for Data Security
- At this time, no further action is required for pre-existing projects
What’s next?
- A selection for the Data Security field may become required for existing projects soon
- We will reach out to Data Sponsors and Data Managers on existing projects before requiring any updates
- When the TigerData secure infrastructure is ready for wide adoption, we will add options for “Level 2 - Confidential” and “Level 3 - Restricted” in the Data Security dropdown in the request wizard
- Selections above Level 1 will lead to stricter security settings for projects upon approval
- We are not planning to support Highly Restricted (Level 4) data in TigerData; instead, please refer to Secure Research Infrastructure | Princeton Research Computing
Additional release notes
- Allow the oldadministrator to stop notifying honeybadger by @carolyncole in #2969
- Adding data security level to emails by @kelynch in #2971
- Vite upgrade by @bess in #2973
- Bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in #2967
- Upgrade mediaflux to v0.62.0 by @JaymeeH in #2978
- Bump the npm_and_yarn group across 1 directory with 3 updates by @dependabot[bot] in #2977
Full Changelog: v0.136.0...v0.137.0