Controlled Research Enclave - CRE

secure research logoThe Controlled Research Enclave (CRE) is a highly secure, isolated computing and storage environment designed for UNL researchers handling sensitive, restricted, or federally regulated data. The CRE ensures your research complies with federal laws, sponsor requirements, and University security policies without slowing down your work.

What data belongs in the CRE?

The CRE is designed to handle research that involves "High Risk" data, including:

  • CUI: Federally Controlled Unclassified Information (e.g., NIST 800-171, CMMC requirements).
  • PHI: Protected Health Information (HIPAA-regulated data).
  • Sensitive Human Subjects Data: Identifiable data categorized as high-risk by the IRB.
  • PII & Financials: Datasets containing Social Security Numbers, passport/visa numbers, or financial account data.
  • ITAR / Restricted EAR: Export-controlled defense or aerospace data.

What data does NOT belong in the CRE?

  • Publicly available manuscripts and associated data
  • Public directory information
  • Standard, non-sensitive research data (e.g., surveys of personal opinions)
  • Personal data not related to University business
  • EAR 99 information

Key Features & Restrictions

Because the CRE is a high-security environment, it operates differently than standard campus IT:

  • No Personal Storage: Data inside the CRE cannot be saved to personal laptops, USB drives, or personal cloud accounts (like OneDrive).
  • Monitored Environment: To meet federal compliance, network traffic and data access within the CRE are actively logged and monitored by University IT.
  • Regulated Data Transfers: Moving data in or out of the CRE to share with third parties requires an approved Data Use Agreement (DUA) or Material Transfer Agreement (MTA).

Prerequisites for Access

Before IT can grant you or your lab staff access to the CRE, you must complete the following:

  1. Project Approval: Your data's risk classification must be approved by the appropriate campus research oversight body (e.g., IRB or Export Control).
  2. Security Training: All personnel must complete Information Security training specifically related to the CRE's data controls.

How to Request

Begin by filling out the CRE request form:

https://nusupport.nebraska.edu/TDClient/33/Portal/Requests/Service/208/Controlled-Research-Enclave-CRE/Request

Once submitted, our team will review and reach out as soon as possible to help determine next steps moving forward.

Frequently Asked Questions (FAQ)

  • Do I really have to use the CRE, or can I just use my lab computers?

If your data is classified as "High Risk" (like CUI, ITAR, or PHI), University policy (Executive Memorandum No. 42) mandates that it be stored and processed in a designated secure environment like the CRE. Storing this data on standard lab computers or personal devices is strictly prohibited and can violate your grant terms.

  • I took CITI/information security training at my previous university. Does that count?

No. Per University policy, security training from other institutions does not transfer. All personnel must complete the specific Information Security training before accessing the CRE.

  • How do I share my CRE data with external collaborators?

Because this data is highly regulated, you cannot simply email it or drop it in a standard shared folder. You must have an executed Data Use/Data Transfer Agreement (DUA/DTA) in place. Contact Research IT, and we will help coordinate the secure transfer of your data once the agreements are signed.

  • Can I access the CRE from off-campus?

Yes, but access requires secure authentication, including Multi-Factor Authentication (Duo / Okta) and potentially a VPN connection, depending on the specific compliance requirements of your project.

  • How much does the CRE cost?

TBD