
The Controlled Research Enclave (CRE) is a highly secure, isolated computing and storage environment for University of Nebraska researchers working with sensitive, restricted, or federally regulated data. The CRE provides the technical safeguards needed to meet applicable federal, sponsor, and University security requirements while supporting your research.
What data belongs in the CRE?
The CRE is designed for research involving High Risk or otherwise regulated data, including:
- CUI — Controlled Unclassified Information: Federally controlled information subject to requirements such as NIST SP 800-171 or CMMC.
- PHI — Protected Health Information: Health information subject to HIPAA or related contractual requirements.
- Sensitive Human Subjects Data: Identifiable research data classified as high risk by the appropriate research oversight body.
- PII and Financial Information: Data containing information such as Social Security numbers, passport or visa numbers, or financial account information.
- ITAR / Restricted EAR Data: Export-controlled research information subject to applicable U.S. export-control requirements.
What data does not belong in the CRE?
Most public, low-risk, and standard research information does not require the additional protections provided by the CRE.
- Publicly available manuscripts and associated public data
- Public directory information
- Standard, non-sensitive research data
- Personal data unrelated to University business
- EAR99 information that does not have additional contractual or regulatory restrictions
Not sure whether your research requires the CRE?
Research IT can help determine the appropriate environment based on your data classification, sponsor requirements, and applicable regulations.
Key Features & Restrictions
Because the CRE is designed for regulated research, it operates differently from a standard University computing environment.
- Restricted Storage: CRE data cannot be stored on personal computers, removable media, personal cloud storage, or other unapproved locations.
- Logging & Monitoring: Network activity and access to regulated information may be logged and monitored to satisfy University, contractual, and federal security requirements.
- Controlled Data Transfers: Data entering or leaving the CRE must follow approved transfer procedures. Transfers to external organizations may also require an executed Data Use Agreement (DUA), Data Transfer Agreement (DTA), Material Transfer Agreement (MTA), or other applicable agreement.
Before You Request Access
Before access can be granted to you or members of your research team, the following requirements may need to be completed:
- Research / Data Approval: The project's data classification and regulatory requirements must be identified and approved by the appropriate University office, such as the IRB or Export Control.
- Required Security Training: Personnel must complete applicable University Information Security training before accessing regulated data within the CRE.
- User Authorization: Access must be approved for each individual who will work within the environment.
Request the Controlled Research Enclave
Submit a CRE request to begin the review process. Research IT will review your project and contact you to discuss requirements, access, and next steps.
Submit a CRE Request
Frequently Asked Questions
Do I really have to use the CRE, or can I use my lab computers?
High Risk or regulated data may require a University-approved secure computing environment based on University policy, federal requirements, sponsor terms, or contractual obligations. Standard lab computers and personal devices may not meet these requirements. Research IT can help determine whether the CRE is required for your project.
I completed security or CITI training at another institution. Does that count?
Previous training may not satisfy University-specific security requirements. Personnel accessing the CRE must complete all training required for their project and level of access.
How do I share CRE data with external collaborators?
Regulated data cannot be transferred through standard email, personal cloud storage, or other unapproved methods. External sharing must follow an approved secure transfer process and may require an executed DUA, DTA, MTA, or other agreement. Research IT can help coordinate the technical requirements for an approved transfer.
Can I access the CRE from off campus?
Remote access may be available depending on your project's security requirements. Access requires approved authentication controls, including multi-factor authentication, and may require additional secure connectivity such as VPN.
How much does the CRE cost?
CRE costs depend on the resources and services required for your research project. Submit a CRE request and Research IT will help identify applicable costs during the project review process.
CRE Forms & Related Requests
Already using the CRE? Use the appropriate form below to request access, account changes, system changes, or external connectivity.