<?xml version="1.0"?>
<News hasArchived="false" page="1" pageCount="1" pageSize="10" timestamp="Fri, 07 Aug 2026 11:00:03 -0400" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts.xml?tag=security">
<NewsItem contentIssues="false" id="145539" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/145539">
<Title>UMBC leads new program to build research security compliance support for mid-sized universities</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2024/11/Spring-Campus24-0010-150x150.jpg" alt="A shot of UMBC's campus with many students walking around. You can see cherry blossoms on the left side of the image in the foreground. There are black banners hanging up with the UMBC logo that says welcome to UMBC." style="max-width: 100%; height: auto;">
    <p>UMBC is leading a new initiative, in partnership with several Historically Black Colleges and Universities (HBCUs) and minority-serving institutions (MSIs) in the region, that’s aiming to expand the research compliance capacity of mid-size (universities with 15,000 or less students) and smaller universities to better adhere to emerging federal research security policies. </p>
    
    
    
    <p>To address the challenges associated with expanding research compliance capacity at institutions at these sizes, UMBC is partnering with the University of Maryland, Eastern Shore, Morgan State University, and Delaware State University to develop the <a href="https://research.umbc.edu/risc/" rel="nofollow external" class="bo">Research Integrity, Security, and Compliance (RISC) program</a>. RISC is supported through a five-year, $3.9 million grant from the National Science Foundation’s <a href="https://new.nsf.gov/funding/initiatives/broadening-participation/granted" rel="nofollow external" class="bo">Growing Research Access for Nationally Transformative Equity and Diversity</a> (GRANTED) program. The program’s goal is to address systemic barriers within the nation’s research enterprise by improving research support and service capacity.</p>
    
    
    
    <p>Principal investigator (PI) <strong>Karl V. Steiner</strong>, vice president for research and creative achievement, and co-PI <strong>Christine Mallinson</strong>, assistant vice president for research and scholarly impact, will lead the multi-institutional RISC program. </p>
    
    
    
    <p>“Mid-size institutions, along with MSIs and HCBUs, are expected to keep pace as new policies and guidance emerge, but they may not have the same ability or capacity to do so, compared to larger and more highly resourced research institutions,” explains Mallinson. “RISC will help us develop and then implement these evolving compliance structures and processes for smaller universities.”</p>
    
    
    
    
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2024/11/Karl-Steiner23-7773-1200x800.jpg" alt="A man, Karl Steiner, wearing glasses smiling at the camera. He has a on a tie with purple swirl like design and a UMBC lapel pin clipped to his lapel. " style="max-width: 100%; height: auto;">
    
    
    
    <img width="957" height="1024" src="https://umbc.edu/wp-content/uploads/2024/11/Christine-Mallinson-2021-957x1024.jpeg" alt="Woman, Christine Mallinson, smiling at the camera" style="max-width: 100%; height: auto;">
    Karl V. Steiner and Christine Mallinson, UMBC’s co-investigators who are leading the <a href="https://research.umbc.edu/risc/" rel="nofollow external" class="bo">Research Integrity, Security, and Compliance (RISC) program</a>. (Marlayna Demond ’11/UMBC)
    
    
    
    <p>Research security, according to the <a href="https://www.whitehouse.gov/wp-content/uploads/2022/01/010422-NSPM-33-Implementation-Guidance.pdf" rel="nofollow external" class="bo">nation’s federal guidelines on government-supported research</a>, is defined as “safeguarding the research enterprise against the misappropriation of research and development to the detriment of national or economic security, related violations of research integrity, and foreign government interference.” As part of the RISC program, UMBC will create, test, and implement a model for how mid-sized and smaller research universities can adhere to new and emerging research security policies.</p>
    
    
    
    <p>That process, Mallinson explains, includes developing training modules on research security and compliance for researchers and research administration staff. The model will be further developed and evaluated among the partnering RISC institutions. </p>
    
    
    
    <p>The program will also support expanding the team in UMBC’s <a href="https://research.umbc.edu/office-of-research-protections-and-compliance/" rel="nofollow external" class="bo">Office of Research Protections and Compliance</a> (ORPC) and an additional cybersecurity specialist role in the <a href="https://doit.umbc.edu/" rel="nofollow external" class="bo">Division of Information Technology</a>, as well as supporting an increase in compliance staffing at the partnering institutions. Mallinson shares the “RISC Roadmap” will be publicly available for other institutions to assist them in responding to research integrity, security, and compliance guidance and meeting institutional needs.</p>
    
    
    
    <img width="981" height="1024" src="https://umbc.edu/wp-content/uploads/2024/11/Interns-at-Grants-Made-conference-scaled-1-981x1024.jpeg" alt="A group of six college students standing in front of a large posture board that says GRANTS MaDE Conference, with the description. The students have hand-written name tag stickers on their blazers. " style="max-width: 100%; height: auto;">Andy Quach (far left) alongside fellow GRANTS MADE Research Administration interns from Morgan State University, and Delaware State University at the GRANTS MADE conference in April 2024. <em>(Photo courtesy of Christine Mallinson)</em>
    
    
    
    <p>“UMBC is at the forefront of this conversation of what it looks like for mid-sized institutions and smaller, emerging research institutions to build their research infrastructure in this area,” says Mallinson.</p>
    
    
    
    <p>“I am very pleased about our multi-institutional, regional partnership and the significant support by the NSF that will allow us to address these pressing issues of research compliance and to create a blueprint for other smaller and mid-size research institutions,” adds Karl Steiner. “We have already benefited from the input provided by our partners during the proposal process.”</p>
    
    
    
    <p>In addition to the RISC program, Mallinson has also been working to educate undergraduate students on careers in research administration with the <a href="https://research.umbc.edu/grants-made/" rel="nofollow external" class="bo">GRANTS MADE Research Administration Internship</a>. The internship, also funded by NSF’s GRANTED program, was created to expand and diversify the research administration workforce. UMBC’s <strong>Alexis Johnson </strong>’24 and current senior <strong>Andy Quach, </strong>both financial economics majors, were a part of the internship program’s inaugural cohort. This summer, Quach continued his potential career interests in research administration with an internship with the ORPC. Quach helped to review and audit active research protocols and drafted various compliance documents. </p>
    
    
    
    <p>Mallinson adds that prospective interns may also have the option to work with the ORPC team, allowing for a synergistic opportunity to train the next generation in this critical area of research security and compliance.</p>
    </div>
]]>
</Body>
<Summary>UMBC is leading a new initiative, in partnership with several Historically Black Colleges and Universities (HBCUs) and minority-serving institutions (MSIs) in the region, that’s aiming to expand...</Summary>
<Website>https://umbc.edu/stories/research-integrity-security-compliance-program/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/145539/guest@my.umbc.edu/e6a868827d3e634fb7df8103fb2b0d7d/api/pixel</TrackingUrl>
<Tag>national-science-foundation</Tag>
<Tag>news</Tag>
<Tag>research</Tag>
<Tag>science-and-tech</Tag>
<Tag>security</Tag>
<Tag>story</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>3</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Mon, 11 Nov 2024 14:06:41 -0500</PostedAt>
<EditAt>Mon, 11 Nov 2024 14:06:41 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="120526" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/120526">
<Title>How secure is your data when it&#8217;s stored in the cloud?</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2018/03/pic-header-150x150.jpg" alt="" style="max-width: 100%; height: auto;"><p><a href="https://theconversation.com/profiles/haibin-zhang-435304" rel="nofollow external" class="bo">By Haibin Zhang, Assistant Professor of Computer Science and Electrical Engineering</a><em><a href="http://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo"><br>
    Header photo:</a><a href="https://www.shutterstock.com/image-illustration/safety-concept-cloud-storage-data-571211755" rel="nofollow external" class="bo">SWEviL/Shutterstock.com</a> </em></p>
    <p>As cloud storage becomes more common, data security is an increasing concern. Companies and schools have been increasing their use of services like <a href="https://www.google.com/drive/" rel="nofollow external" class="bo">Google Drive</a> for some time, and <a href="https://www.businesswire.com/news/home/20170614005856/en/92.48-Billion-Cloud-Storage-Market---Forecasts" rel="nofollow external" class="bo">lots of individual users also store files</a> on <a href="http://dropbox.com/" rel="nofollow external" class="bo">Dropbox</a>, <a href="http://box.com/" rel="nofollow external" class="bo">Box</a>, <a href="https://www.amazon.com/clouddrive" rel="nofollow external" class="bo">Amazon Drive</a>, <a href="https://onedrive.live.com/about/en-us/" rel="nofollow external" class="bo">Microsoft OneDrive</a> and the like. They’re no doubt concerned about keeping their information private – and millions more users might store data online if they were <a href="http://www.securityweek.com/it-pros-still-concerned-over-public-cloud-security-survey" rel="nofollow external" class="bo">more certain of its security</a>.</p>
    <p>Data stored in the cloud is nearly always <a href="https://computer.howstuffworks.com/cloud-computing/cloud-storage3.htm" rel="nofollow external" class="bo">stored in an encrypted form</a> that would need to be cracked before an intruder could read the information. But as a <a href="https://www.csee.umbc.edu/%7Ehbzhang/" rel="nofollow external" class="bo">scholar of cloud computing and cloud security</a>, I’ve seen that where the keys to that encryption are held varies among cloud storage services. In addition, there are relatively simple ways users can boost their own data’s security beyond what’s built into systems they use.</p>
    <h2>Who holds the keys?</h2>
    <p>Commercial cloud storage systems encode each user’s data with a specific encryption key. Without it, the files look like gibberish – rather than meaningful data.</p>
    <p>But who has the key? It can be stored either by the service itself, or by individual users. Most services keep the key themselves, letting their systems see and process user data, such as indexing data for future searches. These services also access the key when a user logs in with a password, unlocking the data so the person can use it. This is much more convenient than having users keep the keys themselves.</p>
    <p>But it is also less secure: Just like regular keys, if someone else has them, they might be stolen or misused without the data owner knowing. And some services might have <a href="https://en.wikipedia.org/wiki/Criticism_of_Dropbox" rel="nofollow external" class="bo">flaws in their security practices</a> that leave users’ data vulnerable.</p>
    <h2>Letting users keep control</h2>
    <p>A few less popular cloud services, including <a href="https://mega.nz/" rel="nofollow external" class="bo">Mega</a> and <a href="https://spideroak.com/" rel="nofollow external" class="bo">SpiderOak</a>, require users to upload and download files through service-specific client applications that include encryption functions. That extra step lets users keep the encryption keys themselves. For that additional security, users forgo some functions, such as being able to search among their cloud-stored files.</p>
    <p>These services aren’t perfect – there’s still a possibility that their own apps might be compromised or hacked, allowing an intruder to read your files either before they’re encrypted for uploading or after being downloaded and decrypted. An encrypted cloud service provider could even embed functions in its specific app that could leave data vulnerable. And, of course, if a user loses the password, the data is irretrievable.</p>
    <p>One new mobile app says it can keep phone photos <a href="https://www.wired.com/story/pixek-app-encrypts-photos-from-camera-to-cloud/" rel="nofollow external" class="bo">encrypted from the moment they’re taken</a>, through transmission and storage in the cloud. Other new services may arise offering similar protection for other types of data, though users should still be on guard against the potential for information to be hijacked in the few moments after the picture is taken, before it’s encrypted and stored.</p>
    <h2>Protecting yourself</h2>
    <p>To maximize cloud storage security, it’s best to combine the features of these various approaches. Before uploading data to the cloud, first encrypt it using your own encryption software. Then upload the encoded file to the cloud. To get access to the file again, log in to the service, download it and decrypt it yourself.</p>
    <p>This, of course, prevents users from taking advantage of many cloud services, like live editing of shared documents and searching cloud-stored files. And the company providing the cloud services could still modify the data, by altering the encrypted file before you download it.</p>
    <p>The best way to protect against that is to use <a href="https://doi.org/10.1007/3-540-44448-3_41" rel="nofollow external" class="bo">authenticated</a> <a href="https://doi.org/10.1145/937527.937529" rel="nofollow external" class="bo">encryption</a>. This method stores not only an encrypted file, but additional metadata that lets a user detect whether the file has been modified since it was created.</p>
    <p>Ultimately, for people who don’t want to <a href="https://www.cryptopp.com/" rel="nofollow external" class="bo">learn how</a> <a href="https://www.openssl.org" rel="nofollow external" class="bo">to program</a> <a href="https://pypi.python.org/pypi/pycryptodome" rel="nofollow external" class="bo">their own tools</a>, there are two basic choices: Find a cloud storage service with trustworthy upload and download software that is open-source and has been validated by independent security researchers. Or use trusted open-source encryption software to encrypt your data before uploading it to the cloud; these are available for all operating systems and are generally free or very low-cost.</p>
    <p> </p>
    <p><em><a href="https://theconversation.com/profiles/haibin-zhang-435304" rel="nofollow external" class="bo">Haibin Zhang</a>, Assistant Professor of Computer Science and Electrical Engineering, <a href="http://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">University of Maryland, Baltimore County</a></em></p>
    <p><em>This article was originally published on <a href="http://theconversation.com" rel="nofollow external" class="bo">The Conversation</a>. Read the <a href="https://theconversation.com/how-secure-is-your-data-when-its-stored-in-the-cloud-90000" rel="nofollow external" class="bo">original article</a>.</em></p>
    </div>
]]>
</Body>
<Summary>By Haibin Zhang, Assistant Professor of Computer Science and Electrical Engineering  Header photo:SWEviL/Shutterstock.com    As cloud storage becomes more common, data security is an increasing...</Summary>
<Website>https://umbc.edu/stories/how-secure-is-your-data-when-its-stored-in-the-cloud/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/120526/guest@my.umbc.edu/0c6b0af862297d3a77d94dd1267e6b84/api/pixel</TrackingUrl>
<Tag>csee</Tag>
<Tag>discovery</Tag>
<Tag>haibin-zhang</Tag>
<Tag>security</Tag>
<Tag>umbc</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Fri, 09 Mar 2018 19:25:16 -0500</PostedAt>
</NewsItem>

</News>
