Search Results for: security policy

Acceptable Use Policy

Acceptable Use Policy

FAS Research Computing (FASRC) cluster access and usage is intended only for legitimate purposes which benefit research at Harvard University.  Access must be authorized by the faculty or management of the FAS or those of our partner schools, and by the staff of Research Computing.  Account access should only be granted for the purposes necessary to accomplish the goals of Harvard University and its research projects.  All active FAS RC account holders are subscribed to our notifications mailing list which is a requirement for all users.

Billing

Cluster usage and additional resources such as storage may be subject to charges to the PI, school, or department.  All billing is done exclusively via Harvard internal billing codes at the Tub/school level.

See our Data Storage Billing documentation.

Academic and Administrative Use

The FASRC clusters (Cannon and FASSE) are for research only and cannot be used for academic purposes. Harvard provides an Academic Cluster for those purposes.

FASRC cluster storage is for research data and results and is not suitable for administrative data storage.

Accounts

Accounts and account credential sharing is not allowed under university policies and reasonable precaution should be taken to keep your account credentials secure and private. No university staff will ever ask for your password.  Additionally, a user may have only one account at FASRC. All individual account holders, whether Harvard affiliates or outside collaborators agree to be held accountable by the Harvard University Electronic Access and Information Security polices: http://huit.harvard.edu/information-technology-policies. In addition, researchers should make themselves familiar with the university research policies maintained by the Provost’s Office.

All account holders agree to respect requests from support staff around how they use the system. The support staff may, as needed, impose whatever policies are required to ensure the system runs effectively for all users of the system.

Data Security

The Cannon cluster is for data rated as Level 2 or below. Level 3 data must be secured and processed on the FASSE cluster and storage. Level 4 or above data is not allowed on any FASRC cluster or storage.

Please also review the FASRC Cluster Storage Policy for guidelines an best practices around storage.

Customs and Responsibilities

In addition, the FASRC clusters and storage are shared resourcesm so please familiarize yourself with our Cluster Customs and Responsibilities.

Additional Policies

FAS RC Research Data Retention and Deletion Policy

FAS RC Research Data Retention and Deletion Policy

Purpose: 

This policy defines FAS RC standards and procedures for the retention and deletion of research data, outputs, temporary files, and associated digital resources managed by the FAS RC in support of research activities. 

Scope: 

This policy applies to all research data stored, processed, or managed on servers, workstations, cloud resources, storage systems, or backup media provisioned by the FAS Research Computing Service Group.

Data Retention: 

Following the departure of faculty from the University, the associated primary department will assume responsibility for the maintenance, storage, and cost of housing the remaining research data.

Home Directories:

Aligning with the University Research Data Security Policy and the Retention and Maintenance of Research Records and Data Frequently Asked Questions (“FAQs”), home directories will be retained for no more than 7 years following a researcher’s departure from the University or the deactivation of their FASRC account. The researcher’s last login to their FASRC account will be used to track compliance. 

Project Data:

Principal Investigators (PIs) should notify FAS RC 60 days prior to their departure from the University including the duration of any appointments (courtesy or associate), with instructions and next steps for remaining datasets. 

For research data associated with completed or inactive research projects and/or departed faculty where no notice has been given to FAS RC as to where the research data should be stored

  1. The PIs Harvard affiliated primary department becomes responsible for the storage and cost of the research data. Closure of the PIs group and project in FAS RC will be used to track compliance. 
  2. The research data will be retained in the source storage directory for 2 years following project completion or inactivity. Completion of a project occurs after: 
    1. final reporting to the research sponsor 
    2. final financial close-out of a sponsored research award segment 
    3. final publication of research results 
    4. cessation of academic or scientific activity on a specific activity on a specific research project, regardless of whether its results are published, whichever is later. 
  3. Following 2 years of inactivity, data will be migrated to FASRC Long-Term Storage. The data will be retained for an additional 5 years to meet the University Data Retention guidelines. Following the completion of 5 years, the data can be deleted. Departments will be notified via email prior to the deletion.

Temporary and Scratch Storage:

Data stored in scratch or temporary directories may be deleted after 90 days without notice to maximize available resources. 

Deletion Procedures: 

  • Faculty and/or departments will be notified in advance of research data being deleted, per the timelines above. If PIs or Faculty are no longer associated with the University, the relevant department leadership will be notified via email. 
  • Data will be deleted using secure erasure methods in accordance with institutional IT security standards. 
  • Requests for retention extension can be made in writing and are subject to approval by FASRC and the department; individuals requesting the extension will be responsible for all associated storage costs. 

Ownership and Roles: 

  • University: Harvard University owns all research data generated through projects conducted under its authority or using its resources. While PIs and researchers manage and safeguard the data, the University is ultimately responsible for compliance with legal and sponsor requirements, ensuring confidentiality and security. 
  • Principal Investigators: Principal Investigators (PIs) are stewards of research data. If PIs choose to delegate responsibility within their research groups, the PI remains accountable to the University for stewardship of the data. Principal Investigators are responsible for ensuring proper data management, storage, and accessibility, meeting all University, legal, and sponsor requirements. This involves setting up procedures for data retention, confidentiality, and sharing while respecting data use agreements. 
  • Departments: In the case that a PI has left the University without delegating responsibility for data, the associated primary department of the departed PI takes on the role of steward. 
  • Researchers: Harvard community members who assist with management of data created, analyzed, and stored on FAS RC systems.
  • FAS RC: Responsible for executing deletions as outlined, maintaining logs of deletion actions, and responding to extension or exception requests. 

Policy Review: 

This policy will be reviewed and updated annually or as required by regulatory or operational changes. 

Last modification date: 2025-12-02

Related Policies and Information 

FASRC Cluster Storage Policy

FASRC Cluster Storage Policy

Cluster storage offered and maintained by FASRC should only be used for research taking place on FASRC clusters.

Examples of data that can be stored on FASRC storage are:

  • Datasets
  • Code
  • Scientific software
  • Research results

Examples of data that should not be stored on FASRC storage include:

  • Clerical or lab administrative data
  • Data related to personnel, grant proposals, business operations, or general lab management
  • Data with personally identifiable or financial information 

FASRC storage filesystems are only approved for Data Security Level 1 (DSL1) and  DSL2 research data on the Cannon cluster. DSL3 data must be stored in the approved FASSE cluster project. Research data containing information classified as DSL 4 must be stored on an appropriate storage solution that is approved for DSL4 sensitive data.*

*A limited number of DSL4 projects exist in their own isolated environments

If it comes to the attention of the FASRC Staff that non research related data is being stored on the FASRC systems, we will alert the lab’s PI.

To view alternative storage options for administrative data, please refer to the FASRC website.  Additional information is also provided on the Harvard Security website regarding Data Security levels.

Data Security Levels

Data Security Levels

What is a Data Security Level (DSL)?

Harvard groups data into 5 data security levels depending on the sensitivity of the data.  The DSL for data determines how that data must be managed.

DISCLAIMER: The information on this page relates only to the FASRC clusters and our current understanding of Harvard policy. Please refer to the Harvard Security Data Security Levels page for up-to-date university policies and information.

 

Cluster Data Security Level Ratings

Public
Public information (Level 1/DSL1): The FASRC Cannon cluster is rated only for DSL 1 and DSL 2 data.
Low Risk
Low Risk (Level 2/DSL2): The FASRC Cannon cluster is rated only for DSL 1 and DSL 2 data.
Medium Risk
Medium Risk (Level 3/DSL3): Only the FASRC FASSE (FAS Secure Environment) cluster is rated for DSL3 data.
High Risk
High Risk (Level 4/DSL4): For DSL4 projects, please contact University RC (URC) for options.
Extreme Risk
Extreme Risk (Level 5/DSL5): FASRC has no systems rated for DSL5 data.

 

LINKS

Web Scraping Policy

Web Scraping Policy

Web scraping is a contentious issue within research. While it is true that fair use provides for many uses of data gleaned from the Internet, in general this is applied to human information gathering, not programmatic machine scraping. That distinction makes the act of brute-force scraping an issue separate from fair use.

You, as a representative of Harvard, are not just using the source’s data, but also their servers, bandwidth, etc. in a way the source may not approve. This can lead to IP blacklisting and even legal action. So please tread carefully as your actions could negatively affect others.

If in doubt or in need of more authoritative guidance, please contact the Harvard Office of the General Counsel or Office of the Vice Provost for Research

If you are scraping for the purpose of train a GAI model, contact the Harvard Office of the General Counsel or Office of the Vice Provost for Research

Please be aware that merely being involved in academic pursuits does not exempt you from the usage policies of social media and other Internet platforms like Facebook, Twitter, etc.

Sensitive Data

If the data you are acquiring is considered sensitive, confidential, or contains human data, you will need to have this data reviewed for compliance before placing it on the FASRC cluster. If in doubt, you should always err on the side of caution and contact the Office of the Vice Provost for Research

 

Scraping data for use on the FASRC Cluster

If your research requires you to scrape content from the web, please review the following guidelines and suggestions.

We highly discourage using the cluster itself to scrape data. Due to its size and ease of parallelization of processes, the cluster is easily weaponized and your actions could have consequences for other researchers. Please seek another avenue for data acquisition first.

You should contact FASRC before commencing any scraping activity using the FASRC cluster.

It is highly preferable that you do the scraping elsewhere and then bring the data to the FASRC cluster for processing. If the data is sensitive, confidential, contains human data, or it is unclear, then this is a requirement. See ‘Sensitive Data’ above.

Also, if you are scraping for the purpose of training a GAI/LLM model, you should respect that site’s policies on this practice (this may be posted on the site, contained in a robots.txt file, or explicitly stated in their ToS). Even if you are doing the scraping manually, you should consider yourself the same as a bot and, if a site excludes GAI/AI bots, this also applies to you. Merely being an academic does not exempt you from following the wishes of a site and/or its members; your exfiltrated data could end up in other models thereby nullifying the source’s right to exclusivity/ownership. Please contact the Harvard Office of the General Counsel or Office of the Vice Provost for Research for further guidance.

Source Permission

If you are in doubt or have questions, please contact the Harvard Office of the Vice Provost for Research

Data on the Internet should not be programmatically (or ‘brute-force’) scraped using FASRC computing resources, even for academic research purposes, unless FASRC has given permission to proceed using the cluster or some system tied to the cluster, and:

A) The source provides an API for this purpose and any requirements they impose have been met.

B) The source allows/does not prohibit scraping in their terms of service or other public notice.

C) The source is the United States government and the data in question was generated with public funds and is publicly available without encumbrance. Further, that the site not be scraped using brute-force means if an API is provided.

D) The source has given you explicit permission in writing or via a secondary document spelling out that permission.

E) The source does not exclude/forbid your use-case, such as GAI or LLM training.

Data cannot be programmatically scraped using FASRC computing resources if the source has explicitly forbidden scraping in their terms of service and written permission to do so cannot be obtained. In such a case, you should investigate other options for acquiring this or similar data.

Throttling and Blacklisting

Scraping content from websites using highly parallelized processes, even with unfettered permission from the source, should be avoided. Doing so runs the risk of having the cluster, or even the university’s, IP range blacklisted. This could have an undesirable effect on other network and cluster users. Please ensure your processes pull data at a reasonable rate unless you explicitly have written approval from the data source to download more aggressively and assurance that this will not lead to blacklisting from them or their upstream provider.

Related:

Harvard Office of the Vice Provost for Research

US Data.gov Data Harvesting Information

Archive.org Scraping

 

Onboarding Policies and Procedures

Onboarding Policies and Procedures

This document outlines FAS Research Computing’s policies and procedures related to the onboarding of researchers and PIs. The document is structured as a checklist, to be utilized by researchers and PIs as they enter the university or join a new lab. The document also notates differences between the onboarding of researchers and faculty (PIs).  

Onboarding Checklist: Faculty

 

Onboarding Checklist: Researchers

Virtual Machines & Virtual Hosting

Virtual Machines & Virtual Hosting

As of December 2024, FASRC does not provide a general virtual machine service as part of its core services. It has in the past attempted to fill this gap when no other options were available, but 1) there was no funding for hardware or support for this service and its infrastructure  is old and being retired 2) other options, within and without Harvard, now exist.

If you require a VM for web hosting or other needs or for hosting or sharing data sets, please see the following options.

Harvard-based options:

Self-service, pay as you go, managed by you:

Please note that PIs and other data owners are responsible for following Harvard Information Security Policy and all other applicable Harvard policies and requirements. This includes knowing your data and following  the requirements for Data Security Level for servers and Research Data Management Security and Ownership Policies

FASSE / Protected Data Transfers

FASSE / Protected Data Transfers

FASSE Protected Data Transfers with VPN and SFTP

To preface this:  You are responsible for knowing, and complying with applicable Harvard Information Security Policy (controls that apply to DSL3 and lower), Harvard Research Data Security Policy, and any applicable contracts / data use agreements.

FASSE data transfers generally work the same as transfers for other environments.  For example:

  • When connected to the FASSE VPN realm, you can copy files to and from the FASSE cluster, assuming this meets policy/DUA compliance requirements.
  • While on FASSE nodes (compute, login, etc.) and the FASSE VPN, you have full access to the Internet through a proxy.
    • Generally, this means that you can push to or pull from any HTTPS, SFTP, or other service that supports a proxy.
    • For example, this means you should be able to pull data from data providers that provide an HTTPS, SFTP, or other service.  You may need to adjust certain configurations and workflows to use the proxy – Some details on this here

With that said, given that FASSE is rated for data security level (DSL) 3 data:

  • Do not store DSL 3 / FASSE data in your home directory.
  • If you have a DUA that requires encryption at rest, you must not use scratch for any data that the DUA applies to.  Neither local scratch, nor our global scratch, support encryption at rest.
  • FASSE VPN, login, compute, and VDI environments use a proxy.  Some transfer solutions do not work through a proxy.  If you run into this:
    • Please ensure you have tried to use a proxy, and if you still run into trouble,
    • Open a ticket with rchelp@rc.fas.harvard.edu indicating
      • What you have tried
      • What you expected to happen
      • What actually happened
      • Include specific commands, where these ran, and output messages including all errors.

FASSE Large Data Transfer with Globus

  • Data security level 3 / FASSE storage is intentionally not included in Globus by default.  If you would like your FASSE project to be exposed through Globus, consider the following:
    • If any data in this project is governed by a contract / data use agreement (DUA), please review the DUA to ensure Globus is compliant.  You might consult your School Security Officer for this.
      • An example scenario where Globus would not be compliant:  DUAs indicating that a VPN or private network must be used for all access to the data.  Globus makes data available over the Internet without a VPN or private network
    • Please submit a ticket to rchelp@rc.fas.harvard.edu as follows:
      • This must include the path to the project to add to Globus (e.g. “/n/piname_project_l3”)
      • This must indicate that the PI attests to Globus being compliant with any contracts/DUAs governing the data in this project storage
      • This must be from, or receive a reply directly from the PI for this project confirming this information

FASSE Storage Access with SMB Shares

  • For Storage, FASSE storage is intentionally not provided SMB shares by default.  If you need your FASSE project exposed through an SMB share, consider the following:
    • Please submit a ticket to rchelp@rc.fas.harvard.edu as follows:
      • This must include the path to the project (e.g. “/n/piname_project_l3”)
      • This must indicate that the PI attests to understanding and accepting the risks of enabling SMB access to this data, given that any system or network that can talk to this tiered storage, could access this data if the credentials from an account in the project were used.  Some example scenarios:
        • Someone with access to your storage accesses it / copies data down to an unmanaged lab computer without data security level controls
        • Someone with access to your storage accidentally clicks the wrong link on a computer with access to this storage. Their computer is compromised, malware identifies SMB access to your data, and compromises the confidentiality, integrity, and/or availability of your data – maybe ransomware, stealing the data, etc.
      • This must include a brief explanation of why SMB access is needed, and from where you will use this SMB access
      • This must be from, or receive a reply directly from the PI for this project confirming this information

If you have any questions or concerns, please do not hesitate to consult us at at security@rc.fas.harvard.edu, although in some cases we may end up pulling in or pointing you to your school privsec officer.

PI Responsibilities at FAS RC

PI Responsibilities at FAS RC

Overview

PIs have a variety of responsibilities at Harvard University.  This document will cover the responsibilities specific to FAS Research Computing, especially around information security and risk.

PIs are individuals given continuous or limited PI rights by the university and whom control their own funding in a school that FAS RC supports. Co-Investigators are not considered PIs.

Responsibilities

  • PIs are responsible for following all applicable Harvard University policies, including but not limited to Harvard Research Data Security Policy and Harvard Information Security Policy, as well as any requirements in data use agreements (DUAs) or contracts that impact them.
  • PIs are responsible for creating and maintaining accurate data documentation in the Harvard Compliance System, as required by University policies, and complying with approved data security and management plans.  Guidance on which applications are needed for your data.
  • PIs are responsible for submitting FASSE project requests for any data security level (DSL) 3 data they plan to use at FAS RC and keeping associated data in the specific FASSE storage provided for these projects.
  • PIs are responsible for informing FAS RC of any changes to Research Administration applications (e.g. DAT12-1234, DUA12-1234, IRB12-1234) governing data they plan to use for their FASSE projects, before moving new data to FAS RC storage for these projects.  This includes informing FASRC before adding data from a new application (e.g. DUA12-1234) to an existing FASSE project.
  • PIs are responsible for ensuring that any access they approve complies with all applicable Harvard University policies and DUA or compliance regimes.  For example, among many other scenarios:
    • If a DUA requires informing or obtaining approval from the data provider before providing access to the data, the PI must ensure this is done before they approve the associated FAS RC access
    • If a DUA states that only Harvard staff may have access to the data, the PI is responsible for ensuring they never approve access to non-Harvard members to that data (e.g. external collaborators)
  • PIs are responsible for informing FAS RC when an account they have sponsored should be disabled (i.e. if they sponsor the account and the person has left or should otherwise be disabled)
  • PIs are responsible for informing FAS RC when any accounts should be removed from groups they manage
  • PIs are responsible for informing FAS RC if and when data needs secure disposal/sanitization, either as required by Harvard University policy or a DUA
  • PIs are responsible for ensuring that FASRC services are used only for acceptable purposes and that billing costs for FASRC services are allowable and covered by their school/center.

Upcoming Responsibilities

  • Coming soon: PIs are responsible for reviewing accounts they sponsor on an annual basis [1]
  • Coming soon: PIs are responsible for reviewing access to groups they manage on an annual basis [1]
[1] If you would like to review spreadsheets of accounts you sponsor and group memberships for groups you approve, please contact rchelp@rc.fas.harvard.edu ask for account and access review spreadsheets.

© The President and Fellows of Harvard College.
Except where otherwise noted, this content is licensed under Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International license.