NIST Cybersecurity Framework

NIST NIST

The National Institute of Standards and Technology (NIST) is a U.S. government agency that develops standards, frameworks, and best practices to advance technology, innovation, and cybersecurity. NIST publishes a variety of cybersecurity and information security standards that may apply to research environments, with specific requirements varying based on the sponsor, contractual obligations, type of research, and sensitivity of the data involved.

For research involving sensitive data or federally regulated information (which, for example, may include data obtained from NIH database of Genotypes and Phenotypes (dbGaP) or genomic data repositories (GDS)), the University of Miami employs a risk-based approach to cybersecurity informed by the NIST Cybersecurity Framework (CSF). The CSF provides a strategic foundation for identifying, protecting, detecting, responding to, and recovering from cybersecurity threats. Depending on project-specific requirements, researchers may be required to comply with different NIST publications, agency-specific cybersecurity requirements, or contractual security obligations. The University works with researchers to identify applicable requirements and implement appropriate safeguards based on the project's risk profile and compliance needs.

The University's use, storage, processing, or transmission of Controlled Unclassified Information (CUI) in sponsored research must comply with the security requirements of NIST SP 800-171, which establish the safeguards necessary to protect CUI and meet applicable federal security and compliance obligations. Additional information about CUI is available in the FAQs below.

NIST SP 800-171 Rev3 Summary

The Graphic converts NIST SP 800-171 Revisions 3 from a list of individual security requirements into a resource-planning and responsibility-assignment framework, showing whether each control is primarily achieved through governance, technology configuration, software capability, operational security practice, or physical infrastructure. This makes it easier to communicate compliance requirements to researchers, IT leadership, and institutional stakeholders.

Through the Research Security Program (RSP), the University brings together key stakeholder offices—including Information Security, Information Technology, Research Administration, Export Control, and other institutional partners—to develop and maintain secure research environments that support compliance with federal regulations, sponsor requirements, and University policies while enabling secure and responsible research.

 

Nist v3 diagram

NIST SP 800-171 Compliance

*Note that there are various NIST SP 800 compliance standards, such as NIST 800-53 (generally used by the DOJ). If you see other NIST references besides NIST SP 800-171 in your FOA/RFA or award/contract agreement, please reach out to the ORA as soon as possible.

One of the mechanisms to achieve research security and/or export control protections for information is through NIST SP 800-171 ("NIST 800") compliance. NIST SP 800-171 is a set of standards cybersecurity established by the National Institute of Standards and Technology. The standards are guidelines for Federal agencies when entering into agreements with other organizations, when sensitive (but not classified) information may be involved in the research. Some projects require the implementation of these standards, either because of the subject matter or because the contract requires it. You are responsible for ensuring NIST SP compliance.

What do I need to do to be NIST 800 compliant?

Before you apply for a grant or contract, determine whether research requires NIST 800 compliance. The following situations generally require NIST 800 compliance:

  • Funding from the DOD, DOE, NASA, and occasionally NSF or NIH awards for more sensitive topics such as high encryption research or semiconductor research;
  • If it is clear in the FOA/RFA that the research restricts publication or restricts foreign nationals from working on the project;
  • If the project is Federally-funded and you will receive or generate Controlled Unclassified Information (CUI);
    • A good rule of thumb is that if you receive any items that are export controlled, or information is export controlled or subject to a federal rule on privacy of the information (e.g. health care information, legal information, financial information, or trade secrets), chances are you are receiving or generating CUI.
  • Regardless of funding source, if the project involves ITAR items or information; or
  • If the terms of the agreement require it, even without CUI as part of the research.

If you need to be NIST 800 compliant:

  • During application: Budget for the use of the secure cyber environment for each specific project that requires it.  Sponsored programs includes this budget item in the budget template.  Costs are partly based on computing needs. If you have questions, please reach out to the Office of Research Administration for assistance with estimating those costs.  
  • During award:  
    • Ensure compliance with the NIST 800 standards, UM's System Security Plan (SSP), and your project Technology Control Plan.  
    • Report any incident to the ORA and Information Security, according to the SSP and/or your TCP (whichever is sooner).  
  • Post award:  
    • Maintain data in the secure environment, as required; or  
    • Destroy data and tangible items, as required by contract.  Note that appropriate destruction must follow NIST 800 standards.  

Getting Started

Open All Tabs
  • Budget Guidance for Secure Enclave Services

    University of Miami Secure Enclave Cost Estimation  

    Researchers planning to use the University of Miami Secure Enclave to meet NIST and Department of Defense (DoD) cybersecurity requirements should use the information below to estimate project costs. Costs are based on the required cybersecurity level and the computational resources needed for the project.  Additional endpoint and device security costs may apply ; investigators should consult University IT Security to obtain project-specific estimates.  

    NIST Cybersecurity Levels and Secure Enclave Costs  

    The Secure Enclave provides varying levels of security controls to support federal cybersecurity requirements and protect sensitive research data.

    NIST
    Level
    Data
    Type
    Security
    Framework
    Alignment
    CMMC
    Equivalent
    Typical
    Research
    Activities
    Initial
    Year
    Cost
    Annual
    Ongoing
    Cost
    1 Public / Non-Sensitive Data Basic IT Controls Below CMMC Publicly available data with no restricted information $5,000 $0
    2 Federal Contract Information (FCI) FAR 52.204-21 CMMC Level 1 Limited datasets, identifiable information, and protected data $25,000 $5,000
    3 Controlled Unclassified Information (CUI) – Moderate Risk NIST SP 800-171 CMMC Level 2 NIH controlled-access datasets such as dbGaP and NIAGADS $100,000 $50,000
    4 High-Risk / Critical DoD Programs NIST SP 800-172 CMMC Level 3 Sensitive CUI and certain federal defense contracts Contact UM IT Security

    Projects involving unique security requirements or high-risk federal contracts should consult University IT early during proposal development to determine required controls and associated costs.

    Secure Enclave Computing Resources and Pricing

    In addition to cybersecurity compliance costs, researchers may require dedicated computing resources within the Secure Enclave environment. Select the tier that best aligns with your project's storage and performance requirements.  

    Tier CPU Cores Memory (RAM) Storage Annual Cost  Monthly Cost
    Small 4 32 GB 1 TB $700 $58.33
    Medium 8 64 GB 3 TB $1,400 $116.67
    Large 16 128 GB 5 TB $3,900 $325.00
    Extra Large 32 256 GB 10 TB $5,300 $441.67

    Need Assistance?

    Researchers are encouraged to engage UM IT Security and the Office of Research Administration during proposal development to:
    • Determine the applicable NIST and CMMC requirements.
    • Estimate Secure Enclave cybersecurity costs.  
    • Identify computing and storage needs.
    • Budget for endpoint security and other project-specific compliance requirements.
    • Ensure proposal budgets adequately support federal cybersecurity obligations.


    For assistance, contact UM IT Security or the Office of Research Administration before proposal submission.

  • Submission

    Work with your department and Office of Research Administration representative to ensure that your proposal meets all of the requirements.  

Other Resources

What is Controlled Unclassified Information (CUI)?

CUI is information that the U.S. Government has determined requires protection or dissemination controls pursuant to applicable laws, regulations, or government-wide policies, but that is not classified information. CUI may be created by, owned by or shared with federal agencies and can include information provided to the University through sponsored projects, contracts, cooperative agreements, subawards, or data use agreements.

Examples of CUI may include:

  • Controlled-access genomic and other protected research datasets
  • Export-controlled technical information
  • Certain proprietary or sensitive government information
  • Information related to critical infrastructure, cybersecurity, or national security interests
  • Other categories identified in the Federal CUI Registry

When the University receives, stores, processes, or transmits CUI, it must protect the information in accordance with applicable federal requirements. This often includes compliance with NIST SP 800-171, which establishes security requirements for safeguarding CUI in nonfederal information systems and organizations.

Click these links for additional CUI resources and the CUI Registry to review the different categories of CUI in the National Archives.

The National Institute of Standards and Technology (NIST) Cybersecurity and Privacy Program develops and maintains an extensive collection of standards, guidelines, recommendations, and research on the security and privacy of information and information systems.

Click these links for additional  NIST SP Resources  and the latest revision of  NIST SP 800-171 .

 

Although the latest revision of NIST 800 is revision 3, the DOD is has released a memo regarding deviation to continue using revision 2. For new agreements with the DOD, if you do not see a DOD deviation clause in your agreement, ask Sponsored Programs and your DOD contact to get a deviation included in the agreement.

For assistance with any of these activities, questions related to NIST 800 compliance, or questions about research security in general, reach out to the Research Security & International Engagement team at RSIE@miami.edu or 305-243-6339.

Frequently Asked Questions

Open All Tabs
  • What is NIST Cybersecurity Framework?

    NIST Cybersecurity Framework provides a common language and structure for understanding and improving security across teams, leadership, and partners. 

    • Helps protect sensitive data and research systems 
    • Improves compliance readiness and audit posture 
    • Provides a consistent approach across departments 
    • Supports risk-based decision making 

    For additional information:  

  • Is NIST required?

    The NIST Cybersecurity Framework (CSF) 2.0 is generally voluntary and is designed as guidance to help organizations manage and reduce cybersecurity risk, not as a universal certification or one-size-fits-all checklist.

    That said, NIST-aligned practices may effectively become necessary when a sponsor, contract, data type, or research environment requires specific cybersecurity safeguards. UM’s research security materials also note that research-related cybersecurity is tied to evolving federal requirements, including expectations under NSPM-33.  

  • Who should use NIST?

    NIST CSF 2.0 is intended for organizations of all types and sizes, not just critical infrastructure or large enterprises. NIST specifically positions the framework as a tool for organizations to understand, assess, prioritize, and communicate cybersecurity risk. 

    At the University of Miami, this can include researchers, study teams, research administrators, IT staff, leadership, and support units that handle sensitive data or support research systems. UM describes research security as a shared institutional responsibility involving faculty, staff, students, and administrators.

  • What problem does NIST solve?

    NIST CSF gives organizations a common structure and language for managing cybersecurity risk. It helps organizations identify what needs protection, improve safeguards, detect issues sooner, respond effectively, and recover more efficiently through the six functions of Govern, Identify, Protect, Detect, Respond, and Recover. 

    It also supports more consistent decision-making across technical and non-technical teams by helping organizations prioritize risk, improve communication, and align cybersecurity with broader organizational risk management. 

    For UM, that matters because research security spans cybersecurity, disclosure, international collaboration, export control, and federal requirements, all of which benefit from a shared risk-based approach. 

  • Is it required for my study?

    Not every study is required to formally adopt NIST CSF by name. However, your study may still need NIST-aligned safeguards if it involves sensitive data, sponsor-specific security terms, restricted systems, or other federal research security expectations.

    At UM, cybersecurity expectations increase when research involves PHI, PII, non-public University data, secure storage needs, restricted access, encryption, or approved institutional systems. UM’s data handling guidance specifically calls for strong safeguards around storage, access, encryption, and approved platforms for sensitive data.

    If the study is federally funded, includes sensitive research data, or is connected to a secure research environment, it is a good idea to confirm requirements with the appropriate UM offices before data collection or system access begins. This is especially important because federal research security expectations are expanding, including training and institutional compliance requirements.

  • How do I know if my project needs enhanced cybersecurity protection?

    Projects may need enhanced protections when they involve non-public University data, PHI, PII, sensitive research data, external sponsor requirements, or secure computing environments. UM’s data handling guidance and research security materials both emphasize using the right security level for the research being conducted.

  • What kinds of data usually trigger higher cybersecurity expectations?

    Higher expectations commonly apply to PHI, PII, confidential or non-public University information, and research data that must be stored in controlled or approved systems. UM specifically directs employees and research teams to safeguard these data types and avoid unapproved storage methods. 

  • Does working with PHI change what I need to do?

    Yes. UM states that employees with access to PHI must complete HIPAA Privacy & Security Awareness training, and PHI should not be stored on unapproved mobile devices or unsanctioned platforms.

  • Does international collaboration affect cybersecurity expectations?

    Yes. Research security guidance emphasizes that international collaboration can create additional risk and should be managed in a way that protects research integrity, intellectual property, and sensitive systems while preserving open science.

  • Who at UM can help me determine what level of cybersecurity my project needs?

    UM’s research security program, Information Security Office, and related compliance and IT resources are intended to help the University community navigate cybersecurity expectations and apply the right safeguards for research systems and data. 

  • What if my sponsor references federal cybersecurity requirements?

    If a sponsor references federal cybersecurity or research security expectations, those requirements should be reviewed carefully because they may impose project-specific obligations beyond UM’s standard baseline practices. UM’s research security and cybersecurity pages note that federal requirements are evolving and may affect researchers directly.

  • Is cybersecurity only an IT issue?

    No. NIST CSF 2.0 is designed for use across the organization, and UM similarly frames research security as a shared institutional responsibility involving leadership, administration, researchers, and technical teams. 

  • What training should my team complete?

    Training depends on the type of data, sponsor requirements, and systems involved. At a minimum, UM points users to cybersecurity awareness resources, and projects involving PHI require HIPAA-related training; federally funded research may also trigger separate research security training requirements.  

    Contact the Research Security and International Engagement (RSIE) team for guidance on applicable training requirements and compliance obligations. Reach us at RSIE@miami.edu or 305-243-6339.

  • What should I do if I think a research system or dataset has been compromised?

    Potential incidents should be reported promptly through UM’s information security resources so the University can investigate, contain risk, and support response and recovery. UM’s Information Security Office and incident-related policies are part of that support structure.  

  • Why is UM using a framework like NIST CSF?

    A framework like NIST CSF helps UM apply a risk-based, consistent approach across different schools, departments, and research environments. That is especially useful in a university setting where research security intersects with data protection, compliance, international engagement, and sponsor expectations.  

Top