Showing posts with label research security. Show all posts
Showing posts with label research security. Show all posts

Friday, July 17, 2026

Trusted CI Report on EDUCAUSE CPPC ’26

Trusted CI released a report on our full-day workshop at EDUCAUSE CPPC on building collaborative, institution-wide approaches to research cybersecurity. You can access the report here

The team also presented a public webinar on the workshop and this report. You can view the recording here

The team will also be presenting at the 2026 EDUCAUSE Annual Conference. If you have requests for future research security training topics, contact the team at info@trustedci.org.  

Wednesday, July 15, 2026

Trusted CI Releases NSF Critical Controls Mapping to the CIS Controls

Trusted CI released a resource mapping the NSF Critical Controls to the CIS Controls (v8.1). This resource was designed to help organizations understand and apply the NSF Critical Controls by highlighting the equivalent CIS Safeguards, alongside Trusted CI commentary. This mapping represents Trusted CI’s interpretation and translation of the NSF language used for each control.  



Looking Ahead

Trusted CI plans to add mappings for other established cybersecurity standards, such as NIST SP 800-171, as well as case studies of how institutions are implementing these controls. If you have any questions or think you might be a good candidate for a case study on implementing an NSF Critical Control, please reach out to info@trustedci.org.


Screenshot of mapping for NSF3


Friday, May 15, 2026

Trusted CI Hosts the First Regional Cybersecurity Summit at the University of Alabama








Last month, Trusted CI partnered with the University of Alabama to host the first Regional Cybersecurity Summit in Tuscaloosa. The two-day agenda (April 21st - 22nd) was modeled off our Annual Summit, with a focus on inviting a group of attendees located in the southeastern region of the US.

The two days of content were split between workshops and a poster session on day 1, and a plenary session of talks and panel discussions on day 2. Highlights on day 1 include training sessions on: security log analysis, Zeek network security monitoring software, software security, security tabletop exercises, quantum machine learning, and a Scholarship for Service panel. The day ended with a welcome reception and poster session. 

Tuesday, March 17, 2026

Welcome to Our New Advisory Committee Members!

In support of our expanded mission, Trusted CI is thrilled to welcome Damian Clarke, Ph.D. and Manish Parashar, Ph.D. to the Trusted CI Advisory Committee. Dr. Clarke rejoins the Advisory Committee after 2 years serving as special advisor to the program. His experiences in leadership positions at universities and university consortia, particularly in the U.S. Southeast, will be particularly valuable to Trusted CI as it works to further engage with institutions of higher education to determine how best to address the cybersecurity requirements of research security. Dr. Parashar brings a wealth of experience related to national cyberinfrastructure and artificial intelligence. We look forward to his input on our new AI initiatives and helping to define our future strategy to support the community with the secure use of AI technologies.

In addition to Drs. Clarke and Parashar, we wish to express our gratitude to the entire Advisory Committee for the guidance they provide and for sharing their time and insights to maximize the value of Trusted CI’s programs to the communities we serve.

Monday, February 9, 2026

SPHERE and Trusted CI Collaborate to Strengthen Research Security

In February 2026, the NSF-funded Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE) project hosted a week-long cybersecurity residency with Trusted CI, the National Science Foundation’s Cybersecurity Center of Excellence. The residency marked an important milestone in SPHERE’s transition from construction toward sustained operations, strengthening an already robust security posture through formal alignment with widely recognized best practices.

SPHERE previously partnered with Trusted CI during the 2024 Trusted CI Framework Cohort, where the SPHERE team adopted the Trusted CI Framework and completed a structured self-assessment of its cybersecurity program against the framework’s 16 Musts. The Musts identify the concrete, critical requirements for establishing and running a competent cybersecurity program. That cohort experience validated SPHERE’s foundational approach to security, while also highlighting an important next step: formally adopting a baseline cybersecurity control set and performing a gap analysis between that baseline and SPHERE’s existing controls. The Trusted CI Framework specifically recommends adoption of a recognized baseline control set in its Must 15.

Building on that groundwork, the February 2026 residency embedded Trusted CI staff directly with the SPHERE DevOps team for one intensive week at the USC Information Sciences Institute in Marina del Rey, CA. Working side by side, the teams aligned SPHERE’s existing cybersecurity controls with the CIS Critical Security Controls (CIS Controls v8), which SPHERE has now formally adopted as its baseline control set.

This work focused on mapping SPHERE’s existing practices to the CIS Controls, identifying gaps, and prioritizing future improvements. The residency also strengthened SPHERE’s alignment with NSF’s evolving expectations for research security, including closer alignment with the NSF Research Infrastructure Guide (RIG) and its set of 14 critical controls. By grounding its program in both the Trusted CI Framework and the CIS Controls, SPHERE gained a common language for documenting controls, reduced reliance on ad hoc decision-making, and ensured consistency with broadly accepted community standards.

During the residency, Trusted CI conducted site visits at all the sites that host SPHERE physical infrastructure. They visited the ISI and USC server rooms, and met virtually with SPHERE co-PIs and their teams at Northeastern University Khoury College of Computer Sciences and the University of Utah Kahlert School of Computing. These discussions helped ensure that SPHERE’s distributed architecture is protected in a coordinated and consistent manner across institutions.

With the gap analysis complete, SPHERE is well positioned to prioritize future security investments as it moves toward full operations. The outcome directly supports SPHERE’s core mission of enabling realistic and reproducible experimentation without compromising trust in the facility or the science it supports. Achieving this mission requires protecting the underlying infrastructure from attack and security breaches, safeguarding the integrity and availability of shared resources, and ensuring strong isolation and protection of researcher experiments and data.

SPHERE will share lessons learned from the residency with the broader Trusted CI Research Infrastructure Security Community (RISC), contributing back to the ecosystem that helped shape its approach.

 

SPHERE (Security and Privacy Heterogeneous Environment for Reproducible Experimentation) is an NSF Mid-scale Research Infrastructure-1 project (Award #2330066) spanning USC Information Sciences Institute, Northeastern University, and the University of Utah. SPHERE provides a public testbed for reproducible science and experimentation tailored to the needs of cybersecurity and privacy researchers and educators.

Trusted CI, the NSF Cybersecurity Center of Excellence, is supported by the National Science Foundation under Interagency Agreement #A2407-049-089-064206.0. Trusted CI’s mission is to enable trustworthy NSF science by partnering with cyberinfrastructure operators to build and maintain effective cybersecurity programs, publishing resources for the broader NSF community, and advancing the processes, tools, and knowledge needed to secure research progress.

Friday, January 16, 2026

Trusted CI Mission Expanding to Address Cybersecurity for Research Security and AI

As we enter into 2026, Trusted CI leadership is excited to share some important updates regarding the expansion of our mission. We will begin addressing the needs of higher education institutions as they relate to research security and the cybersecurity requirements of NSPM-33. In addition, we will begin major new strategic initiatives focused on the secure use of AI in research. Both of these changes represent significant expansion of our mission and also the number of institutions that we will directly impact.

Our core mission continues to be supporting the security of research through cybersecurity excellence.  This includes our existing community of NSF Major Facilities and Mid-Scales, a community we remain committed to supporting. We will continue to host the annual NSF Cybersecurity Summit and will expand the program to include topics related to research security and AI. In addition, this year we’ll host our first Regional Summit in partnership with the University of Alabama.

In support of our expanded mission, we will begin partnering strategically with the SECURE Center and NAIRR-related projects. SECURE Center’s expertise in research security complements our cybersecurity expertise, and we will partner to provide comprehensive support to academic institutions who are navigating compliance with emerging NSPM-33 cybersecurity requirements. We will partner with NAIRR stakeholders to support their cybersecurity program needs. 

We have established our plans for 2026 inclusive of our new objectives. This includes pivoting our cohort model to new communities focused on research security in 2026.

We look forward to engaging with new community members in the coming year! Please send any comments or questions to info@trustedci.org