Closeout instructions should be established at the beginning of each project. The instructions will determine whether any project data needs to be retained at closeout, and for what duration.
If the project data does not have outlined handling instructions in the contract language and/or data management plan,the project freezing option below will be followed by default, with data being retained for 1 year before deletion. PIs will be notified appropriately
When project closeout requires retention, there are two data storage options currently available:
Projects can be retained within the CUIE when necessary. All accounts with access to the project and project data will be deactivated and/or removed from the project team. Project Tagging may be used to prevent accounts that must remain active from accessing the data. The inactive accounts will prevent any access to the data, thus freezing it in place.
When only trivial amounts of data need to be retained, it may be more appropriate to encrypt the data using FIPS 140-2 Validated methods, and download the data for storage in a secure location. All decryption keys are to be maintained in a separate location from the data. Appropriate storage locations for the encrypted files are: UMD Box, Network Storage. Any other storage locations must be approved by ECO, ORA and DIT.
Upon completion of a CUIE project, if your research agreement or Data Use Agreement (DUA) requires any destruction/sanitization of data, the following offboarding procedures should be followed:
Per Tera Insights, deletion in tiCrypt is equivalent to cryptologic sanitization. When a user deletes a file from their vault, the system deletes the key file used to decrypt it. This very long randomly generated key is the only way to decrypt the file. Since the drives contain random noise without any decryption keys, there is no need to officially sanitize. Any attempts of data sanitation do not do anything because there is no longer a decryption key.
Any physical data drives in the CUIE that must be removed will be shredded according to the DIT provided Device Destruction Service.