English

Design choices for productive, secure, data-intensive research at scale in the cloud

Cryptography and Security 2019-09-17 v2

Abstract

We present a policy and process framework for secure environments for productive data science research projects at scale, by combining prevailing data security threat and risk profiles into five sensitivity tiers, and, at each tier, specifying recommended policies for data classification, data ingress, software ingress, data egress, user access, user device control, and analysis environments. By presenting design patterns for security choices for each tier, and using software defined infrastructure so that a different, independent, secure research environment can be instantiated for each project appropriate to its classification, we hope to maximise researcher productivity and minimise risk, allowing research organisations to operate with confidence.

Keywords

Cite

@article{arxiv.1908.08737,
  title  = {Design choices for productive, secure, data-intensive research at scale in the cloud},
  author = {Diego Arenas and Jon Atkins and Claire Austin and David Beavan and Alvaro Cabrejas Egea and Steven Carlysle-Davies and Ian Carter and Rob Clarke and James Cunningham and Tom Doel and Oliver Forrest and Evelina Gabasova and James Geddes and James Hetherington and Radka Jersakova and Franz Kiraly and Catherine Lawrence and Jules Manser and Martin T. O'Reilly and James Robinson and Helen Sherwood-Taylor and Serena Tierney and Catalina A. Vallejos and Sebastian Vollmer and Kirstie Whitaker},
  journal= {arXiv preprint arXiv:1908.08737},
  year   = {2019}
}
R2 v1 2026-06-23T10:55:00.822Z