Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NIST requirements for Sage #18

Open
1 of 3 tasks
ByroneCole-SageBionetworks opened this issue Jan 11, 2023 · 0 comments
Open
1 of 3 tasks

NIST requirements for Sage #18

ByroneCole-SageBionetworks opened this issue Jan 11, 2023 · 0 comments
Assignees
Labels
CHOP CHOP task Sage Sage Bionetworks task SevenBridges SevenBridges task
Milestone

Comments

@ByroneCole-SageBionetworks
Copy link

ByroneCole-SageBionetworks commented Jan 11, 2023

  • Tom: Byrone is putting together the meeting to loop in the Sage ISO (information security officer) along with key people in INCLUDE to get a better understanding of the security required on Synapse and sign off by CHOP and SBG for what we want to achieve.

  • Jack: I would very strongly suggest starting a new Compliance agreement for Sage. We are in the final signatures of the CHOP/SBG/NHLBI agreement (2 of 3 parties have signed). That will cover the clearinghouse for SBG and NIST controls for CHOP.

  • Allison: We should be clear about this - there is a three way agreement between SBG, CHOP and NHLBI as part of the ISA. This is because SBG and CHOP systems are directly transferring data with the NHLBI account. There is no expectation that Sage/Synapse will need to directly connect to the NHLBI account and no need for any further federal agreements. However, since CHOP is now required to do NIST 800-171, we may make requests to Sage/Synapse about compliance artifacts because we anticipate the platform to be able to index and utilize CHOP S3 resources for DMC purposes. It would be good to have a three-way discussion however, because I think we would like to use similar models that SBG does for their users / systems that do not have to interconnect with federal systems. I'll bring a diagram to the meeting and hopefully that'll help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CHOP CHOP task Sage Sage Bionetworks task SevenBridges SevenBridges task
Projects
No open projects
Status: Todo
Development

No branches or pull requests

4 participants