CRS CRS Research Data Management & Security 2 — Questions and Answers
Question 1: What does the NIH Data Sharing Policy primarily require of funded researchers?
- That all NIH-funded datasets be destroyed after 5 years
- That researchers make final research data available for sharing where appropriate (Correct answer)
- That only de-identified data may be statistically analyzed
- That all data be stored exclusively on NIH-managed servers
Correct answer: That researchers make final research data available for sharing where appropriate
The NIH Data Sharing Policy requires researchers receiving significant NIH funding to make their final research data available to the broader scientific community where appropriate.
Question 2: What is the key difference between data confidentiality and data anonymization?
- They are the same concept and may be used interchangeably
- Confidentiality restricts access to identifiable data; anonymization permanently removes identifiers (Correct answer)
- Anonymization is legally required by all federal agencies; confidentiality is optional
- Confidentiality applies only to paper records, not electronic data
Correct answer: Confidentiality restricts access to identifiable data; anonymization permanently removes identifiers
Confidentiality protects identifiable data through access restrictions and policies, while anonymization permanently removes identifying information so re-identification is impossible.
Question 3: In research data management, what is a 'chain of custody'?
- A multi-step funding approval process
- A documented chronological record of who accessed and handled data at each stage (Correct answer)
- A ranked list of study participants by enrollment date
- A statistical method for validating data accuracy
Correct answer: A documented chronological record of who accessed and handled data at each stage
Chain of custody is a documented record of every person who has accessed, transferred, or handled research data, ensuring data integrity and accountability.
Question 4: Which type of data storage is most appropriate for the long-term preservation of research data?
- Personal laptop hard drives
- Institutional email servers
- Institutional repositories or certified data archives (Correct answer)
- Portable USB drives kept in a locked drawer
Correct answer: Institutional repositories or certified data archives
Institutional repositories and certified data archives provide secure, long-term storage with appropriate metadata standards, access controls, and preservation protocols.
Question 5: What is the primary security risk of accessing research data over open public Wi-Fi networks?
- Significantly slower data processing speeds
- Unauthorized interception of unencrypted data transmissions (Correct answer)
- Increased cloud storage costs
- Automatic violations of IRB compliance requirements
Correct answer: Unauthorized interception of unencrypted data transmissions
Open Wi-Fi networks lack encryption, making data transmissions vulnerable to interception by unauthorized third parties through man-in-the-middle attacks.
Question 6: What is metadata in the context of research data management?
- A specialized type of multivariate statistical analysis
- Structured information that describes, explains, or provides context about a dataset (Correct answer)
- Encrypted backup files created during data transfer
- Raw participant survey responses before coding
Correct answer: Structured information that describes, explains, or provides context about a dataset
Metadata is structured information that describes a dataset's content, format, provenance, and context, making the data easier to find, understand, and reuse.
What does the NIH Data Sharing Policy primarily require of funded researchers?