Why it matters
A secure workflow extends from instruments and transfer paths to analysis dependencies, reference data, and backups.
Where the boundary sits
An instrument's network connection, an analyst's workstation, and a shared storage account can all influence the same genomic result. Looking at only the final database leaves the earlier processing path unexplained. A review should follow the data through the systems that create and transform it.
Cybersecurity does not answer every governance question. A properly authenticated researcher may still propose a use outside the permitted purpose of a collection. Access controls and research authorization should therefore be connected, while remaining distinct decisions that can be reviewed separately.
Sources
- PRIMARY SOURCE NIST: Genomic Data Threat Modeling