Information Security · Teachers College
Research Security Templates
Ready-to-use templates and forms for the most common research security and compliance needs — reviewed by the TCIT Information Security team.
The templates below are designed to help you meet TC's research security requirements without starting from scratch. Each one has been reviewed by the Information Security team. If you're not sure which template applies to your situation, visit the Secure My Research page, check our Research Security FAQ, or follow the Researcher Pathway for step-by-step guidance.
Plans & Documentation
Templates you create, complete, and submit as part of an IRB protocol, grant application, or compliance requirement.
Data Security Plan Template
DOCXUse this template to document how your research data will be stored, accessed, shared, and destroyed. Commonly required for IRB submissions and grant proposals, and recommended for any project handling Confidential or Restricted data.
Research Data Management Plan (DMP)
DOCXFor IRB submissions and federal grant applications (NIH, NSF, IES, NEH). Documents the full lifecycle of your research data — from collection through archiving or destruction. Many federal funders now require a DMP as part of grant applications.
IRB Confidentiality of Data — Sample Language
DOCXTCIT Information Security-reviewed sample language for the Confidentiality of Data section of your IRB protocol submission. Includes five scenarios: anonymous data, identifiable data, HIPAA/PHI, AI tool use, and remote/video-based data collection.
AI Use Disclosure Template for IRB Protocols
DOCXSample language for researchers disclosing AI tool use in TC IRB protocol submissions. Includes four use-case scenarios — qualitative analysis, transcription, literature review, and AI-assisted data collection — plus participant consent language and a researcher checklist.
Data Use Agreement (DUA) Template
DOCXA starting point for data use agreements with external partners or institutions. All DUAs must be reviewed by the Office of the General Counsel before being signed — this template streamlines that review process.
Agreements & Checklists
Templates for tracking, documenting, and maintaining data security practices throughout your project — and at its conclusion.
Research Confidentiality Agreement
DOCXRequired for research team members — including RAs, student researchers, and temporary affiliates — who will access sensitive or identifiable research data. Covers non-disclosure, device security, incident reporting, and data return obligations. One agreement per team member.
Research Team Data Security Checklist
DOCXA recurring checklist for use at research team kickoff and at regular intervals throughout your project. Covers pre-collection setup, data handling practices, team training, and end-of-project offboarding. Completed checklists serve as documentation for audits and IRB renewals.
Research Team Security Training Log
DOCXUse this log to document security training completed by all research team members throughout the project lifecycle. Includes a required trainings reference list covering TC, IRB, HIPAA, NSF, DOE, and export control requirements. Retain completed logs with project records.
End-of-Study Data Checklist
DOCXFor use when a project concludes, a team member departs, or the data retention period ends. Covers team offboarding, retention period management, and step-by-step secure data destruction. Completed checklists should be retained as project documentation.
International Research Data Transfer Checklist
DOCXFor TC researchers collecting data abroad or sharing with international collaborators. Covers legal and regulatory review, data security controls for international transfer, receiving party information, and participant consent considerations. Contact InfoSec and OGC before any international data transfer.
Forms & Requests
Forms to submit to an office or service when reporting an incident or requesting access on behalf of a research team member.
Research Data Security Incident Report
DOCXUse this form to document a suspected or confirmed data security incident involving research data. Includes incident type, data involved, immediate actions taken, and an InfoSec review block. Early and complete reporting is required under TC policy — report first, complete this form after contacting InfoSec.
Temporary Research Affiliate Request Form
FORMFor faculty sponsoring a recently graduated student's continued access to TC systems and data. This request goes to HR first, with final sign-off from Information Security. See the Researcher Pathway for the full process.
Research Security FAQ
WEBAnswers to the most common research security questions — covering data storage, IRB compliance, AI tools, incident reporting, temporary research affiliates, and more.
Don't see what you need?
TCIT Information Security · 212-678-3300, Opt. 2