Written and maintained by CASRAI Editorial Board
Last updated
Cybersecurity is the discipline of protecting computing systems, networks, and the information they hold from attack, misuse, and failure — and of recovering when protection fails. It is two things at once. It is an academic and engineering research field, with its own theory, methods, conferences, and funding programs. It is also an operating obligation: any university, laboratory, or research hospital that holds data, runs instruments, or administers federal awards has to run a cybersecurity program, and a growing share of grant and contract terms spell out what that program must contain. This guide explains both sides, with an emphasis on what a research institution actually has to do. It is educational and defensive in intent: it describes how protection is organized, not how to attack anything.
What Cybersecurity Means
There is no single universal definition, but a widely cited one appears in the NIST glossary, drawn from the Committee on National Security Systems (CNSS) glossary: cybersecurity is the “prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.” Three of those properties are usually taught as a unit, often called the CIA triad:
- Confidentiality — information is disclosed only to those authorized to see it. A leaked set of identifiable participant records is a confidentiality failure.
- Integrity — information and systems are changed only in authorized ways. Silently altered instrument output or a tampered dataset is an integrity failure, and for research it is arguably the most damaging kind, because it corrupts results without anyone noticing.
- Availability — systems and data can be used when needed. A ransomware attack that locks a laboratory out of its own data is an availability failure.
The NIST definition adds authentication (confirming who or what is acting) and nonrepudiation (an action cannot later be convincingly denied). Cybersecurity is not the same as privacy, although the two overlap: privacy is about appropriate use of personal information, while security is about protecting the systems and data that make appropriate use possible. It also differs from physical security, from safety (see AI Safety vs. AI Security for how that distinction plays out in one domain), and from the older, narrower term “information security,” which is often used as a near-synonym but historically emphasized information in any medium, not only digital systems.
Cybersecurity as a Research Field
Treated as an academic subject, cybersecurity sits inside computing but draws heavily on mathematics, engineering, economics, law, and the behavioral sciences. It studies an adversarial setting: unlike most engineering problems, someone is actively trying to make the system fail, so results have to hold against an intelligent opponent rather than against random error. That shapes what counts as a result. A security claim is only as strong as the threat model it is stated against, and much of the field’s methodological discipline is about being explicit regarding what an attacker can and cannot do. For the parent discipline, see What Is Computer Science?
Major Subfields
- Cryptography — the mathematics and engineering of encryption, digital signatures, key exchange, and related protocols. It is the most theory-heavy part of the field, with formal proofs of security under stated assumptions, and has its own professional society, the International Association for Cryptologic Research (IACR).
- Systems and software security — how operating systems, browsers, compilers, and applications can be built or analyzed so that flaws are rarer and less exploitable, including memory safety, program analysis, fuzzing, and isolation techniques.
- Network and distributed-systems security — protecting communication and coordination between machines, including authentication protocols, intrusion detection, and resilience to denial of service.
- Hardware and embedded security — vulnerabilities and defenses at the processor, firmware, and device level, including side channels and trusted execution.
- Privacy-enhancing technologies — methods such as differential privacy and secure multiparty computation that allow data to be analyzed or shared while limiting what is revealed about individuals.
- Usable security and human factors — why people bypass controls, fall for phishing, or misconfigure systems, and how to design protections that people will actually use.
- Cyber-physical and application-specific security — security of systems that control the physical world, such as industrial controls, vehicles, and implanted or connected medical devices. CASRAI covers one such area in What Is Medical Device Cybersecurity?
- Security of machine learning and AI systems — both attacks on models and the use of models in defense, an area that overlaps with the frontier-AI-safety material elsewhere on this site, starting with What Is AI Safety?
- Security economics, policy, and law — incentives, liability, disclosure norms, and regulation.
How the Field Works: Methods
Security research uses several recurring methods, and understanding them helps when reading a paper or reviewing a proposal.
- Threat modeling — stating what assets matter, who might attack them, with what capabilities, and what the system is claimed to withstand. Almost every defensible security result begins here.
- Formal methods and proofs — mathematical arguments that a protocol or program satisfies a property under a stated model. They give strong guarantees about the model and say nothing about what the model leaves out.
- Empirical measurement — large-scale observation of real systems, such as how widely a configuration weakness is present or how quickly patches are applied.
- Vulnerability research and coordinated disclosure — finding flaws in existing software and reporting them to the vendor, with an agreed delay before public release so users can be protected. This is research with an ethical dimension, and it is why institutions increasingly expect researchers to understand disclosure norms and the legal limits on testing systems they do not own.
- Controlled experiments — including user studies of security behavior and testbeds that emulate networks or industrial systems, which allow attacks to be studied without touching production systems.
- Red-team and penetration-testing exercises — authorized, scoped attempts to defeat an organization’s defenses in order to find weaknesses before real adversaries do. The authorization and scope are what separate this from an attack.
Because security research can involve intrusive techniques, studies that involve human participants or live systems usually need institutional review and explicit authorization, and researchers handling sensitive material should follow the institution’s research-ethics process.
A Short History
Computer security became a research topic in the early decades of multi-user computing. An early-1970s U.S. Air Force study led by James P. Anderson, commonly called the Anderson report, set out the problem of securing shared computer systems. In 1975, Jerome Saltzer and Michael Schroeder published “The Protection of Information in Computer Systems,” whose design principles, such as least privilege, are still taught. Public-key cryptography was introduced in the open literature by Whitfield Diffie and Martin Hellman in 1976, and the RSA scheme followed in 1977 and 1978. The U.S. Computer Fraud and Abuse Act was enacted in 1986, amending earlier computer-crime provisions from 1984.
The 1988 Morris worm, one of the first widely disruptive internet incidents, led to the creation of the CERT Coordination Center at Carnegie Mellon University, an early model for coordinated incident response. Through the 1990s and 2000s the field expanded with the commercial internet; NIST selected the Rijndael algorithm as the basis of the Advanced Encryption Standard in 2000 and published the standard as FIPS 197 in 2001, and federal information-security management was formalized in law, notably the Federal Information Security Management Act of 2002. Since then, the scope has widened from protecting individual machines to managing organizational risk, supply chains, and the security of AI systems. For research institutions in particular, the last several years have added a new overlay: research security, discussed below.
Cybersecurity as a Research-Institution Obligation
For most readers of this site, the practical question is not what the field studies but what the institution must do. Three layers are worth separating, because they are routinely confused.
1. A voluntary risk-management framework: NIST CSF 2.0
The NIST Cybersecurity Framework (CSF) 2.0, published on February 26, 2024, is a voluntary framework for managing cybersecurity risk. Its core is organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the addition in version 2.0 and covers strategy, roles and responsibilities, policy, oversight, and supply-chain risk management. CSF is not a certification, and an institution cannot “pass” it. What it gives a research office is a shared vocabulary and a way to describe the current state of a program and a target state. CASRAI’s guide NIST Cybersecurity Framework 2.0 for a Federally Funded Research Lab walks through how it fits alongside the compliance work most research offices already do.
2. A contractual requirement: NIST SP 800-171 and CUI
NIST Special Publication 800-171 sets out security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. It is a technical standard rather than a law, and it reaches a university through a specific clause in an award, most often a Department of Defense contract or subaward, or through other agency CUI terms. Revision 2 contains 110 requirements in 14 families; Revision 3, published in May 2024, restructured the document and contains 97 requirements. Which revision applies to a given award depends on the terms of that award, so check the clause rather than assuming. Questions of scope, such as whether work qualifies as fundamental research and so falls outside CUI controls, are where institutions most often go wrong. See CASRAI’s NIST SP 800-171 and CUI in University Research, the companion guide to the SPRS score and self-assessment, and the dictionary entries for NIST SP 800-171 and Controlled Unclassified Information.
3. Research security
Research security is a distinct, policy-driven layer: protecting federally funded research from undisclosed foreign influence, misappropriation, and improper access, as set out in National Security Presidential Memorandum 33 (NSPM-33) and implemented through agency requirements. NSPM-33’s research security program elements include cybersecurity, foreign travel security, research security training, and export control training. Cybersecurity is therefore one required component of research security rather than the whole of it. See Research Security, NSPM-33 Research Security Program Requirements, and Research Security Training. Institutions outside the U.S. face parallel regimes; for the UK, see UKRI Security Management Plan and Certification Requirements.
Other standards research offices encounter
ISO/IEC 27001 is a general information-security management system standard that appears in vendor assessments and sponsor questionnaires; it is explained, with its limits for research data, in ISO 27001 for Research Data Security. Sector rules add further layers: health data brings HIPAA obligations, and connected medical devices bring FDA expectations.
Where Responsibility Sits in an Institution
A common failure is treating cybersecurity as only an IT matter. In practice the work is shared. Central IT or an information-security office operates controls and monitoring. Research administrators and sponsored-programs staff read award terms, flag security clauses at proposal and negotiation stage, and coordinate attestations and assessments. Principal investigators decide how data is handled in their own labs and are often the people closest to the instruments and data that matter. Compliance, export-control, and research-security staff connect these to legal duties. Leadership owns risk acceptance, which is what the Govern function in CSF 2.0 is about. See What a Research Administrator Does for the role most directly responsible for reading and routing these obligations.
Training and Career Paths
Cybersecurity is studied through computer science degrees, dedicated cybersecurity programs, electrical and computer engineering, mathematics (especially for cryptography), and information systems. Research careers typically run through a PhD with a systems, cryptography, or human-factors emphasis. In the United States, the NSF-supported CyberCorps: Scholarship for Service program funds cybersecurity education and workforce development in exchange for government service, and the National Security Agency, with federal partners, designates colleges and universities as National Centers of Academic Excellence in Cybersecurity. Practitioner certifications also exist, and they matter more for operational roles than for research careers.
Funders, Venues, and Societies
- Funders — in the United States, the National Science Foundation’s Secure and Trustworthy Cyberspace (SaTC) program, led by the Directorate for Computer and Information Science and Engineering (CISE) with partner directorates, is an interdisciplinary program spanning several NSF directorates that funds research aimed at a secure, resilient, and trustworthy cyber ecosystem. DARPA and other defense agencies also fund security research, and industry funding is substantial.
- Venues — four conferences widely regarded as among the field’s top tier are the IEEE Symposium on Security and Privacy, the ACM Conference on Computer and Communications Security (CCS), the USENIX Security Symposium, and the Network and Distributed System Security (NDSS) Symposium. Cryptography has its own venues through the IACR, whose flagship conferences are Crypto, Eurocrypt, and Asiacrypt. In this field, conference papers carry the weight that journal articles carry elsewhere.
- Societies — ACM SIGSAC, the IEEE Computer Society’s security and privacy technical community, USENIX, and the IACR.
The field also has its own norms for research assessment. Because top conferences are the main outlet, citation metrics and journal-based evaluation behave differently from, say, biomedicine, which matters when promotion or grant reviewers are not from computing.
Frequently Asked Questions
What is the difference between cybersecurity and information security?
The terms overlap heavily and are often used interchangeably. Information security is the older and broader term, covering information in any form, while cybersecurity focuses on digital systems and networks. Standards such as ISO/IEC 27001 use the information-security framing.
Is NIST CSF 2.0 mandatory for universities?
No. It is voluntary guidance. Some sponsors or state agencies may reference it in their terms, so check the specific award or policy. It is not a certification.
When does NIST SP 800-171 apply to a research project?
When an award or contract includes a clause that requires it, typically because the work involves CUI. Work that qualifies as fundamental research is generally treated differently, but the determination is made per project and per award. See the NIST SP 800-171 guide.
Is research security the same as cybersecurity?
No. Research security is the broader policy concern of protecting research from foreign interference and misappropriation. Cybersecurity is one required element of a research security program, alongside foreign travel security and training elements.
Who funds cybersecurity research?
In the U.S., chiefly NSF (notably SaTC), DARPA and other defense agencies, and industry. Funding structures differ elsewhere.
Do researchers need permission to test the security of a system?
Yes. Testing systems without authorization can create legal liability regardless of intent. Researchers should obtain explicit authorization, follow coordinated disclosure practice, and consult their institution’s counsel and research-ethics office before starting.
What should a principal investigator do first?
Read the security-related clauses in the award, ask the sponsored-programs office whether CUI or export-controlled data is involved, and involve the institution’s information-security office before data is collected, not after.
Where Cybersecurity Fits Among the Sciences
Cybersecurity is a branch of computing with strong links to mathematics, engineering, and the social sciences. For a map of how disciplines relate, see CASRAI’s overview of the branches of science.








