Welcome to Holly
Working in Holly is very different from Longleaf or Sycamore. If you have experience with the Secure Research Workspace (SRW), many of these concepts and patterns will be familiar.
Holly uses an Enclave approach; all work with regulated data must be conducted within an enclave, which sets hard boundaries for access to data and other capabilities. Data from one enclave cannot be reached from another, even for a user who belongs to both enclaves.
Technical controls prevent users from taking many actions one may be accustomed to in other platforms such as Longleaf. For example, there is no access to the internet from a login host, nor a compute node because all data ingress/egress is a highly controlled, logged, and audited process. Everything is denied by defafult; exceptions must be risk reviewed and approved. Different enclaves may have different capabilities as the protection obligations and risk tolerance for a given project drive any necessary or appropriate deviations from baseline security controls.
Go To Holly AI/HTC Cluster Documentation (onyen required): holly docs
Why does Holly work the way it does?
Regulated data can take many forms. Platforms and environments for working with regulated data must meet an increasing array of security and compliance documentation requirements; "SecOps" is a convenient term for reference (security operations).
SecOps includes technical controls that prevent users of the platform from doing certain things. It also includes maintaining, via regular risk assessment and review, documentation describing details of the platform and how it measures up against a list of security controls as defined in various security control frameworks.
Protection Obligations are specific and detailed requirements that must be met by a platform to satisfy the needs of a particular organization, data provider, funding partner, etc. An Internal Protection Obligation is one that is derived from UNC-CH policies and procedures for handling regulated data. The definition of UNC-CH internal protection obligations are documented in the Information Security Controls Standard IT policy, also known as the Minimum Security Standard, or MSS. MSS is the default security control framework for IT platforms hosting or interacting with regulated data at Carolina.
External protection obligations are ones that are derived from sources outside of UNC-CH, such as a funding agency or data provider. These are often written into contracts and grants, or they can be broad agency-wide requirements. They can be as simple as an IT-best-practices requirement in the form of an NDA, or as stringent as the controls framework used to protect US Federal IT systems hosting PII and PHI, as is the default categorization for any regulated data coming from a NC state agency as per the NC DIT Statewide Information Security Policies.
Which control framework guides Holly compliance and why?
Holly is designed and maintained in accordance with the NIST 800-53 R5 Security and Privacy Controls for Information Systems and Organizations.
Holly is designed to meet the following security objectives as defined in FIPS 199:
{(confidentiality, Moderate), (integrity, Moderate), (availability, Low)}
with an overall system impact level of Moderate.
The availability security objective is low due to the research nature of this service.
UNC-CH internal protection obligations (MSS-HIGH) are considered to be met when a system successfully maintains a NIST 800-53 Moderate compliance regime.