Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Universities can protect research without treating international collaboration as a threat: keep research open by default, assess specific projects for concrete risks, and apply only safeguards proportionate to those risks. NIST’s research-security framework and G7 guidance offer a practical basis for doing that, while legal and funder requirements remain specific to each jurisdiction and award.

What research security means for open science

Research security is the set of practices used to protect research, researchers, and research institutions from risks such as inappropriate interference, loss of intellectual property, or misuse of research. It is not a reason to close research automatically. NIST’s Research Security Office says the purpose is “not to stifle collaborative research, but rather to enable and safeguard it.” Its framework is intended to support international science while taking relevant security concerns into account.

Open science means making research inputs, outputs, and processes available with minimal restrictions. The G7 says research should be accessible when there is no justification for keeping it closed, while recognizing that dissemination may sometimes carry adverse ethical, geopolitical, or national-security implications. Its best practices describe openness and security as complementary rather than opposing aims.

The practical question is therefore not whether a university should be “open” or “secure.” It is whether a particular collaboration, activity, or information-sharing decision presents a substantiated risk—and what limited measure would address it without unnecessarily restricting sound research.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to review a collaboration without closing it by default

NIST’s framework covers researchers, international travel, international collaborations, requests for products, services, or software tools, and funding opportunities. It encourages institutions to consider a project’s purpose and potential outcomes, relevant information, and indicators tied to the engagement. The sequence below translates those categories and G7 proportionality principles into a usable institutional review; it is a synthesis, not a workflow prescribed verbatim by either source.

  1. Define the engagement and its scientific purpose. Record who is collaborating, what the project aims to accomplish, and what each participant is expected to contribute.
  2. Identify what will be shared or accessed. Consider research knowledge, data, equipment, software, services, facilities, travel, and funding—not only publications or formal partnership agreements.
  3. Assess plausible risks using project-specific facts. Consider potential misuse, undue influence, or loss of intellectual property. Distinguish evidence about this engagement from assumptions based on a person’s nationality, institutional affiliation, or field alone.
  4. Consult the right institutional specialists. Depending on the issue, involve research-security, legal, export-control, privacy, or ethics offices. Check applicable laws, funder terms, and institutional policies.
  5. Choose the least restrictive effective safeguard. A measure should address an identified concern while preserving collaboration and access wherever closure is not justified. Possible responses will depend on the risk and applicable rules; the cited guidance does not establish one universal safeguard for every case.
  6. Record the rationale and revisit it when circumstances change. Document the evidence, decision, and reason for any restriction. Reassess if the project’s scope, partners, funding, access, or risk changes.

How to judge whether a safeguard is balanced

Universities can use these questions to compare proposed measures and check whether a decision protects research without imposing avoidable barriers.

  • Risk basis: Is the measure tied to a documented concern about this project, or applied categorically?
  • Proportionality: Does it address the identified risk while limiting unnecessary restriction?
  • Openness and scientific merit: Does it preserve access and collaboration where there is no justified reason to restrict them? G7 principles say scientific merit and excellence should continue to guide research partnerships.
  • Rights and fairness: Does the review protect privacy, civil liberties, academic freedom, and equal treatment? NIST says its framework is designed to protect privacy and civil liberties and should be implemented without xenophobia, prejudice, or discrimination.
  • Operational fit: Can the institution apply the approach consistently across people, travel, collaboration terms, information, tools, and funding?
  • Legal and funder fit: Does the decision reflect the institution’s jurisdiction and the conditions of the specific award?

NIST characterizes its approach as integrated, mission-focused, risk-balanced, scalable, and non-intrusive. Those qualities help explain why a sound program should not rely on blanket restrictions when a narrower response can address the evidenced concern.

What U.S. and UK institutions should check

Research-security obligations vary by jurisdiction and funder. The examples below are not universal legal rules; institutions should verify current requirements against the relevant award and applicable law.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

United States

NIST’s current Research Security Office guidance, accessed in 2026, says that institutions receiving more than $50 million per year in federal science and engineering funding must have a research security plan and program under NSPM-33. NIST also says institutions below that threshold that engage in international research collaborations should still take steps to secure research. See the NIST Research Security Office for the U.S.-specific guidance.

United Kingdom

UKRI says it added two trusted research and innovation conditions for organizations receiving its funding in April 2024. It points recipients to related UK guidance, including export controls, the National Security and Investment Act, and the Academic Technology Approval Scheme. Award recipients should confirm the current conditions and whether they apply to their specific award through UKRI’s trusted research and innovation guidance.

The UK Research Collaboration Advice Team (RCAT), a government-academia collaboration, offers institutions a first point of contact about national-security risks linked to international research and tailored risk-management guidance. Its role is described on the RCAT page.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What universities should avoid

  • Do not equate international collaboration with risk. Review the engagement and relevant facts rather than relying on broad categories or assumptions.
  • Do not restrict access without a reason. G7 guidance supports access when there is no justification for keeping research closed.
  • Do not treat security review as separate from research integrity and rights. Privacy, civil liberties, fair treatment, and scientific merit belong in the decision.
  • Do not assume one country’s threshold or funder conditions apply everywhere. Confirm the rules that govern the institution and award.

NIST’s research-security FAQ frames the goal as facilitating open science and international collaboration while protecting national and economic security interests. That is a useful institutional standard: protect the work where there is a concrete reason, and preserve openness where there is not.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.