Stay Informed & Inspired

User Attestation & Training Requirement

To align with the National Institutes of Health (NIH) data security requirements for controlled-access data, Research Infrastructure Services (RIS) has implemented a formal annual security attestation and training in Workday for all users and has now assigned it to all users as of  June 30, 2026. 

This approach has been approved by the Regulated Research Subcommittee and developed in collaboration with the OVCR to ensure alignment with institutional and sponsor expectations.

❓ Why

This process establishes compliance with NIST 800-171 security controls. Rather than limiting these controls strictly to specific systems, RIS is implementing them across its entire infrastructure. This proactive measure strengthens the overall security posture for all university research. 

The attestation and 10-minute security training will maintain a consistent, auditable security baseline in our shared environment, even if your work does not interact with controlled-access data.

❗️ Impact

The RIS environment itself is not changing; while we are fulfilling this compliance requirement, there will be no other changes to how users work within RIS outside of completing this attestation, unless they interact with controlled-access data. Failure to complete this Workday task by the September 30, 2026, deadline will result in restricted or terminated access to RIS resources.

🗓️ Timeline

  • Workday Assignment – 2 tasks – June 30, 2026
    • Task 1 – RIS User Attestation Document – Due September 30, 2026 
    • Task 2 – Insider Threat Awareness Training – Due September 30, 2026 
  • Between June 30 and September 30, users will be reminded of incomplete tasks and encouraged to complete them by the deadline.

Once assigned, please complete the attestation and training in Workday to ensure uninterrupted access to the RIS environment.

Use this guide to learn how to log in and complete the attestation and training.

Have questions? Contact us at the RIS Service Desk.

FAQ

What is changing for RIS users?

To comply with NIH data security requirements, Research Infrastructure Services (RIS) has introduced an annual security attestation and training requirement for all users.

Why do I have to do this if I don’t work with controlled-access data?

RIS is implementing NIST 800-171 security controls across its entire infrastructure, not just specific systems. This proactive approach ensures a consistent, auditable security baseline that protects all university research within our shared environment.

What happens if I miss the deadline?

Failure to complete both Workday tasks by the deadline will result in restricted or terminated access to RIS resources.

Will this change how I daily interact with the RIS environment?

No. The RIS environment itself is not changing. Aside from completing these two Workday tasks, your day-to-day workflow will remain exactly the same (unless you interact directly with controlled-access data).

How do I complete these requirements?

Log into Workday to find your assigned tasks. You can reference the provided guide to walk you through the login, attestation, and training process.