INFO: Azure Enclave Key Researcher Attestations

When provisioning and submitting access to an Azure Enclave project workspace, the project Prinicipal Investigator (PI) and staff members must attest to the following:

1. Researcher Azure Enclave Project Workspace Key Responsibilities

  • Cost Monitoring & Analysis Monitoring and planning all spending in almost real time (8-72 hr. delay) using the MS Azure Portal. This involves analyzing usage patterns, identifying trends, and planning ahead to make informed decisions and prevent budget overruns. You will be a provided a link to the Azure Portal to view these costs.
    • Cost control implementations like budgets and alerts are provided to assist you.
    • To save on Workspace (Virtual Machine) cost, the self-service ability to power down the VM is provided to you.
    • You are responsible for managing Large Language Model (LLM) cloud usage costs.
    • You WILL NOT DEPLOY NOR USE an LLM with a Deployment Type of 'Global Standard'. You will be in violation of MGB security policy if you do. Deployment Type of 'Standard' must always be used.
    • Monthly Storage, Licenses (if applicable), and Infrastructure costs are always incurred for the life of the project.
  • Billing Ensure your Azure spend billing invoice is persistently applied to the Fund Number assigned to your Workspace for the life of your project. For any invoice NOT received or does not align with your Azure spend, you must immediately:
    1. Submit a support ticket to the Cloud FinOps team. To submit, follow this KB0043810 - How To: Submit a FinOps-Reed Request to resolve the issue. Include your Azure Enclave Project Workspace Resource Group value provided in the access welcome email when workspace access is provisioned.
    2. Notify the Azure Enclave Support team by opening a Research Issue/Inquiry Request ticket and choose the Request Type dropdown value of Project Workspace Issue/Inquiry (Non-Access Related). Mention you have an Azure Enclave workspace.
  • Payment The Fund Number assigned to your Workspace must be funded to cover current and future Azure spend for the life of your project. You must immediately notify the Azure Enclave Support team for any concerns related to bill payment funding.
  • Planning Ahead Updates to your Azure Enclave Project Workspace configuration take time to implement. Submit requests 2 weeks in advance for:
    • Fund Number Updates
    • Changes To Workspace Configuration
    • Closing Your Project

Any questions or concerns with assuming these responsibilities MUST BE addressed with the Azure Enclave Support team. All responsibilities must be assumed by:

  1. The PI prior to Azure Enclave Workspace provisioning.
  2. All researchers submitting access to the workspace.

2. Enclave Data Import Compliance

The Analytics Enclave is currently NOT compliant with National Institute Of Standards & Technology (NIST) SP 800-171 security requirements. Until such time the Analytics Enclave is compliant, you MUST review the list of NIH Controlled-access Data Repositories (CADRs) located on the NIH site page: Requirements for NIH Controlled-Access Data Repositories and Users | Grants & Funding and attest to the following:

You MUST NOT IMPORT any data originating from the listed NIH CADRs into your Enclave Project Workspace.

Go to KB0045086 in the IS Service Desk