Giter Site home page Giter Site logo

redcapgovernancedocs's People

Contributors

davidbard avatar thomasnwilson avatar wibeasley avatar

Stargazers

 avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

redcapgovernancedocs's Issues

Security Discussions in other Universities

In the spirit of #8, I'd like to collect material about security and keep it in this thread, along with any accompanying comments that we have.

Also, there may be issues relevant to

  • Plugin Security in Issue #8, and
  • API Security in Issue #10.

Important: Remember that this is a GitHub repository, and is visible to people outside OUHSC. Please don't post any material that has PHI, or material that can help someone get a step closer to REDCap PHI, such as usernames, tokens, or even URLs

Audit Log from list IRB usernames

From https://github.com/OuhscCcanMiechvEvaluation/MReporting/issues/314

Build upon the the previous audit log. But instead of just listing names, have it compare against a list from the IRB that has two columns: (a) IRB Project ID, and (b) OUHSC username.

  1. Create a simple report for IRB Auditing (do tonight)
  2. Draft a proposed mechanisms for how a reviewer looks at the flagged cases (ie, usernames who accessed a REDCap project, but weren't on the IRB list given to us). (do in the next few days)
  3. Look for precedence set by other universities for this auditing mechanism.

The proof of concept for now will assume everyone has an OUHSC username. When REDCap moves to one of the open standards (for collaboration with other universities), we'll need to expand this somehow.

REDCap Testing (Brainstorming)

@wibeasley @bard1536

With regards to upgrading the instances of REDCap:

What do we want to test?
How do we want to test them?

Ideas that David and I discussed:

Creating bogus projects in the devbox. After REDCap has been upgraded, test these bogus projects to ensure that all features are working correctly.

Have a standard "new" project to create in the new version on the devbox.

Testing the superuser features (deleting a project etc)

What are your thoughts?

--Ignore me--

I created this issue (ie, "Meeting 2013-10-28") in the wrong repository

Include FERPA

Include FERPA in documents.

And go back in time and aska question on the REDCap Google groups that sounds something like this:

FERPA Compliance Statement
We are needing to add a FERPA compliance statement to our REDCap documentation. Does anybody have an example that they could share?

Plugin Discussions in other Universities

@thomasnwilson, there seems to be some good materials/discussions on the REDCap Forums and Wiki. Let's post them in this issue as we see them. I'm going to close it, but keep posting when you see something.

Also, if you're looking for issues related to Plugin security, please scan Issue #10.

Important: Remember that this is a GitHub repository, and is visible to people outside OUHSC. Please don't post any material that has PHI, or material that can help someone get a step closer to REDCap PHI, such as usernames, tokens, or even URLs

Create protocol for regular upgrade of REDCap components

spun off from Thomas's post:

On the big meeting yesterday (eg, Wilson, Thomas N (HSC); Beasley, William H.; Moore, Randy W. (HSC); Steward, Shad (HSC); Mack, Cliff W (HSC); Miller, Tony D. (HSC); Bard, David E. (HSC)), Randy, Shad, and other supported a protocol that would update the REDCap components every 6 months, with ad hoc updates whenever there was a serious security update.

There are several components that need to be updated, such as

  1. REDCap code itself
  2. MySQL
  3. phpMySQL (ie, a web GUI for MySQL; a relevant forum discussion)
  4. PHP
  5. Linux (which is Red Hat, I think)

@thomasnwilson, are there any extra layers that need to be installed/updated explicitly, such as JDBC/ODBC drivers?

REDCap address change and aliases

@thomasnwilson

I'd like for our REDCap address name to change from miechvprojects.
to redcapbbmc.

Also, please check to see if we can use aliases for individual projects. Be sure to ask what happens when an alias is appended with a private survey tag.

Thanks.

BBMC Logos

@wibeasley

Where are the BBMC logos stored? Also, can you direct me to the code you used to create the logos? I am needing the specific color codes. You can just e-mail me directly. I would have e-mailed you, but you're still in e-mail timeout.

Enumerate routes for an audit flag

After the REDCap governance meeting last week, Randy suggested that I list all the ways a user might be flagged during the audit. We'll Then asses the probabilty of that occurring. And then assess the potential damage of each. He generously said he'd help with the last two, after I create a list.

-Duplicate- ignore this issue

In the spirit of #8 and #10, I'd like to collect material about REDCap API and keep it in this thread, along with any accompanying comments that we have.

Important: Remember that this is a GitHub repository, and is visible to people outside OUHSC. Please don't post any material that has PHI, or material that can help someone get a step closer to REDCap PHI, such as usernames, tokens, or even URLs

LDAP + table-based

@wibeasley

We need to discuss a plan to "flip the switch" from LDAP to LDAP+table-based. There is a project coming online in early January that needs the table-based authentication.

Let me know when would be a good time to talk over the break.

API Discussions in other Universities

In the spirit of #8 and #10, I'd like to collect material about REDCap API and keep it in this thread, along with any accompanying comments that we have.

Also, if you're looking for issues related to API security, please scan Issue #10.

Important: Remember that this is a GitHub repository, and is visible to people outside OUHSC. Please don't post any material that has PHI, or material that can help someone get a step closer to REDCap PHI, such as usernames, tokens, or even URLs

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.