Managing Software and Code#
Role: Researcher / Data Analyst and Data Engineer
The Secure Data Enclave (SDE) provides approved software, programming languages, development tools, and packages for research and analysis. SDE VMs do not have internet access. Software and package installation is controlled by Northwestern IT.
Licensed software, such as Stata or MATLAB, may be considered for installation when there is an approved research need. The Data Engineer has the permissions to install approved software, but no installation should occur without Northwestern IT approval and coordination.
Code and other files entering or leaving the SDE must follow the approved ingress and egress processes. SDE systems log ingress and data movement activity. The research group is accountable for unauthorized ingress associated with their environment.
Action |
Responsibility |
|---|---|
Use software and packages already available in the SDE |
Researcher / Data Analyst and Data Engineer |
Request licensed software such as Stata or MATLAB |
Researcher / Data Analyst or Data Engineer |
Approve and coordinate software installation |
Northwestern IT |
Install approved licensed software |
Data Engineer, with IT approval and coordination |
Ingress approved code or other files |
Data Engineer through the approved ingress process |
Develop and modify code in the SDE |
Researcher / Data Analyst and Data Engineer |
Export code from the SDE |
Data Engineer through the approved egress process |
Warning
Ingressing packages into the SDE is not an approved method for adding R or Python packages to the environment.
The following workflows apply throughout the SDE:
Activity |
Approved workflow |
|---|---|
Install licensed software |
Request → IT review and approval → approved files enter through ingress → malware scan → Data Engineer installs with IT coordination |
Bring code into the SDE |
Approved ingress source → Data Engineer ingresses files → malware scan → files move to the appropriate SDE project |
Export code from the SDE |
Researcher or Data Engineer prepares code → approved egress process → Data Engineer completes transfer → code is downloaded after approval |
Important
All ingress and data movement activity is logged. The research group is responsible for ensuring that only authorized files and data enter or leave its environment.
Use software already available#
Role: Researcher / Data Analyst and Data Engineer
SDE VMs include approved software, programming languages, R and Python packages, and development tools.
See Available Software in the SDE to find out what is already available.
If the software or package you need is already available, you can use it without submitting a request.
If an R or Python package is not available, do not attempt to bring it into the SDE. Request the package by submitting a request ticket to Northwestern IT.
Request licensed software#
Role: Researcher / Data Analyst and Data Engineer
Licensed software such as Stata or MATLAB may be considered for installation when it is needed for approved research.
Before submitting a request, confirm that the software:
Supports Ubuntu Linux Operating System
Can operate without direct internet access
Meets the CPU, memory, and storage requirements of the target VM
Has any required license or activation information available
Check the VM’s configuration by following these steps.
Submit a software request#
Role: Researcher / Data Analyst and Data Engineer
Submit a request through the resource request process.
Include:
Software name
Version, if applicable
Link to the vendor’s official page
Why the software is needed
Which SDE VM requires the software
License or activation requirements
Any known Ubuntu or system requirements
IT will review the request and determine whether the software can be approved for use in the SDE.
Important
Approval is required before the software is installed. The Data Engineer may have the technical permissions needed to perform the installation, but those permissions do not replace IT approval.
The same approval requirement applies when installing software on the Data Ops VM or a Workspace Project VM.
Provide installation files when requested#
Role: Researcher / Data Analyst and Data Engineer
If IT requests an installer or other installation file, follow the instructions in the request ticket.
Do not install the software yourself.
The Data Engineer will use the approved ingress process to bring the required files into the SDE.
After the files have completed the required ingress process and IT has approved the installation, the Data Engineer may install the software on the approved VM.
Warning
Do not proceed with an installation based only on a software request, a downloaded installer, or your access to the VM.
The Data Engineer’s ability to install software is a technical capability, not an authorization to install it. Wait for IT approval and coordination.
Ingress code into the SDE#
Role: Data Engineer
The Data Engineer can ingress approved code and other files into the SDE.
The SDE does not provide direct access to GitHub, public package repositories, or other external code repositories. Code from an external source must enter through the approved ingress process.
The Data Engineer can use the Data Ingress Project and the approved ingress infrastructure to bring files into the SDE. Approved code may then be moved to the appropriate project, such as the Data Ops Project or a Workspace Project.
Request a new ingress source#
Role: Researcher / Data Analyst and Data Engineer
If code needs to come from a source that is not already configured for ingress, submit an ingress request ticket.
The source must be approved and configured before the Data Engineer uses it to bring files into the SDE.
Danger
Do not download, clone, copy, or otherwise bring code or other files into the SDE outside the approved ingress process.
This rule applies even when the Data Engineer has access to the target VM or has the technical ability to transfer files directly.
Ingress and data movement activity is logged. The research group is accountable for unauthorized ingress associated with its project if identified during an audit.
Request architecture changes for software#
Role: Researcher / Data Analyst and Data Engineer
The default SDE VM configuration denies inbound and outbound connections. Some software may require network access for licensing, authentication, APIs, or other external services.
Any software installation that changes the underlying SDE architecture requires Information Security Office (ISO) approval. Examples include:
Opening ports or allowing internet access
Modifying firewall rules
Allowing software to retrieve tokens, authentication, or licensing information
Allowing connections to external APIs, services, or portals
These requests are handled by Northwestern IT. The request and approval are documented in a ticket for audit purposes.
Provide information for ISO review#
Role: Researcher / Data Analyst and Data Engineer
When requesting software that requires an architecture change, provide enough information for IT and ISO to complete their review without additional follow-up.
For example, provide:
Purpose: What will the library be used for?
External service: What service or portal will it access, and what will it retrieve?
Connection direction: Inbound, outbound, or bidirectional?
Data leaving the enclave: What information will be sent outside the SDE?
Data retrieved: What information will be retrieved?
Data sensitivity: Will any restricted or sensitive data leave the SDE?
Also provide the software/package name and version, target VM, external service or domain, required ports or protocols, and authentication or licensing requirements when applicable.
Important
The research group’s responsibility is to provide complete and accurate information for the request. Northwestern IT handles the technical review, ISO approval, and any resulting architecture changes.
Work with code in the SDE#
Role: Researcher / Data Analyst and Data Engineer
Once the approved code is inside the SDE, users can develop and modify it on the appropriate VM.
Researcher / Data Analysts generally work in their Workspace Project VMs.
Data Engineers perform processing, cleaning, and analysis work in the Data Ops VM.
You can:
Create and modify code on the appropriate VM
Use Git for local version control
Store working repositories on the VM
Save important code to an approved project bucket
Important
Keep important code in an approved project bucket rather than relying on the VM as the only copy. Code stored only on a VM may be lost if the VM is deleted.
Export code from the SDE#
Role: Researcher / Data Analyst and Data Engineer
Code can leave the SDE only through the approved egress process.
Step |
Role |
Action |
|---|---|---|
1 |
Researcher / Data Analyst |
Place the code in the designated Egress Dataprep bucket in the Data Lake Project. |
2 |
Researcher / Data Analyst |
Submit an egress request through the egress process. |
3 |
Data Engineer |
Review the request and complete the required approval and transfer process. |
4 |
Data Engineer |
Transfer approved code to the Data Egress Project. |
5 |
Researcher / Data Analyst |
Download the approved code to your managed endpoint. |
Warning
Do not download, copy, or otherwise remove code directly from an SDE VM.
This applies to both Workspace Project VMs and the Data Ops VM. Code must leave the SDE through the approved egress process.