A
Acceptable Use Policy — AUP
A policy that defines how users are permitted to use an information
system, research infrastructure, digital service or computing resource.
It may specify permitted and prohibited activities, security
requirements, responsible use of computing capacity, handling of data,
consequences of misuse and procedures for reporting suspected
violations.
Do not confuse with:
Access policy. An access policy
determines who may obtain access and under what conditions; an AUP
governs behaviour after access has been granted.
Access policy
A policy defining who may access a resource or service, the eligibility
conditions, available access levels, applicable restrictions and the
procedure for requesting, approving, modifying or withdrawing access.
An access policy may also define user groups, resource limits,
authentication requirements, selection procedures, costs and the
responsibilities of users and providers.
See also:
Acceptable Use Policy
,
Terms of Use.
Accountability
The obligation of a person, organisational unit or governance body to
explain and justify its decisions, demonstrate that assigned
responsibilities have been fulfilled and accept scrutiny of the
resulting actions and outcomes.
Accountability normally requires documented authority, identifiable
responsibilities, records of decisions, reporting arrangements and
mechanisms for review or corrective action.
Do not confuse with: responsibility. Responsibility
concerns performing an activity; accountability concerns answering for
whether the required result was achieved appropriately.
Back to Browse terms ↑
C
Change management
A controlled process for planning, assessing, approving, implementing
and reviewing changes to services, systems, configurations, policies or
operational procedures.
Its purpose is to introduce necessary changes while limiting disruption,
security risks, unintended consequences and adverse effects on users or
dependent services.
See also:
Risk management,
Service continuity management
.
Communication Officer
The designated EOSC Node role responsible for coordinating
communication, dissemination and stakeholder information concerning
the Node and its participation in the EOSC Federation.
The role may include maintaining communication channels, coordinating
public information, supporting community engagement and ensuring that
relevant Federation information reaches the Node's users, providers and
participating organisations.
See also:
Node Coordinator,
EOSC Node Coordinators Committee
.
Competence Centre
An organisational unit, collaborative structure or expert network that
concentrates and coordinates knowledge, skills, training, consultation
and support within a defined thematic, institutional, regional or
national scope.
In Open Science and research data management, a Competence Centre may
support researchers and institutions through guidance, training,
consultations, reusable resources, community coordination and access to
specialist expertise.
A Competence Centre may operate a helpdesk, but its functions are
broader than responding to individual support requests.
See also:
Helpdesk,
User support network.
Compliance
The condition of meeting applicable legal, regulatory, contractual,
policy, security, ethical or standards-based requirements.
Compliance should be supported by documented controls, assigned
responsibilities, monitoring, evidence and procedures for addressing
identified nonconformities.
See also:
Accountability,
Policy,
Risk management.
Cybersecurity Officer
The designated EOSC Node role responsible for coordinating
cybersecurity matters affecting the Node and its interaction with the
EOSC Federation.
The role may coordinate security contacts, incident communication,
implementation of security requirements, risk assessment and
cooperation with technical teams or computer security incident
response functions.
Designation of this role does not remove the security responsibilities
of service providers, system administrators or participating
organisations.
See also:
Information security management
,
Incident management.
Back to Browse terms ↑
D
Data controller
A natural or legal person, public authority, agency or other body that
determines why and how personal data is processed.
The controller is responsible for ensuring that the processing has an
appropriate legal basis, that data-protection principles are followed
and that the rights of data subjects can be exercised.
Two or more organisations may be joint controllers when they jointly
determine the purposes and means of processing.
See also:
Data processor,
Data Protection Officer
.
Data curator
A specialist who reviews, organises, documents and improves research
data or a data publication package so that it can be understood,
validated, preserved, published and reused.
Curation may include checking files and formats, improving metadata,
documenting provenance, verifying identifiers, reviewing README and
manifest files, recording quality information and preparing data for
repository deposit.
The curator supports the quality and usability of the package but does
not normally verify the scientific correctness of every research
result.
See also:
Data steward,
Repository manager.
Data governance
The system of decision-making authority, policies, roles,
responsibilities and oversight used to control how an organisation or
collaboration manages, protects, shares and derives value from data.
Data governance may cover data quality, access, security, privacy,
metadata, retention, ownership claims, stewardship, interoperability
and compliance.
Do not confuse with: data management. Governance
determines authority and rules; data management implements activities
under those rules.
Data management support
Organised assistance provided to researchers and research teams in
planning, organising, documenting, protecting, storing, publishing,
preserving and sharing research data.
Support may be delivered through consultations, training, templates,
reviews, repository assistance, technical services, guidance materials
and referral to legal, ethical or information-security specialists.
See also:
Data steward,
User support.
Data manager
A person responsible for coordinating or performing operational data
management activities for a project, research group, facility,
database or organisation.
Activities may include organising data flows, applying naming and
versioning conventions, controlling access, coordinating transfers,
maintaining documentation, checking data quality and preparing data
for analysis or publication.
The exact boundary between data manager and data steward varies
between organisations.
See also:
Data steward,
Data curator.
Data owner
An organisational role assigned authority and accountability for
decisions concerning a defined collection or category of data.
The data owner may approve access rules, quality expectations,
retention requirements, classifications and permitted uses, while
operational tasks are delegated to data stewards, managers or system
administrators.
Important: the term does not necessarily establish
legal ownership, copyright or the status of data controller under
data-protection law. Its meaning must be defined in the applicable
institutional policy.
Data processor
A natural or legal person, public authority, agency or other body that
processes personal data on behalf of a data controller and according
to the controller's documented instructions.
The responsibilities of the processor must be defined through a
contract or another applicable legal instrument.
See also:
Data controller,
Legal/Privacy Officer
.
Data Protection Officer — DPO
An independent data-protection function that advises an organisation
on its obligations, monitors compliance with applicable
data-protection rules and acts as a contact point for data subjects and
supervisory authorities.
Appointment of a DPO is required only in circumstances defined by
applicable legislation. The DPO must be able to perform the role
independently and without receiving instructions concerning the
exercise of the DPO's tasks.
Do not confuse with:
Legal/Privacy Officer
. The latter is an operational role within an EOSC Node and is not
automatically the institution's legally designated DPO.
Data steward
A professional who supports researchers and organisations in
implementing appropriate research data management and FAIR data
practices before, during and after a research project.
A data steward connects research practice with institutional
policies, funder requirements, standards, repositories, metadata,
infrastructures and specialist support.
Data stewards may work at institutional, disciplinary, project,
infrastructure or research-group level and may specialise in policy,
research processes, data curation or technical infrastructure.
See also:
Embedded data steward
,
Data stewardship.
Data stewardship
The responsible planning, oversight and practical care of data
throughout its lifecycle so that the data remains appropriately
managed, protected, documented, accessible and reusable.
Data stewardship combines policies, professional expertise,
infrastructure, standards and day-to-day practices. It is therefore
broader than the work of any single data steward.
See also:
Data governance,
Data management support
.
Back to Browse terms ↑