—BACKGROUND: Information Security is impor- tant for e-Science research groups and other small organisations that design and operate science gateways and virtual research environments, especially when such environments are being used for (bio)medical research. We propose a novel method to do risk assessments: MISRAM, the Model-based Information Security Risk Assessment Method. It uses an information architecture model, a method to assign values to information assets and IT components, and a method to calculate risks. The output of MISRAM is a ranked list of risks and a list of actionable tasks to solve the main issues. METHODS: MISRAM was applied as a test case to an e- Science research group at a Dutch research hospital. Meetings and surveys were used to create and evaluate lists of information assets and IT components. One meeting was used to create a list of practical task recommendations. RESULTS: Good insight into the information architecture and security problems of the IT infrastructure was gained. Also the participating group members confirmed that the identified security issues were realistic. CONCLUSIONS: Our approach raises awareness about se- curity among the developers and operators of e-Science environments. It also gives insight in how the technical architecture affects information security. Traditional questionnaires are an important part of any risk assessment, and MISRAM’s inclusion of such generic questionnaires is an important aspect to create an integrated information security risk assessment.
European laws on privacy and data security are not explicit about the storage and processing of genetic data. Especially whole-genome data is identifying and contains a lot of personal information. Is processing of such data allowed in computing grids? To find out, we looked at legal precedents in related fields, current literature, and interviews with legal experts. We found that processing of genetic data is only allowed on distributed systems with specific security measures, both technical and organizational. Informed consent, although important, offers no substitute for such requirements.