🤖 AI Summary
Clinical research management applications—such as REDCap—process highly sensitive data and face severe security threats. This work presents the first threat modeling study of REDCap that systematically integrates the MITRE ATT&CK framework with the STRIDE model. We conduct a multi-dimensional analysis of REDCap’s architecture, data flows, and security controls, evaluating its defensive capabilities against confidentiality, integrity, and availability (CIA) threats. Our analysis identifies critical vulnerabilities, including misconfigured access permissions and insecure API endpoints. Based on these findings, we propose pragmatic, usability-aware security enhancements. The study contributes a reusable, methodology-driven threat modeling approach tailored for research data management systems, along with a practice-oriented security framework. It addresses a significant gap in the literature by delivering the first systematic, holistic security assessment of Research Management Applications (RMAs), thereby advancing both theoretical understanding and operational resilience in this domain.
📝 Abstract
Research management applications (RMA) are widely used in clinical research environments to collect, transmit, analyze, and store sensitive data. This data is so valuable making RMAs susceptible to security threats. This analysis, analyzes RMAs' security, focusing on Research Electronic Data Capture (REDCap) as an example. We explore the strengths and vulnerabilities within RMAs by evaluating the architecture, data flow, and security features. We identify and assess potential risks using the MITRE ATT&CK framework and STRIDE model. We assess REDCap's defenses against common attack vectors focusing on security to provide confidentiality, integrity, availability, non-repudiation, and authentication. We conclude by proposing recommendations for enhancing the security of RMAs, ensuring that critical research data remains protected without compromising usability. This research aims to contribute towards a more secure framework for managing sensitive information in research-intensive environments.