LabKey Server has a group- & role-based security model. This means that each user of the system belongs to one or more security groups, and can be assigned different roles (combinations of permissions) related to resources the system. When you are considering how to secure your LabKey site or project, you need to think about which users belong to which groups, and which groups have what kind of access to which resources.

A few best practices: - Keep it simple. - Take advantage of the permissions management tools in LabKey. - Use the rule of least privilege: it is easier to expand access later than restrict it. - Prioritize sensible data organization over folder structure. - Iterate when necessary. - Test after every change.

Tutorial

- Tutorial: Security

Topics

- Best Practices for System Security - Configure Permissions: Setting permissions for a group on a project or folder. - Security Groups: Assigning users to security groups. - Security Roles Reference: The permission levels available to be granted to users. - User Accounts: Adding users to your LabKey site and managing their accounts. - Authentication: Configure authentication providers. - Test Security Settings by Impersonation: Testing security settings for users in various groups. - Virus Checking: (Premium Feature) - Best Practices: Security Scans: (Available only to Premium Edition subscribers)

You may not need to understand every aspect of LabKey security architecture to use it effectively. In general the default security settings are adequate for many needs. However, it's helpful to be familiar with the options so that you understand how users are added, how groups are populated, and how permissions are assigned to groups.

Related Topics

- Content Security Policy - Compliance - (Premium Features) Comply with security and auditing standards, such as FISMA and HIPAA. - Manage Study Security - Security management specific to studies and datasets. - Securing Portions of a Dataset (Row and Column Level Security) - How to expose specific portions of a dataset, without granting access to the dataset as a whole. - Export and Import Permission Settings - Export and Re-import security settings to another environment. - Web Application Security - Describes the most important web application security vulnerabilities and how to protect against script injection.

Was this content helpful?

Log in or register an account to provide feedback


previousnext
 
expand allcollapse all