SPSS Security Safeguards

Tags SPSS

IBM SPSS - SECURITY SAFEGUARDS

How to Use SPSS Safely with Sensitive University Data

Area Safeguard How to Apply Why It Matters Applies To
Uploaded Image (Thumbnail)


 Device Usage

Use SPSS on appropriately secured university-managed machines.
  • Use university-managed devices only
  • Enable device encryption
  • Keep OS and security software up to date
  • Use MFA and strong passwords
Protects data from unauthorized access or device compromise.
Device desktopDevice
(Desktop)
Sensitive dataSensitive
Data
Store sensitive data in approved storage locations and minimize identifiers.
  • Save data in university-approved storage
  • Do not use personal cloud or USB drives
  • Apply de-identification/data minimization where appropriate before analyzing PII/PHI
Reduces risk of data exposure and supports compliance.
Device desktopDevice
(Desktop)
Access controlAccess
Control
Limit access to authorized users only.
  • Use unique user IDs and role-based access
  • Restrict access to datasets and outputs
  • Use MFA for system access
Ensures only authorized individuals can view or use sensitive data.
Device desktopDevice
(Desktop)
EncryptionEncryption
Use encryption to protect data at rest.
  • Ensure device and storage encryption
  • Use SPSS file encryption for data files, output files, and syntax files when needed
Protects data if files or devices are lost, stolen, or accessed without authorization.
Device desktopDevice
(Desktop)
Temporary and auto-recovery filesTemporary /
Auto-Recovery
Files
Secure SPSS temporary and Auto-Recovery locations.
  • Auto-Recovery is enabled by default
  • Verify recovery file location
  • Ensure temporary folders are on secure, access-restricted storage
SPSS creates temporary and recovery files that may contain sensitive information.
Device desktopDevice
(Desktop)
Audit loggingAudit
Logging
Maintain audit logging for sensitive data activities.
  • Enable logging where available
  • Track access, modification, and export of sensitive datasets
  • Review logs regularly
Supports monitoring, investigations, and regulatory compliance.
Device desktopDevice
(Desktop)
Web and cloud usageWeb-Based /
Cloud Usage
Review web or cloud usage separately before using regulated data.
  • Use only approved cloud services
  • For processing PHI, ensure HIPAA-ready services and a Business Associate Agreement (BAA) with IBM
IBM applies additional HIPAA requirements when applicable IBM cloud services are used with PHI.
Web cloudWeb / Cloud
(IBM Cloud)
AI Output AssistantAI Output
Assistant
Review AI Output Assistant separately before use with regulated data.
  • AI Output Assistant is powered by IBM watsonx.ai
  • Feature can be disabled by administrators in restricted environments
It introduces functionality beyond standard SPSS Desktop processing and should therefore be separately evaluated for regulated data.
Web cloudWeb / Cloud
(watsonx.ai)

Always follow university policies and applicable regulatory requirements(PII, PHI, FERPA, HIPAA) when using SPSS.