Most guidance you find by searching "how to keep a research notebook" assumes an ordinary government R&D project. But once a project is tied to a national core technology, or an institution's own review classifies it as a "security project," the way the notebook itself gets managed changes. Here's what actually changes, with the regulatory basis behind each point.
What counts as a security project, and who decides
A security project is one where leaking the R&D results outside the institution would cause substantial technical or financial harm, so extra security measures are required. That determination comes from two directions.
- Whether it involves a national core technology — whether the
technology appears on the list designated and publicly notified by the Ministry of Trade, Industry and Energy under the Act on Prevention of Divulgence and Protection of Industrial Technology. The National Intelligence Service's overview of national core technology covers what qualifies and how designation works.
- The institution's own security review — even without a national
core technology involved, the principal investigator or a dedicated department can review a project at the application or execution stage and designate it a security project on its own.
This designation isn't something an individual researcher decides — it's finalized by the institution's security management office (an industry-university cooperation foundation's security team, a dedicated research security officer, etc.) under the Common Security Management Guidelines for National R&D Projects.
It starts with the management number — how it compares to a regular notebook
A regular research notebook also gets registered in a management ledger and assigned a management number, but a security project stacks several layers on top of that.
| Regular project | Security project | |
|---|---|---|
| Management number | Ledger registration is enough | Ledger registration + a separately tracked classification marking |
| Storage location | A lab or department office | A designated protected zone (access-controlled, with entry logged) |
| Access | Approval as an authorized viewer | Restricted to people already cleared to enter the protected zone |
| Removal (including portable media and laptops) | No special restriction | Requires prior removal approval and a logged removal record |
| Electronic storage | Regular systems or cloud services are fine | Encryption required, a separate backup system, and restrictions on external cloud storage |
The core idea is treating the notebook itself — paper or electronic — as controlled information. In a security project, the moment it leaves the protected zone is the moment that gets controlled. The requirement to have entry/exit procedures for laptops and external drives comes from the same logic.
When a classification level is assigned — protection period and retention period attach separately
Among security projects, ones directly tied to national security and formally classified under the Security Business Regulation go one step further. Classified material is graded Level I, II, or III by content and sensitivity, and the original and every copy must carry a notice statement specifying the protection period, handling method, and retention period (Security Business Regulation, Article 14). The full text is available on Korean Wikisource.
One thing to watch: the retention period can never be shorter than the protection period. Separate from the general 30-year retention period for ordinary research notebooks, classified material must be kept for at least the protection period its classification level requires. The retention period's start date follows the same general rule set by the Enforcement Decree of the Act on Public Records Management — January 1 of the year following the year the matter was closed out — with the classification-level protection period layered on top of that same baseline. Exactly how many years each level's protection period runs is often spelled out in an institution's own internal rules, so check with your institution's security regulations before applying any of this.
Can you still use an electronic notebook and timestamping on a security project?
A common question is whether security projects are simply barred from using electronic notebooks. What the guidelines actually restrict isn't electronic record-keeping itself — it's leaking through an uncontrolled channel. Even the government's own standard manual for R&D security management only requires encryption, storage inside a protected zone, and a separate backup system for sensitive research data; it doesn't prohibit electronic records outright.
In practice, though, two things need to stay clearly separate.
- Where it's stored — uploading the original to an external
commercial cloud service is likely to conflict with security-project requirements. An internal system the institution has approved, or a server inside the protected zone, comes first.
- How you prove it hasn't been altered — separate from where it's
stored, proving later that "this record existed with this exact content on this date" requires its own evidence, such as a hash seal or a timestamp. Controlling where something is stored and proving that what's inside hasn't changed since are two different problems — and the higher the classification level, the easier it is to neglect the second one.
What to check right now
- [ ] Have you confirmed whether your project involves a national core
technology, or has gone through an institutional security review?
- [ ] If it's designated a security project, is the notebook actually
kept in a designated protected zone?
- [ ] Are prior-approval and logging procedures actually being followed
when laptops or external storage media leave the site?
- [ ] If you use an electronic notebook, is it stored on a system your
institution has approved — not with the original sitting on an external commercial cloud service?
- [ ] If material is classified, does the original carry a notice
statement showing the protection period and retention period?
Whether a project counts as a security project, and what classification level applies, is decided by your institution's dedicated security office, not by an individual researcher. This post lays out the general regulatory structure; before applying any of it, check your institution's own research security rules together with the Common Security Management Guidelines for National R&D Projects.
nanalLabs Blog