nanalLabs Blog

← Blog

How a "security project" research notebook differs — classification levels, protected zones, removal approval

2026-09-17research notebooksecurity projectnational core technologyregulation

Most guidance you find by searching "how to keep a research notebook" assumes an ordinary government R&D project. But once a project is tied to a national core technology, or an institution's own review classifies it as a "security project," the way the notebook itself gets managed changes. Here's what actually changes, with the regulatory basis behind each point.

What counts as a security project, and who decides

A security project is one where leaking the R&D results outside the institution would cause substantial technical or financial harm, so extra security measures are required. That determination comes from two directions.

technology appears on the list designated and publicly notified by the Ministry of Trade, Industry and Energy under the Act on Prevention of Divulgence and Protection of Industrial Technology. The National Intelligence Service's overview of national core technology covers what qualifies and how designation works.

core technology involved, the principal investigator or a dedicated department can review a project at the application or execution stage and designate it a security project on its own.

This designation isn't something an individual researcher decides — it's finalized by the institution's security management office (an industry-university cooperation foundation's security team, a dedicated research security officer, etc.) under the Common Security Management Guidelines for National R&D Projects.

It starts with the management number — how it compares to a regular notebook

A regular research notebook also gets registered in a management ledger and assigned a management number, but a security project stacks several layers on top of that.

Regular projectSecurity project
Management numberLedger registration is enoughLedger registration + a separately tracked classification marking
Storage locationA lab or department officeA designated protected zone (access-controlled, with entry logged)
AccessApproval as an authorized viewerRestricted to people already cleared to enter the protected zone
Removal (including portable media and laptops)No special restrictionRequires prior removal approval and a logged removal record
Electronic storageRegular systems or cloud services are fineEncryption required, a separate backup system, and restrictions on external cloud storage

The core idea is treating the notebook itself — paper or electronic — as controlled information. In a security project, the moment it leaves the protected zone is the moment that gets controlled. The requirement to have entry/exit procedures for laptops and external drives comes from the same logic.

When a classification level is assigned — protection period and retention period attach separately

Among security projects, ones directly tied to national security and formally classified under the Security Business Regulation go one step further. Classified material is graded Level I, II, or III by content and sensitivity, and the original and every copy must carry a notice statement specifying the protection period, handling method, and retention period (Security Business Regulation, Article 14). The full text is available on Korean Wikisource.

One thing to watch: the retention period can never be shorter than the protection period. Separate from the general 30-year retention period for ordinary research notebooks, classified material must be kept for at least the protection period its classification level requires. The retention period's start date follows the same general rule set by the Enforcement Decree of the Act on Public Records Management — January 1 of the year following the year the matter was closed out — with the classification-level protection period layered on top of that same baseline. Exactly how many years each level's protection period runs is often spelled out in an institution's own internal rules, so check with your institution's security regulations before applying any of this.

Can you still use an electronic notebook and timestamping on a security project?

A common question is whether security projects are simply barred from using electronic notebooks. What the guidelines actually restrict isn't electronic record-keeping itself — it's leaking through an uncontrolled channel. Even the government's own standard manual for R&D security management only requires encryption, storage inside a protected zone, and a separate backup system for sensitive research data; it doesn't prohibit electronic records outright.

In practice, though, two things need to stay clearly separate.

  1. Where it's stored — uploading the original to an external

commercial cloud service is likely to conflict with security-project requirements. An internal system the institution has approved, or a server inside the protected zone, comes first.

  1. How you prove it hasn't been altered — separate from where it's

stored, proving later that "this record existed with this exact content on this date" requires its own evidence, such as a hash seal or a timestamp. Controlling where something is stored and proving that what's inside hasn't changed since are two different problems — and the higher the classification level, the easier it is to neglect the second one.

What to check right now

technology, or has gone through an institutional security review?

kept in a designated protected zone?

when laptops or external storage media leave the site?

institution has approved — not with the original sitting on an external commercial cloud service?

statement showing the protection period and retention period?

Whether a project counts as a security project, and what classification level applies, is decided by your institution's dedicated security office, not by an individual researcher. This post lays out the general regulatory structure; before applying any of it, check your institution's own research security rules together with the Common Security Management Guidelines for National R&D Projects.

nanalStamp — automatically seals your Obsidian notes the moment they settle and anchors the proof into Bitcoin, so anyone can verify your records are tamper-free. About the service · 75 free record kits