Vendor Risk Assessments

Before a vendor or third party can access, create, or maintain university data, UT System Administration policy UTS 165 requires a security risk assessment of the vendor’s products and/or services. In addition, Texas Government Code 2054.003 (13) requires state agencies, institutions of higher education, and public community colleges entering onto or renewing contracts tied to cloud computing services comply with Texas Cyber Command’s Texas Risk and Authorization Management Program (TX-RAMP) statutory requirements beginning January 1, 2022. TX-RAMP is a framework that provides a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process agency data.

The security assessment must ascertain the following:

  • that the vendor has sufficient technological, administrative, and physical safeguards to ensure the confidentiality, security, and integrity of the data at rest and during any transmission or transfer; and
  • that any subcontractor or other third-party that will access, maintain, or create data pursuant to the contract will also ensure the confidentiality, security, and Integrity of such data while it is at rest and during any transmission or transfer.

 

Minimum Security Requirements

Request a Vendor Risk Assessment (ISOTRAQ)

 


FAQs

What do we assess?

The Information Security Office performs security assessments of software used by UT System Administration and selected system-wide initiatives. We also assess service providers, including UT System contractors (either individual or organization).If a UT System Administration account is provisioned, security awareness training is required per HB 3834. This training can be accessed here.

Why is it necessary to assess vendors and other third-parties?

We assess software and service providers in order to comply with UT System policy (UTS 165) and State policy (Texas Administrative Code 477). Additionally, weak vendor security leads to an increase in system breaches and data exposure.

When should I request a vendor risk assessment?

You should request an assessment before the decision is made to procure new software or services; or when you are renewing a contract/agreement for existing software or services that will access, process, store or create confidential or controlled university data. You should also request a new assessment if there are significant changes to the software or services being provided. For example: a previous installation of software was on premise, but the new contract is for cloud-based software. In addition, you should request a new assessment for software and services that access, transmit, or create confidential data or is considered critical infrastructure - if the previous assessment is more than one year old.

When is an assessment not required?

An assessment is not required for the software or service if:

  • An assessment has been performed in the last two years;
  • The software or service does not require access to confidential data or is critical infrastructure:
  • There has not been a significant change to the use case or data classification; and 
  • All recommendations from the previous assessment have been implemented (if applicable).

An assessment is also not required if it will only access, process, store or create published data, or is a consumption-focused service.

What about hardware, does it need to be assessed?

An assessment for a hardware purchase is only required if the hardware contains a software component that allows a login or authentication capability. For example: a firewall or an intrusion protection system.

What about Artificial Intelligence (AI) tools?

Any use of AI features should be disclosed while completing the intake form for the vendor risk assessment. AI poses various risks, such as data leakage, present wrong or incorrect statements as facts, and may use university data to train its model, which is not allowed by state law. AI should not be used with confidential or controlled data unless an exception is approved.

Should I provide any documentation for the assessment?

For requests that will use confidential data or serve a critical infrastructure role for UT System Administration, a HECVAT (Higher Education Community Vendor Toolkit) is required. The HECVAT allows us to reduce risk by ensuring that third-party vendors have the appropriate information security and privacy policies in place to protect our data. Please contact your vendor representative to obtain their current HECVAT, or if they have not completed one already, a blank one can be downloaded from EDUCAUSE's website. Additional documentation such as a vendor's information security policy, certifications (ISO 27001, SOC 2, Cloud Security Alliance, etc.) or implementation guides are appreciated and allow us to better understand the intended use of the product/service you would like to purchase as well as the third-party vendor.

What is considered "Critical Infrastructure"?

This refers to our physical and virtual assets, systems, and networks that are so essential for UT System Administration business operations. Some examples include, but are not limited to, routers, firewalls, switches or data centers.

What if an assessment has already been performed for the software I want to use?

If you would like to use software that is already being used by another department, we still require a separate request to be submitted. While the software may be the same, the intended use case, enabled features or modules, and the type of data being processed can differ between departments. For example, one department may handle Confidential data, while another may only process Controlled data. Submitting a new request also allows us to assess the different use cases appropriately and helps maintain visibility into software usage across multiple departments in our organization.

What happens after the assessment?

You will receive an email from our ISOTRAQ application, where you can review our results, and any recommendations or requirements before continuing in your procurement process.