Security Checklist for Hosted IT Services
CSUN reviews hosted, cloud, and third-party technology services to help protect university information and reduce cybersecurity risk.
If you're considering a new vendor or service that will access, store, process, or transmit university information, contact Information Security early in the planning or purchasing process.
Do I Need a Security Assessment?
A security assessment may be required when a service or vendor will:
- Access, store, process, or transmit Level 1 or Level 2 university information.
- Collect sensitive information on behalf of CSUN.
- Access CSUN systems or university information.
- Process payment card information.
- Introduce significant information security or privacy risk.
Not sure if a review is required? Contact Information Security at iso@csun.edu before moving forward.
Before You Purchase
Before purchasing or implementing a hosted, cloud, or third-party service:
- Check for an existing CSUN solution that meets your needs.
- Identify the data involved and determine whether it includes Level 1 or Level 2 information.
- Contact Information Security early to determine whether a security assessment is required.
- Complete applicable procurement, accessibility, privacy, and security reviews.
- Do not provide sensitive university information to the vendor until required reviews and approvals are complete.
Learn About Data Classification
What We Review
Accordion: Data Protection & Privacy
The security review considers how the vendor will protect university information, including:
- Access to university information
- Privacy and confidentiality
- Encryption in transit and at rest
- Data storage and location
- Vendor employees and subcontractors
- Data sharing and disclosure
- Data retention and secure disposal
- Return of university information when the service ends
Access to university information should be limited to individuals with a legitimate business need.
The review may evaluate:
- Authentication and access controls
- Multifactor authentication (MFA)
- CSUN-approved single sign-on (SSO), when required
- Administrative and privileged access
- Account provisioning and removal
- Vendor access to CSUN systems or information
Access controls should be appropriate for the sensitivity of the information and service.
Vendors should maintain security controls appropriate for the service and information involved.
The review may include:
- Vulnerability and patch management
- Secure system configuration
- Malware protection
- Security logging and monitoring
- Secure software development
- Penetration testing
- Incident response
- Business continuity and disaster recovery
Information Security may request documentation to evaluate a vendor's security practices.
Depending on the service and risk, this may include:
- Higher Education Community Vendor Assessment Toolkit (HECVAT)
- SOC 2 Type II report
- Independent penetration test or vulnerability assessment results
- Security or compliance certifications
- Information security policies
- Incident response documentation
- Business continuity and disaster recovery documentation
Information Security determines the appropriate documentation based on the service and level of risk.
Vendor agreements should address cybersecurity incidents involving CSUN information or services.
Requirements may include:
- Prompt notification to CSUN
- Cooperation with investigation and response activities
- Preservation of relevant logs and evidence
- Identification of affected information
- Remediation of vulnerabilities
- Appropriate breach-notification procedures
Security incidents involving CSUN information should be reported promptly.
For services important to university operations, the review may consider:
- Service availability
- Backup and recovery
- Business continuity
- Disaster recovery
- Recovery time objectives
- Recovery point objectives
- Testing of recovery procedures
Departments should consider how long they can operate without the service and how much data loss is acceptable.
Additional requirements may apply depending on the information and service involved, including:
- FERPA — Student education records
- GLBA — Certain financial information
- HIPAA — Certain protected health information
- PCI DSS — Payment card information
- CSU and CSUN information security requirements
- Privacy requirements
- Records retention requirements
- Accessibility requirements
Contracts should address what happens to CSUN information when a service ends.
Considerations may include:
- Return or export of university information
- Secure deletion of university information
- Treatment of backups and archived copies
- Continued confidentiality requirements
- Transition assistance
- Termination rights related to security or compliance concerns
CSUN should be able to retrieve university information in an appropriate format before the service is terminated.
Security Assessment Process
The security assessment process generally includes:
1. Identify the Service
Provide information about the vendor, service, business need, and university information involved.
2. Determine the Risk
Information Security determines the appropriate level of review based on the service, data, users, and technology involved.
3. Review Vendor Security
The vendor may be asked to provide a HECVAT, SOC 2 report, or other security documentation.
4. Address Findings
The department, vendor, and Information Security work together to address identified security risks or required safeguards.
5. Complete the Review
Required security review and approvals should be completed before applicable purchasing or implementation activities proceed.
Learn About the Risk Management Process
Resources
- Risk Management — Security assessments for projects, applications, vendors, and services.
- Data Classification & Protected Data — Identify Level 1, Level 2, and Level 3 university information.
- Policies & Standards — Review applicable information security requirements.
- Information Security Plan — Learn about CSUN's approach to protecting university information and technology.
- Information Security — Find additional security guidance, services, and assistance.
Need Help?
Contact Information Security early when planning a hosted, cloud, or third-party service that will handle sensitive university information.
CSUN Information Security
Email: iso@csun.edu
Phone: (818) 677-6100