Security Checklist for Hosted IT Services

CSUN reviews hosted, cloud, and third-party technology services to help protect university information and reduce cybersecurity risk.

If you're considering a new vendor or service that will access, store, process, or transmit university information, contact Information Security early in the planning or purchasing process.

Do I Need a Security Assessment?

A security assessment may be required when a service or vendor will:

  • Access, store, process, or transmit Level 1 or Level 2 university information.
  • Collect sensitive information on behalf of CSUN.
  • Access CSUN systems or university information.
  • Process payment card information.
  • Introduce significant information security or privacy risk.

Learn About Risk Management

Not sure if a review is required? Contact Information Security at iso@csun.edu before moving forward.

Before You Purchase

Before purchasing or implementing a hosted, cloud, or third-party service:

  1. Check for an existing CSUN solution that meets your needs.
  2. Identify the data involved and determine whether it includes Level 1 or Level 2 information.
  3. Contact Information Security early to determine whether a security assessment is required.
  4. Complete applicable procurement, accessibility, privacy, and security reviews.
  5. Do not provide sensitive university information to the vendor until required reviews and approvals are complete.

Learn About Data Classification

What We Review

Accordion: Data Protection & Privacy

The security review considers how the vendor will protect university information, including:

  • Access to university information
  • Privacy and confidentiality
  • Encryption in transit and at rest
  • Data storage and location
  • Vendor employees and subcontractors
  • Data sharing and disclosure
  • Data retention and secure disposal
  • Return of university information when the service ends

Access to university information should be limited to individuals with a legitimate business need.

The review may evaluate:

  • Authentication and access controls
  • Multifactor authentication (MFA)
  • CSUN-approved single sign-on (SSO), when required
  • Administrative and privileged access
  • Account provisioning and removal
  • Vendor access to CSUN systems or information

Access controls should be appropriate for the sensitivity of the information and service.

Vendors should maintain security controls appropriate for the service and information involved.

The review may include:

  • Vulnerability and patch management
  • Secure system configuration
  • Malware protection
  • Security logging and monitoring
  • Secure software development
  • Penetration testing
  • Incident response
  • Business continuity and disaster recovery

Information Security may request documentation to evaluate a vendor's security practices.

Depending on the service and risk, this may include:

  • Higher Education Community Vendor Assessment Toolkit (HECVAT)
  • SOC 2 Type II report
  • Independent penetration test or vulnerability assessment results
  • Security or compliance certifications
  • Information security policies
  • Incident response documentation
  • Business continuity and disaster recovery documentation

Information Security determines the appropriate documentation based on the service and level of risk.

Vendor agreements should address cybersecurity incidents involving CSUN information or services.

Requirements may include:

  • Prompt notification to CSUN
  • Cooperation with investigation and response activities
  • Preservation of relevant logs and evidence
  • Identification of affected information
  • Remediation of vulnerabilities
  • Appropriate breach-notification procedures

Security incidents involving CSUN information should be reported promptly.

For services important to university operations, the review may consider:

  • Service availability
  • Backup and recovery
  • Business continuity
  • Disaster recovery
  • Recovery time objectives
  • Recovery point objectives
  • Testing of recovery procedures

Departments should consider how long they can operate without the service and how much data loss is acceptable.

Additional requirements may apply depending on the information and service involved, including:

  • FERPA — Student education records
  • GLBA — Certain financial information
  • HIPAA — Certain protected health information
  • PCI DSS — Payment card information
  • CSU and CSUN information security requirements
  • Privacy requirements
  • Records retention requirements
  • Accessibility requirements

View Policies & Standards

Contracts should address what happens to CSUN information when a service ends.

Considerations may include:

  • Return or export of university information
  • Secure deletion of university information
  • Treatment of backups and archived copies
  • Continued confidentiality requirements
  • Transition assistance
  • Termination rights related to security or compliance concerns

CSUN should be able to retrieve university information in an appropriate format before the service is terminated.

Security Assessment Process

The security assessment process generally includes:

1. Identify the Service
Provide information about the vendor, service, business need, and university information involved.

2. Determine the Risk
Information Security determines the appropriate level of review based on the service, data, users, and technology involved.

3. Review Vendor Security
The vendor may be asked to provide a HECVAT, SOC 2 report, or other security documentation.

4. Address Findings
The department, vendor, and Information Security work together to address identified security risks or required safeguards.

5. Complete the Review
Required security review and approvals should be completed before applicable purchasing or implementation activities proceed.

Learn About the Risk Management Process

Resources

Need Help?

Contact Information Security early when planning a hosted, cloud, or third-party service that will handle sensitive university information.

CSUN Information Security
Email: iso@csun.edu
Phone: (818) 677-6100

Learn About Risk Management