Educause Security Discussion mailing list archives

Re: HECVAT alternative for On-Prem Vendors


From: randy <marchany () VT EDU>
Date: Fri, 9 Nov 2018 11:13:18 -0500

This is our "on-prem" vendor questionnaire that we've used in the past
couple of years. It's at
https://itpals.vt.edu/content/dam/itpals_vt_edu/newitasitedocs/it-procurement/it_security_questionnaire2.pdf.
We took Notre Dame and IU's original questionnaires and modified them.

We will be using HECVAT for more  evals in the future..

Randy Marchany
VA Tech IT Security Office and Lab


On Fri, Nov 9, 2018 at 7:24 AM Belsito, Louis D <belsito () rowan edu> wrote:

I’ve been struggling with this issue as well.  I’ve been using Gartner’s
Security and Privacy Vendor Application Evaluation (VSPT Questionnaire)
it’s a spreadsheet for basic security and privacy assessment of vendor
applications.  It’s not as clean and pretty as the HECVAT.  It’s about 60
questions.





*____________________________________*



*Lou Belsito, MBA, MISM, CISSP, CISA*

Manager, Information Security Risk

Information Security Office

Division of Information Resources & Technology



Rowan University

201 Mullica Hill Rd., Glassboro, NJ 08028

T: 856-256-5725

Rowan.edu



*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Tyler Newell
*Sent:* Thursday, November 1, 2018 9:26 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] HECVAT alternative for On-Prem Vendors



Community,



We started using the HECVAT for cloud vendor assessments a little more
than a year ago and have been very happy with it especially when a vendor
has already filled one out so we aren’t waiting to receive it back.



That said, we’ve had contract expirations for some of our on-premise
vendors and wanted to run them through a similar process to properly assess
their product(s). I wasn’t able to find a standardized assessment
questionnaire like the HECVAT when it comes to on-premise, so I thought I
would reach out to see if anyone had a document already created that they
are willing to share.



I appreciate your time for reading this.



Thank you,



//SIGNED//

Tyler Newell, Information Security Analyst

Bowling Green State University | Information Technology Services

P: 419.372.0999 | tnewell () bgsu edu | www.bgsu.edu/infosec



This e-mail, including any attachments, may contain information that is
protected by law as privileged and confidential, and is transmitted for the
sole use of the intended recipient.  If you are not the intended recipient,
you are hereby notified that any use, dissemination, copying or retention
of this e-mail or the information contained herein is strictly prohibited.




Current thread: