Educause Security Discussion mailing list archives

Re: Information on Contracts with Third Parties


From: Chad Tracy <chad.tracy () COLBY EDU>
Date: Thu, 30 Nov 2017 14:31:41 -0500

Cindy,

I have attached what we use as a boilerplate addendum for MSA's. Feel free
to use anything you like in terms of language. I worked on this last year
with our College's Risk Manager who is also an attorney. Feel free to call
me or email with any questions.

Thanks!


Chad Tracy
Director of Information Security
Colby College
Waterville, ME 04901
207 . 859 . 4199
chad.tracy () colby edu

On Tue, Nov 28, 2017 at 12:46 PM, Lusby, Cindy (lusbyca) <
lusbyca () ucmail uc edu> wrote:

Hello,



I work as a Security Analyst for the University of Cincinnati (UC).  Here
at UC, we have a contract rider that we have put in place for third party
contracts when they require access to university data.



I would like to get some feedback from this group on if you have standard
contractual language pertaining to security that you typically add to
contracts with third parties. I am looking to improve our process and
rider, and would greatly appreciate any feedback you may have as to what
your current process is.



Thank you for any information that you can provide.



Regards,

*Cindy Lusby*

Information Security Analyst

IT@UC Office of Information Security | University of Cincinnati

*lusbyca () uc edu <lusbyca () uc edu>* | *www.uc.edu/infosec
<http://www.uc.edu/infosec> *| @UC_OIS <https://twitter.com/uc_ois> on
Twitter

Attachment: Colby College Standard for Safeguarding Information Ver. 1.0.docx
Description:


Current thread: