Educause Security Discussion mailing list archives

Re: HECVAT Users List


From: John Forker <jforker () MAINE EDU>
Date: Fri, 23 Feb 2018 16:01:09 -0500

We are using the HECVAT-lite at the University of Maine System.  We have
are using it, unmodified, but supplement it with a few other questions -
especially around non-cloud components.  We accept the full HECVAT.  As
stated, even the lite version can be heavy-duty for some situations so we
evaluate the data types (sensitivity) and volumes and require it only when
applicable.

I completed the form to be listed and encourage wider spread use to have a
uniform tool for vendors.

John
------------------
John Forker, CISSP
Chief Information Security Officer
University of Maine System
(207) 262-7907

On Wed, Feb 21, 2018 at 1:20 PM, Allen, Jon <Jon_Allen () baylor edu> wrote:

Hello!



The 2019 Higher Education Cloud Vendor Assessment Tool (HECVAT) working
group is devoting effort to getting the word out about institutional HECVAT
adoption.  We want to create a list of institutions that are using the
HECVAT to publish on the HECVAT web page (https://library.educause.edu/
resources/2016/10/higher-education-cloud-vendor-assessment-tool
<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.google.com%2Furl%3Fq%3Dhttps%3A%2F%2Flibrary.educause.edu%2Fresources%2F2016%2F10%2Fhigher-education-cloud-vendor-assessment-tool%26sa%3DD%26ust%3D1519160086542000%26usg%3DAFQjCNHtq6sVc7M6Yijyrp-FyIIhP7-g3A&data=01%7C01%7Cjon_allen%40baylor.edu%7C2f31c9f2ae8048feb12908d5789c6998%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=xWyOTuLEnGCCgx273bRaeoOn%2FF5jzLxFimJ28wRO8BQ%3D&reserved=0>).
The purpose of this list is two-fold: First, to demonstrate HECVAT adoption
at higher education institutions (so that vendors will want to participate
in completing a HECVAT). Second, to provide a list of HECVAT references (so
that institutions can contact their peers with HECVAT questions). If you
are interested in being listed on the webpage in this manner, please fill
out this form. Institutional names only (not contact information) will be
listed on the webpage.



If you would like your institution to be listed in this way, please
complete our form:



https://goo.gl/forms/BJlson23HVDMy1Q63
<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgoo.gl%2Fforms%2FBJlson23HVDMy1Q63&data=01%7C01%7Cjon_allen%40baylor.edu%7C2f31c9f2ae8048feb12908d5789c6998%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=BjbsQBbg%2FPZVtOhlWIHMTXXOSHq1TTzBXwqVNMfqoQk%3D&reserved=0>



Thanks,



*_________________________________*

*Jon Allen, CISSP, EnCE *

*Assistant Vice President & *

*Chief Information Security Officer*

*Baylor University *

*254.710.4793 <(254)%20710-4793>*



[image:
/Users/jon_allen/Library/Containers/com.microsoft.Outlook/Data/Library/Caches/Signatures/signature_1325000890]

        *www.baylor.edu/bearaware* <http://www.baylor.edu/bearaware>


Current thread: