Educause Security Discussion mailing list archives

Re: Anyone Using Slate CRM?


From: John Bradley <bradlejp () PLATTSBURGH EDU>
Date: Thu, 9 Jan 2020 13:30:50 -0500

Try EDUCAUSE:

https://library.educause.edu/resources/2016/10/higher-education-community-vendor-assessment-toolkit

  --

JOHN BRADLEY
(He, Him, His, Himself)
Assistant CIO/ Associate Director of Computing Services
0217 Feinberg
101 Broad Street
Plattsburgh, NY 12901
(o) 518-564-2435 <+1-518-564-2435>
plattsburgh.edu <https://www.plattsburgh.edu/>
[image: Facebook Logo] <https://www.facebook.com/sunyplattsburgh> [image:
Twitter Logo] <https://twitter.com/sunyplattsburgh> [image: Instagram Logo]
<https://www.instagram.com/sunyplattsburgh/> [image: Snapchat Logo]
<https://www.snapchat.com/add/sunyplattsburgh> [image: LinkedIn Logo]
<https://www.linkedin.com/school/suny-plattsburgh/>
[image: SUNY Plattsburgh Logo]



**This email message, including any attachments is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. If you are not the intended recipient, please contact the
sender by email and destroy any copies of the original.  Thank you.**

On Thu, Jan 9, 2020 at 11:38 AM Victoria Gabbai <vgabbai1 () jhu edu> wrote:

We do, but I haven’t done a full audit on it.  Could you point me in the
direction of the HECVAT? I can’t seem to find it on
https://www.ren-isac.net/hecvat/cbi.html (maybe this is the wrong site
for it?)



Thanks,

Vicky



*Victoria Gabbai* *cisa, M.Sc.** | *
*Sr. Information Technology Auditor **443-997-3117 (W)**  |  **443-997-6399
** (F)  |  *X7*3117**  |  **vgabbai1 () jhu edu <vgabbai1 () jhu edu>*

[image: cid:image001.png@01D27557.3BF1C2B0]



*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Travis, Andrew
*Sent:* Thursday, January 9, 2020 9:58 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] Anyone Using Slate CRM?



We are looking at migrating to Slate for our student CRM and I was curious
if anyone else on this list is using Slate at your school?  We've received
the HECVAT and AWS SOC2 report, but the HECVAT noted that they have no
CISO, security engineers, security analysts or security operations center.
Technolutions (the creators of Slate) confirmed their CIO is their security
team.  My concern is that they don't have anyone reviewing security events
to detect data breaches or system compromises.  Since we are evaluating
using Slate to store highly sensitive data such as SSNs and Driver's
License numbers, I'm hesitant to approve purchasing their product.  I'm
curious how any of you all would have mitigated that risk if you use Slate.



Thanks for your help!



Andrew Travis

Information Security Officer

Radford University

radford.edu/it-security <https://www.radford.edu/it-security>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: