Software Acquisition Checklists

Generally, the requestor or related individual within the College will. However, you may also have your vendor contact assist with or fill out the checklist for you.
This greatly depends on the type of data that is being stored/processed by the application in question and the scope of its users. If there is sensitive/regulated data, the College requires up-to-date documentation detailing the organization’s security controls. Below is a brief list of common types of documentation and their requirements:

 

Service Contract – The contract between the vendor and the College.  This should be included with every checklist.
SLA Contract – Service Level Agreement document which should be included with every checklist.
VPAT – Voluntary Product Accessibility Template
Please include if it is mandatory to use this product/application to complete College business/academic tasks.
SOC2 – Service Organization Controls report;
Please include if your application stores or processes sensitive/regulated data.
HECVAT – Higher Education Community Vendor Assessment Toolkit
Please include if your application stores or processes sensitive/regulated data.
Data Steward approval – If your application stores sensitive/regulated data, you will need approval from the respective Data Steward.
The sooner, the better!  There are multiple individuals and departments that can be involved, and thus their availability might not sync up.  If you require technical changes such as Single Sign-On integration or network and email changes, please allow for at least four weeks lead time.