Policies
The Office of Information Technology (OIT) conducts Data Security Reviews to safeguard Brown University's network infrastructure, institutional data, and research participant data. Any software, hardware, or third-party service, including Proofs of Concept (POCs) and Requests for Proposals (RFPs) that handles, stores, or accesses Brown information must undergo this review.
Prerequisites & Special Approvals
- Merchant Services / Payment Cards: Any software or service accepting payments on behalf of Brown University must comply with the University Policy on Accepting and Handling Payment Cards to Conduct University Business and receive prior approval from the University Commerce Committee. Contact Financial Services at commerce@brown.edu to initiate this process before submitting a DSR request.
- BCM Access Required: Contract-related security reviews are processed via the Brown Contract Management Platform (BCM). Requesters must complete formal training prior to receiving platform access. For details, refer to BCM Access and Training – Strategic Procurement & Contracts.
Completion of the OIT Security Questionnaire is required for all software and vendor solutions, regardless of FedRAMP authorization status. OIT utilizes the questionnaire responses along with the security assessment rating to determine the final Data Risk Classification and vendor approval status:
- FedRAMP Authorized (Moderate & High): Mapped to Data Risk Classification Level 3
FedRAMP Authorized (Li-SaaS): Mapped to Data Risk Classification Level 2
Important Note : Departments are expected to have sufficient knowledge of the software functionality, data scope, and integration plans to complete the preliminary questionnaire; these questions must not be sent directly to the vendor. If the requester is not the primary software user, explicitly state the end user's full name and email address in the request summary so OIT can direct follow-up questions appropriately.
How to Submit a Review Request
To initiate a Data Security Review, submit a request through the Brown Contract Management Platform (BCM). Note that BCM access requires completion of mandatory training. For details on completing training and gaining access, refer to BCM Access and Training – Strategic Procurement & Contracts.
Request Type Submission Pathway Key Instructions Contracted Software / Service Submit as a New Contract request Under the Risk Questionnaire tab, complete the Data Security Questions indicating IT Software, Hardware, or IT Professional Services. Non-Contracted Software (e.g., Proof of Concept, RFP) Submit as a Data Security Review Only request Under the Risk Questionnaire tab, when prompted for "What type of request are you submitting", select "No BCM contract" from the dropdown list. Once the request has been submitted in BCM, OIT evaluates the engagement to establish a Data Risk Classification. This classification dictates the date security review needs, vendor documentation requirements, and recurring review schedules.
| No Risk |
|
|---|---|
| Level 1 |
|
| Level 2 |
|
| Level 3 |
|
All software deployments, device configurations, and user activities must remain compliant with Brown University IT policies and endpoint protection standards:
- Acceptable Use of Information Technology Resources Policy
- Security of Desktop, Laptop, Mobile and Other Endpoint Devices Policy
- Minimum Security Standards for Desktop, Laptop, Mobile, and Other Endpoint Devices
Questions & Support
For assistance or questions regarding the Data Security Review process, contact the OIT Data Security Team at oit-datasecurity@brown.edu.
For questions regarding legal terms in software, hardware, and cloud contracts, please contact the Strategic Procurement and Contracts Team at SPCcontracts@brown.edu or visit the IT Contract Review page.