Office of Information Technology
Effective Date March 19, 2021
All OIT Policies

Data Security Review Process

Policies

The Office of Information Technology (OIT) conducts Data Security Reviews to safeguard Brown University's network infrastructure, institutional data, and research participant data. Any software, hardware, or third-party service, including Proofs of Concept (POCs) and Requests for Proposals (RFPs) that handles, stores, or accesses Brown information must undergo this review.

Prerequisites & Special Approvals

Completion of the OIT Security Questionnaire is required for all software and vendor solutions, regardless of FedRAMP authorization status. OIT utilizes the questionnaire responses along with the security assessment rating to determine the final Data Risk Classification and vendor approval status:

  • FedRAMP Authorized (Moderate & High): Mapped to Data Risk Classification Level 3
  • FedRAMP Authorized (Li-SaaS): Mapped to Data Risk Classification Level 2

    Important Note : Departments are expected to have sufficient knowledge of the software functionality, data scope, and integration plans to complete the preliminary questionnaire; these questions must not be sent directly to the vendor. If the requester is not the primary software user, explicitly state the end user's full name and email address in the request summary so OIT can direct follow-up questions appropriately.

    How to Submit a Review Request

    To initiate a Data Security Review, submit a request through the Brown Contract Management Platform (BCM). Note that BCM access requires completion of mandatory training. For details on completing training and gaining access, refer to BCM Access and Training – Strategic Procurement & Contracts.

    Request TypeSubmission PathwayKey Instructions
    Contracted Software / ServiceSubmit as a New Contract requestUnder the Risk Questionnaire tab, complete the Data Security Questions indicating IT Software, Hardware, or IT Professional Services.
    Non-Contracted Software (e.g., Proof of Concept, RFP)Submit as a Data Security Review Only requestUnder the Risk Questionnaire tab, when prompted for "What type of request are you submitting", select "No BCM contract" from the dropdown list.

    Once the request has been submitted in BCM, OIT evaluates the engagement to establish a Data Risk Classification. This classification dictates the date security review needs, vendor documentation requirements, and recurring review schedules.

No Risk
  • Examples of “No Risk” contracts are the purchase of local software licenses that do not inherently store data within them and are not sending data off premises, i.e., Microsoft Word
  • Security re-review is needed every 5 years
Level 1
  • Low-impact data or services with minimal security risk exposure.
  • OIT will review and evaluate the submission in BCM. Contract legal terms are reviewed separately by Strategic Procurement and Contracts.
  • Security re-review is needed every 5 years
Level 2
  • If that data is held at Brown:
  • If the data is being held with the vendor:
    • If not vetted by an OIT-approved standardized security assessment?
      • OIT will send out a Higher Education Cloud Vendor Assessment Tool form (“HECVAT”) to the vendor to complete.
      • Once the HECVAT is completed, OIT will review the answers. Additional questions to the vendor and/or department may be needed.
      •  A copy of a SOC 2 Type 2 report can be accepted in lieu of a HECVAT.
    • If vetted by an OIT approved standardized security assessment vendor
      • No HECVAT is needed (security review complete)
    • OIT will work with SPC to review and approve the legal terms in all software, hardware and cloud contracts
  • Security re-review is needed every 3 years
Level 3
  • If that data is being held at Brown:
  • If the data is being held with the vendor:
    • If not vetted by an OIT approved standardized security assessment?
      • OIT will send out a Higher Education Cloud Vendor Assessment Tool form (“HECVAT”) to the vendor to fill out.
      • Once the HECVAT is completed, OIT will review the answers. Additional questions to the vendor and/or Department may be needed.
      •  A copy of a SOC 2 Type 2 report can be accepted in lieu of a HECVAT.
    • If vetted by an OIT approved standardized security assessment vendor?
      • No HECVAT is needed (security review complete)
    • OIT will work with SPC to review and approve the legal terms in all software, hardware and cloud contracts
    • Security review is needed every year

All software deployments, device configurations, and user activities must remain compliant with Brown University IT policies and endpoint protection standards:

Questions & Support

For assistance or questions regarding the Data Security Review process, contact the OIT Data Security Team at oit-datasecurity@brown.edu.

For questions regarding legal terms in software, hardware, and cloud contracts, please contact the Strategic Procurement and Contracts Team at SPCcontracts@brown.edu or visit the  IT Contract Review page.