University of South Alabama Logo     
Policy No: 2169
Responsible Office: Computer Services Center
Last Review Date: 07/24/2026
Next Required Review: 07/24/2031
Policy No: 2169
Responsible Office: Computer Services Center
Last Review Date: 07/24/2026
Next Required Review: 07/24/2031

Third-Party Management


1. Purpose

This policy establishes a consistent, risk-based framework for managing third-party IT vendors (hereafter "vendors") that access, store, process, transmit, or connect to university information, data, or IT systems.
 
This policy is designed to:
  • Protect the confidentiality, integrity, and availability of university data;
  • Ensure compliance with applicable laws and regulations (e.g., FERPA, HIPAA, PCI-DSS);
  • Mitigate operational, financial, and reputational risks associated with vendors;
  • Establish formal risk assessments, risk ratings, and due diligence procedures;
  • Define clear roles and responsibilities for vendor selection, onboarding, monitoring, and offboarding.

2. Applicability

This policy applies to all members of the USA campus community (University General Division), specifically, to any University faculty, staff, researchers, departments, or administrative units who are requesting vendor agreements involving the procurement and lifecycle management for IT services or infrastructure provided by third-party vendors.

It includes but is not limited to agreements for:
  • Cloud Services: Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS), Infrastructure-as-a-Service (IaaS);
  • Software & Hardware: Licensed software, IT hardware, and related maintenance services;
  • Professional Services: IT consultants, contractors, developers, and managed service providers (MSPs);
  • Any other third-party entity that handles University Data or is granted access to the University's network or IT infrastructure.

3. Definitions

Third-Party IT Vendors (Vendors):  Any non-University entity (including contractors and service providers) that provides IT products or services to the University or handles University Data.

University Data:  All information created, collected, stored, or managed by or on behalf of the University. This is classified into levels, such as:
  • Regulated/Restricted Data (High-Risk): Data protected by law (e.g., student PII under FERPA, patient PHI under HIPAA, credit card data under PCI-DSS). Unauthorized disclosure could result in severe legal, financial, or reputational penalties;
  • Sensitive Data (Moderate-Risk): Data not publicly available, including intellectual property, proprietary research, and internal administrative information;
  • Public Data (Low-Risk): Information intended for public consumption.
Data Steward:  The University official (e.g., Dean, Department Head, Principal Investigator) who has planning and policy-level responsibility for data within their functional area.

Relationship Owner:  The University department or individual responsible for initiating the vendors request and managing the day-to-day relationship, performance, and communications with specific Vendors.

Office of Information Security (OIS):  The University office responsible for executing information security strategy, policy, and due diligence.

Subject Matter Experts (SMEs): Designated staff from offices such as Information Security, Procurement, Legal (General Counsel), and Finance, who are responsible for reviewing specific areas of vendor risk.

4. Policy Guidelines

4.1  Risk-Based Approach
 
All vendor relationships must be assessed for risk before a contract is executed. The level of due diligence, contractual scrutiny, and ongoing monitoring required shall be directly proportional to the risk rating (High, Medium, Low) assigned to the vendors, which is based on data sensitivity (as defined in Section 3 under "University Data") and service criticality.
 
4.2  Centralized Oversight
 
The Office of Information Security (OIS) must be involved in the review and approval of all new IT Vendors agreements and renewals. Departments are prohibited from independently engaging IT Vendors that handle Regulated/Restricted or Sensitive Data without this formal review.
 
4.3  Mandatory Due Diligence

Prior to agreement approval, all potential Vendors must undergo a formal due diligence review coordinated by the OIS. Required documentation and review frequency will be based on the assigned risk rating, as defined in the associated procedures. This may include:
  • Security Questionnaires (e.g., a "Vendors Risk Assessment Intake Form");
  • Third-Party Attestations (e.g., SOC 2 Type 2 reports, ISO 27001 certification, PCI Attestation of Compliance);
  • Evidence of data privacy policies and incident response plans.
4.4  Contractual Requirements

All contracts, service agreements, and terms of service involving IT Vendors must be reviewed by Procurement Services and the Office of General Counsel. Contracts involving Regulated/Restricted or Sensitive Data should include, when feasible, specific clauses addressing:
  • Data ownership, confidentiality, and security requirements;
  • Security breach notification (specifying timelines and procedures, as outlined in our Personal Data Protection policy, and Data Protection Addendum);
  • Right to audit and security assessments;
  • Data protection and privacy requirements (adherence to FERPA, HIPAA, etc.);
  • Secure offboarding procedures, including data return and/or secure destruction requirements.
4.5  Ongoing Monitoring

The OIS is responsible for maintaining a central inventory of IT vendors and triggering periodic security reviews based on the Vendor’s risk rating (e.g., annually for High-Risk, every 18-24 months for Medium-Risk).

5. Procedures

5.1  Initiation: Agreements identified as engagement of Third-Party IT Vendors mandate the completion of a "Vendors Risk Assessment Intake Form" (provided by the OIS). This "risk questionnaire" captures the data type, service, and other details needed for triage.
 
5.2  Risk Triage & SME Assignment: The OIS reviews the intake form to assign an initial Risk Rating (High, Medium, Low). Based on this rating the OIS will perform an appropriate review.
 
5.3  Due Diligence & Review:
 
In cases where a vendor cannot or will not provide required information, the Chair or Dean must state their willingness to assume the risk of continuing to do business with the vendor for business reasons, in writing. This should be entered into the DocRoute request, for legal review.
Based on the determined risk ratings, OIS will respond as follows.
  • High-Risk (example: USA shares or hosts electronic data, but the vendor has not provided full documentation): The OIS will conduct a comprehensive security assessment. Completion of a Higher Education Community Vendor Assessment Toolkit (HECVAT) is required;
  • Medium-Risk (example: USA shares or hosts electronic data with the vendor, and the vendor has provided all documentation necessary to validate compliance with OIS and University security policies): The OIS will conduct a comprehensive security assessment, including the review of SOC 2 reports or equivalent;
  • Low-Risk (example: USA does not share personal electronic data [PII, PHI, HIPAA, FERPA, PCI, etc.] with the vendor): The OIS will conduct a comprehensive security assessment.
5.4  Risk Remediation & Acceptance:
  • SMEs work with the Vendors to remediate any identified security or contractual gaps;
  • All due diligence documentation and SME reviews/approvals must be centrally retained.
5.5  Approval and Onboarding: Once all reviews are complete and identified risks are addressed the Chief Information Security Officer (CISO) will approve the vendor agreement and the Relationship Owner will coordinate with IT regarding provisioning services or access.
 
5.6  Termination/Offboarding: Upon termination of a contract, the Relationship Owner must initiate the offboarding process. This includes coordinating with IT to immediately revoke all logical and physical access and confirming with the Vendors that all University Data has been securely returned or destroyed, as stipulated in the contract.

6. Enforcement

Failure to comply with this policy may result in the delay or denial of procurement or suspension of access. Exceptions must be documented and formally approved by the CISO.

7. Related Documents