This questionnaire is for technology service providers to complete. Technology service providers include any vendor providing hardware, software, or a service to the college. It is highly recommended to provide these questions to the vendor in early discussions to avoid delays or possible late cancellations due to security concerns. Send this to the vendor representative you are in contact with and forward the results to informationsecurity@morainevalley.edu. The Information Security team will review the results and if the vendors answers yes to any of the questions, the Information Security team will provide a response including a risk analysis.
- List the security practices that are in place by the service provider:
- Is the vendor processing payments? If yes:
- PCI Compliance: Vendor must have and provide records of PCI compliance.
- Payment types: Will credit card terminals be used on site, payments made online, or both?
- Section two must be completed.
- If vendor is accessing, storing, or transmitting sensitive data? If yes:
- Security Posture: How is sensitive data managed, particularly in areas where forms collect user information, and comply with data protection regulations. Include information on multi-factor authentication, firewalls, encryption (at rest and in transit) and intrusion detection systems. Include history of Cybersecurity incidents.
- Data Privacy: Provide policies regarding the use or sale of user data, including marketing practices. Provide details on how user data is handled, and confirm that no data is sold or used for unauthorized purposes.
- Compliance: Describe your data privacy program and how it ensures compliance with U.S. federal and state laws, as well as international laws like, particularly in relation to personal data collection, storage, and processing.
- Confidentiality: Describe how user access and permissions are managed.
- Does the vendor use equipment or services from the following companies?
- Huawei Technologies Company
- ZTE Corporation
- Hytera Communications Corporation
- Hangzhou Hikvision Digital Technology Company
- Dahua Technology Company
- AO Kaspersky Lab
- China Mobile International USA Inc.
- China Telecom (Americas) Corp.
- Pacific Networks Corp or ComNet (USA) LLC
- China Unicom (Americas) Operations Limited
- Kaspersky Lab, Inc