Home page logo

educause logo Educause Security Discussion mailing list archives

Re: Risk analysis And Vendor Management
From: Sol Bermann <solb () UMICH EDU>
Date: Fri, 18 Jul 2014 13:40:20 -0400

We require 3rd-party assessments for service providers when sensitive data
is involved

Sol Bermann
Interim University of Michigan Chief Information Security Officer
Privacy Officer and IT Policy, Compliance and Enterprise Continuity
ITS - Information & Infrastructure Assurance
University of Michigan

solb () umich edu

On Fri, Jul 18, 2014 at 1:33 PM, David Grisham <Dgrisham () salud unm edu>

We require our business Associates and other vendors to supply information
on systems, applications, databases, medical devices, etc. That way we can
do a risk analysis and document controls that are in place by the vendor as
well as what we need to do to mitigate where controls are ineffective or
But we're getting some internal feedback that this is not a standard
--One of the big issues is HIPAA/HITECH requiring assurances of security
controls. I have found Stanford to have an excellent policy on vendor
-- Is there anybody else out there who requires third-party assessments
when confidential/ePHI/PII data is involved? Especially if it's outsourced?
To see Stanford's policy "
Cheers --grish
David D. Grisham
David Grisham, Ph.D.,  CISM, CRISC
Manager, IT Security,
UNM Hospitals, IT Division
Suite 3131, 933 Bradbury Drive, SE  Albuquerque, New Mexico 87106
Ph: (505) 272-5657
Department FAX 272-7143, Desk Fax 272-9927
Work email:  dgrisham () salud unm edu

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]