Request Contract and Cybersecurity Review from IT

📌 Purpose

Salve Regina University is required to evaluate certain third-party vendors before contracts are executed when those vendors will access, store, process, transmit, or otherwise interact with University data. This review helps ensure that the vendor maintains appropriate security, privacy, and regulatory safeguards to protect institutional and customer information.

This requirement is driven in part by the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, which requires institutions to oversee service providers and verify that they are capable of protecting sensitive information. The Safeguards Rule specifically requires organizations to:

  • Take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards.
  • Require service providers, by contract, to implement and maintain those safeguards.
  • Periodically assess service providers based on the risk they present and the adequacy of their security controls.  [ecfr.gov]

As part of this process, the Office of Information Technology and other applicable departments may review contracts, security documentation, privacy policies, SOC reports, HECVAT assessments, data protection terms, AI usage practices, and other relevant materials before a purchase or agreement is approved.

Please submit this request before signing any contract, purchase agreement, terms of service, click-through agreement, or renewal involving a third-party vendor. Early review helps avoid delays and ensures the University's compliance and security obligations are met.

Additional Resources

For more information about the GLBA Safeguards Rule and service provider oversight requirements, see: