Compliance Requirements for Outsourced Services
All third-party vendors dealing with Cal Poly Level 1, Level 2, or Level 3 data must submit the following documentation for the level of data handled by the vendor:
Required documentation for L1 or L2 data
- Attestation of Compliance (AOC) – (e.g. cert from Cloud Security Alliance)
- Report on Compliance (ROC) – (SOC3, SSAE16)
- Contract (confidentiality agreement)
- Dataflow
- Third-Party Vendor Security Questionnaire
(CSA V3 questionnaire for Level 1 data; Third-Party Vendor Security Questionnaire for level 2 data - Incident Response (this should be included in the contract)
- Security exception (if needed)
- Application data request (if needed)
Please note- this form should be submitted after a vendor has been vetted - Authentication request (if needed)
Please note- this request should be submitted
after a vendor has been vetted
Required documentation for L3 data
- Contract
- Third-Party Vendor Security Questionnaire
- Security exception (if needed)
- Application data request (if needed)
- Authentication request (if needed)
Flowchart
(click image for larger version)