Specifications include, but are not limited to: In an effort to better meet our risk management and compliance obligations, Massachusetts College of Art and Design (MassArt) and Framingham State University (FSU) (together referred to herein as the Participating Institutions) wish to jointly engage a qualified Managed Security Service Provider (MSSP) to provide Chief Information Security Officer (CISO) services and to help advise on, and implement portions of, each institutions information security management program. We seek consultative services that would deal with the following objectives: Attain expert information security capabilities Independently validate the existing Information Security Program Create a risk, effort and cost prioritized gap analysis of the existing Information Security Program to direct the further implementation of the Information Security Program. Ensure the proper implementation of the Information Security Program based on our institutional needs. The CISO will be required to fulfill the following duties and responsibilities on an as needed basis: Produce monthly status reports for the two CIOs a single report for both is acceptable noting status of work planned for, underway and completed with respect to fulfilling the provisions of the WISP, remediation of non-compliance with specific regulations, and any other information security initiatives designed to reduce risk exposure. This should include creating and maintaining a list of issues encountered since the prior reporting period, issues resolved, and a timeline for addressing any unresolved issues along with personnel or organizations with designated responsibility for taking corrective action. Participation, as required, in meetings convened by either CIO (by phone) Respond to and help resolve security issues on either campus which arise on an as needed basis Propose remediation projects to solve compliance gaps and reduce risk exposure as they are identified. Those projects would need to approved, rejected or deferred based on risk, compliance needs and budget. Provide input and direction on annual budgeting and planning for each campus to address security concerns