Specifications include, but are not limited to: Ticketing platform for the full management, sale, and redemption of tickets for hosted events at each of its campuses. These instructions are for vendors interested in providing the institution with a software and/or a service. This worksheet should not be completed by an institution entity. The purpose of this worksheet is for the vendor to submit robust security safeguard information in regards to the product (software/service) being assessed in the institution's assessment process. Campus IT environments are rapidly changing and the speed of cloud service adoption is increasing. Institutions looking for ways to do more with less see cloud services as a good way to save resources. As campuses deploy or identify cloud services, they must ensure the cloud services are appropriately assessed for managing the risks to the confidentiality, integrity and availability of sensitive institutional information and the PII of constituents. Many campuses have established a cloud security assessment methodology and resources to review cloud services for privacy and security controls. Other campuses don’t have sufficient resources to assess their cloud services in this manner. On the vendor side, many cloud services providers spend significant time responding to the individualized security assessment requests made by campus customers, often answering similar questions repeatedly. Both the provider and consumer of cloud services are wasting precious time creating, responding, and reviewing such assessments. The Higher Education Community Vendor Assessment Toolkit (HECVAT) attempts to generalize higher education information security and data protections and issues for consistency and ease of use. Some institutions may have specific issues that must be addressed in addition to the general questions sets provided in the toolkit. It is anticipated that the HECVAT will be revised over time to account for changes in services provisioning and the information security and data protection needs of higher education institutions. The Higher Education Community Vendor Assessment Toolkit: ● Helps higher education institutions ensure that vendor services are appropriately assessed for security and privacy needs, including some that are unique to higher education ● Allows a consistent, easily-adopted methodology for campuses wishing to reduce costs through vendor services without increasing risks ● Reduces the burden that service providers face in responding to requests for security assessments from higher education institutions The Higher Education Community Vendor Assessment Toolkit is a suite of tools built around the original HECVAT (known now as HECVAT - Full) to allow institutions to adopt, implement, and maintain a consistent risk/security assessment program. Tools include: ● HECVAT - Triage: Used to initiate risk/security assessment requests - review to determine assessment requirements ● HECVAT