Dear UIC instructors and staff,
To further protect university data and ensure compliance with institutional security and privacy policies and regulations, UIC Security and Privacy Risk Assessments will be required for applicable software purchases submitted through iBuy.
What is happening?
Effective Tuesday, April 28, a Security and Privacy Risk Assessment questionnaire must be completed when submitting an iBuy requisition for software or services where a third-party vendor hosts or has access to university data, the university network or incorporates artificial intelligence.
The questionnaire collects information about the type and classification of data that may be shared with the vendor and helps determine whether there are any regulatory (such as PIPA, FERPA, GDPR or HIPAA) or contractual privacy or security risks that need to be evaluated and managed before the purchase can proceed.
What do I need to do?
If your software or services purchase involves a third-party vendor that will host or access university data, the university network or incorporates AI, please complete the Security and Privacy Risk Assessment questionnaire before submitting the iBuy requisition.
Please ask your vendor to send you any security and privacy documentation they have, which may assist in expediting the completion of the security and privacy risk assessments.
Completing the questionnaire in advance will help avoid delays in processing your requisition. The questionnaire can be accessed at: it.uic.edu/risk.
Who should I contact with questions?
If you have questions or concerns about the Security and Privacy Risk Assessment questionnaire, UIC units can contact security@uic.edu.
Thank you for your cooperation in helping safeguard university users, data and systems.
Regards,
Shefali Mookencherry
Chief Information Security and Privacy Officer
Technology Solutions