Streamlining Vendor Risk Management with the HECVAT

Wednesday, November 01 | 2:00PM–2:50PM ET | Meeting Room 104A/B, 100 Level
Session Type: Breakout Session
Delivery Format: Interactive Presentation
Campus IT environments are rapidly changing, and the speed of cloud service adoption only appears to increase. As campuses deploy or identify cloud services in use on their campus, they need to ensure that cloud services are appropriately assessed and managed for information security risk. Many campuses have established a cloud security assessment methodology and have the resources to assess many of their cloud services, but few campuses have sufficient resources to assess all cloud services. A joint EDUCAUSE, Internet2, and REN-ISAC working group has developed a Higher Education Cloud Vendor Assessment Tool (HECVAT) and is preparing to take the next steps for sharing campus cloud security assessments. This presentation will provide an update on the working group efforts, introduce the latest version of the HECVAT, discuss the REN-ISAC Cloud Broker Index and how Internet2 Cloud Services is including it in their program, and encourage discussion for future community collaborations to manage vendor information security risk.

Outcomes: Learn what the HECVAT is and how it can save time in assessing the security of cloud services * Learn about the REN-ISAC Cloud Broker Index * Discuss best practices to managing vendor risk

Presenters

  • Joanna Grama

    Senior Principal, Vantage Technology Consulting Group
  • Kim Milford

    CISO, University of Illinois at Urbana-Champaign

Resources & Downloads

  • Streamlining Vendor Risk Management with the HECVAT

    1 MB, pptx - Updated on 1/22/2024