This information applies to pages in the CSUN template system.Windows-press ALT + an access key. Macintosh-press CTRL + an access key.

The University can choose to contract with software and services vendors. These arrangements can require the University to send protected data from its systems to those of the vendor. The University must take steps to ensure that these arrangements do not weaken its information security or place its data at risk of unauthorized disclosure. This document describes the information security requirements for vendors who obtain protected data from the University.
Application Service Providers (ASP's):
An application service provider is any vendor that provides the University with software that will contain University data but is managed and operated in the vendor’s data center and is not controlled or secured by the University’s Division of Information Technology. This includes third party software and services vendors.
Audit Trail:
The audit trail shall identify all accesses to the source file, success or failure of the access, the completion status of the access (e.g., failed or successful authentication, or user terminated), and the record and field modified.
Protected Data:
Protected data are any information that the University has deemed to be confidential or sensitive in nature and therefore require additional safeguards in its handling and use. This includes information protected by law such as social security number or credit card numbers. Also included is information that the University has decided to treat as protected because its unauthorized disclosure could cause a loss of privacy, damage to reputation, or economic harm. A list of protected data can be found on the IT website.
Information Assets:
Information assets include anything used to process or store information, including (but not limited to) records, files, networks, and databases; and information technology facilities, equipment (including personal computer systems), and software (owned or leased).
University:
This term is used interchangeably to refer to California State University, Northridge (CSUN) and its auxiliary units.
University Official:
This is any person employed by the campus or an auxiliary unit performing administrative or professional duties.
This document establishes the information security requirements that Application Service Providers (ASPs) must follow when providing software or services to the University that involve the transfer or storage of University protected data on hardware and software maintained by the vendor outside the CSU or CSUN data center. Compliance with this policy is the responsibility of every University official.
The University Application Service Provider policy specifies the minimum standards that a vendor must meet to ensure that it is handling protected data in a manner that complies with relevant laws, Executive Orders, campus policies, and established best practices. This policy applies to all ASPs hosting CSUN protected data for new contracts, existing contracts as they come up for renewal, and contracts when they are amended to include protected data.
1. Requirements of ASP Sponsoring Organization:
Any University department entering into an agreement to use software operated by an ASP or to provide protected data to a vendor who will store it on its own system (outside CSUN) must ensure that the vendor chosen complies with this policy. Departments must obtain the review and approval of the CSUN Information Security Officer (ISO) that the selected vendor is in compliance with the policy before it is permissible for the Purchasing & Contract Administration Department to negotiate an agreement with the ASP. The department wishing to enter into the ASP arrangement must also secure the written approval of the CSUN division that has overall responsibility for the protected data (if they are not one and the same).
The Information Security Officer (ISO) is responsible for working with CSUN departments to inform vendors of the requirements of this policy and for reviewing the evidence of compliance supplied by the vendor.
2. Requirements of the Application Service Provider:
Venders can comply with this policy in one of two ways. Either they can offer proof that a third party has attested to the soundness of their security practices through a SAS-70 audit or they can demonstrate that they follow the practices outlined in this policy. These methods of compliance are explained in sections 2.1 and 2.2. Depending on the nature of the project, the ISO may request that additional security measures be implemented in addition to the measures stated in this document.
ASPs that do not meet these requirements may not be used for CSUN projects that transfer or store protected data.
2.1 Type II SAS-70
2.2 Alternatives to a Type II SAS-70
University officials will contact the ISO requesting permission for use of an ASP. Once the ISO confirms the ASP is in compliance with this policy, a University official may then request Purchasing & Contract Administration negotiate a contract with the ASP. If approval is not given, the ISO will work with the University official to resolve issues regarding the use of the ASP or pursue alternatives.
The Information Security Officer (ISO) is responsible for reviewing this policy and updating it on a periodic basis.
University officials are responsible for obtaining permission to host CSUN data on the ASP from the application owners, working with the ISO to review the security practices of the ASP, and working with Purchasing & Contract Administration to ensure the ASP agreement is governed by terms and conditions acceptable to the University.
The ISO is responsible for contacting the ASP if there is a security issue and disabling the application if deemed necessary.
SANS organization (http://www.sans.org/)
Contact the campus Information Security Officer (ISO) by email at iso@csun.edu
Approved by the President
California State University, Northridge at 18111 Nordhoff Street, Northridge, CA 91330 / Phone: 818-677-1200 / © 2007 CSU Northridge
Last Updated: 8/21/2007