Third Party Vendor Management
Purpose
Third-Party Vendor Management is necessary for Howard Community College (HCC) to meet the information security requirements to be followed in the selection and management of third-party service providers at HCC. This policy also defines the information security requirements for contracts with third parties.
All engagements with service providers shall be in accordance with the policy. Arrangements involving third-party access to college information processing facilities or assets shall be based on a formal contract. The contract will contain, or reference, all security requirements and the assigned responsibilities to ensure that there is no misunderstanding between the College and the third party.
Policy
Sponsors and owners of outsourced business functions in collaboration with the CIO shall exercise appropriate due diligence in the selection of the service provider, including the following consideration:
- Service provider references and experience
- Security expertise of service provider personnel
- Background checks on service provider personnel
- Non-disclosure agreements covering the College’s systems and data
- How legal requirements are to be met, as data protection legislation or regulations
- The right to audit and review any recent audit reports
- Availability of services to be maintained in the event of disasters
- Service provider physical and logical controls used to restrict and limit the access to the organization’s sensitive business information of unauthorized users
- Service provider levels of security to be provided for outsourced equipment
- Clear understanding of the service provider security and incident response policy and assurance that the provider shall communicate incidents promptly
HCC shall contractually require that the service provider implements appropriate security controls in accordance with college policies. Services provided by the service provider shall be monitored to confirm that they are in accordance with these policies.
The college shall periodically assess service providers; at least annually, based on the risk they present and the continued adequacy of their safeguards.
If the service provider provides confidential information, it is the sponsor’s responsibility to ensure that any obligations of confidentiality are satisfied.
In higher-risk relationships, the College maintains the right to require changes to standards and obtain access to the service provider for evaluations of its performance. In lower risk relationships, the College shall require the use of standardized reports, such as trust services reports or a Higher Education Community Vendor Assessment Toolkit (HECVAT).
Service providers that do not meet these requirements shall not be used for projects.
The following terms shall be included in all third-party contracts:
- The general policy on information security
- Asset protection, including:
- Procedures to protect College assets, including information and software
- Procedures to determine whether there has been any compromise of assets, e.g., whether loss or modification of data, has occurred
- Controls to ensure the return or destruction of information and assets at the end of, or at an agreed point during, the contract
- Provisions regarding integrity and availability
- Restrictions on copying and disclosing information
- A description of each service to be made available
- The target level of service and unacceptable level of service
- Provisions for the transfer of staff where appropriate
- The respective liabilities of the parties to the Agreement
- Responsibilities with respect to legal matters, e.g., the service provider will comply with US legislation including commerce and export control laws in securing the data
- Intellectual Property Rights (IPRs) and copyright assignment and protection of any collaborative work
- Access control agreements covering:
- Permitted access methods, and the control and use of unique identifiers such as user IDs and passwords
- An authorization process for user access and privileges
- A requirement to maintain a list of individuals authorized to use the services being made available and what their rights and privileges are with respect to such use
- The right to monitor and revoke user activity
- The right to audit contractual responsibilities, or to have those audits carried out by a mutually agreed upon third-party
- A requirement that all subcontractors be approved, and that the third party remain responsible for the acts of any approved subcontractors
- A description of the third-party provider’s contingency plans to ensure that services are maintained in the event of a disaster
- Any required physical protection controls and mechanisms to ensure that the controls are followed
- Any proprietary software and documents be kept in escrow to provide the college access to these resources in the event the third party is no longer a viable entity
- An acknowledgement that the service provider is responsible for the security of college information including cardholder data the service provider processes, transmits or stores Accounts used by vendors for remote maintenance (including remote access accounts) shall be enabled only during the time period needed, where appropriate.
For third parties with access to credit card data, a list of service providers shall be maintained, and the PCI compliance status of each service provider should be verified at least annually.
Related Regulations
This policy is a component of the HCC information security program that is intended to comply with the PCI-DSS, FERPA, Gramm Leach Bliley Act, and other regulations.
Exceptions
Only the Chief Information Officer (CIO) or a designated appointee is authorized to make exceptions to this policy. Any requests for exceptions shall be made using the “Request for Policy Exception” form and a copy maintained by the CIO.
Violations
Any user found to have violated this policy may be subject to disciplinary action, up to and including notifying the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity
The Associate Vice President of Student Development and Social Support, or designee, will address violations for this policy by students as outlined in the Student Handbook.
Disclaimer
The college makes no warranties of any kind, whether expressed or implied, with respect to the information technology services it provides. The college will not be responsible for damages resulting from the use of communication facilities and services, including, but not limited to, loss of data resulting from delays, non-deliveries, missed deliveries, service interruptions caused by the negligence of a college employee, or by the user's error or omissions. Use of any information obtained via the Internet is at the user's risk. The college specifically denies any responsibility for the accuracy or quality of information obtained through its electronic communication facilities and services, except material represented as an official college record. The college also does not accept responsibility for removing material that some users may consider defamatory or otherwise offensive. Users should be advised, however, that dissemination of such material may subject them to liability in other forums.
Responsibilities
|
Role |
Responsibility |
|
Management |
Follows this policy for contracts with third parties. Appoints a point of contact for managing the relationship with the third party |
|
IT Staff |
Assists sponsors and owners of the business function to be outsourced with the due diligence required |
|
Information Security Officer |
Ensures the compliance with this policy |
References
|
Frameworks |
The National Institute of Standards and Technology (NIST) Cybersecurity Framework, Center for Internet Security (CIS) v8 Critical Controls |
|
Regulations and Requirements |
|
|
Supporting Standards and Procedures |
|
Date: January 22, 2026
Approved By: Senior Leadership Team