Skip to main content

Standard for Information Security Related to Vendors and External Parties

I. Purpose

The purpose of this standard is to establish the university’s obligation to ensure the protection of university assets accessible or hosted by vendors and other external parties.

II. Scope

It is the responsibility of any faculty or staff working with vendors and other external parties who may be accessing or hosting university assets to understand and apply information security policies, standards, and guidelines which ensure appropriate security for those assets.

III. Contacts

Direct any general questions about this standard to your unit’s Information Security Liaison. If you have specific questions, please contact OneIT Information Security Compliance at ISCompliance-group@charlotte.edu.

IV. Standard

When providing vendors and other external parties with access to university assets or when contracting with vendors and other external parties to host university systems or services, steps should be taken to ensure the protection of those assets. Agreements or contracts with vendors and other external parties should include the following security controls:

Related Resources

ISO/IEC 27002 was adopted by The University of North Carolina at Charlotte in 2012. All standards and guidelines are based on this code of practice for Information Security Management.

Revision History

Initially approved by Information Assurance Committee 6/05/15
Updated 6/6/24