Third-Party & Vendor Risk Management Policy (SFA 06-107.4)

Summary

Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.

Body

Quick Overview
  • This is one of SFA's information security policies under SFA 06-107. It sets the rules for working safely with outside vendors and service providers.
  • It makes vendor security and privacy review a required step before SFA signs any contract with a vendor that will touch SFA data or systems.
  • It applies to every SFA employee, department, and unit that buys from, contracts with, or otherwise brings in a third party, no matter the funding source or contract type.
  • A policy says what SFA must achieve. The matching standards say how. This policy is carried out mainly through the Cybersecurity Risk Management Standard and the Personnel & Third-Party Security Standard.
  • Following this policy is mandatory. Skipping the required review can lead to disciplinary action and can void a vendor contract.

Stephen F. Austin State University relies on outside vendors, service providers, contractors, and cloud providers to deliver many essential services, and those third parties often store, process, transmit, or connect to SFA data and systems. That convenience also brings risk: a weak vendor can expose university data just as easily as a weak internal system. This policy makes sure that every vendor who will handle SFA data or reach SFA systems is checked for security and privacy risk before a contract is signed, and that the university keeps watching that risk for as long as the relationship lasts. It does not contain step-by-step instructions; those live in the supporting standards and procedures.

i
How the pieces fit together
Policy = the goal (what SFA must achieve).   Standard = the requirement (the specific rules that meet the goal).   Procedure = the how-to (the exact steps a team follows). This document is a policy. It is put into practice mainly by the SFA 06-107.1.2 Cybersecurity Risk Management Standard and the SFA 06-107.1.3 Personnel & Third-Party Security Standard, with support from several other standards listed near the bottom of this article.

Who This Applies To

This policy applies to all SFA employees, departments, and units that procure, contract with, or otherwise engage third parties, including:

  • Anyone who buys from or contracts with a vendor that will store, process, transmit, or access SFA data
  • Anyone bringing in a vendor that will have logical or physical access to SFA information systems or networks
  • Anyone engaging a service that is integrated with or dependent upon SFA information resources
  • All procurement activity, regardless of funding source or method: purchase orders, master service agreements, statements of work, data sharing agreements, memoranda of understanding, grant subawards, and software-as-a-service (SaaS) subscriptions

Wherever you see an italicized term in the full policy, its exact meaning is in the SFA 06-107 Definitions.

Who Is Responsible

The policy assigns specific duties across procurement, security, privacy, and legal. Most users won't hold these roles, but it helps to know who is accountable, especially who has to sign off before a vendor contract can move forward. Expand for a plain-language summary of the key roles.

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person. This article uses CISO for the person and Office of Information Security for the office.
  • Institutional Agency Head (President): Ensures SFA's procurement policies require the CISO and Privacy Officer to take part in third-party risk assessments before any contract is signed (as required by TAC 202.77).
  • Chief Business Officer (CBO): Ensures procurement and contracting enforce the security review "gate," so no vendor accessing SFA data is contracted before CISO and Privacy Officer review.
  • Chief Information Security Officer (CISO): The primary authority for vendor security risk. Builds and runs SFA's vendor risk management program, sets the review criteria, and can delay or block a purchase that carries unacceptable risk, working independently of procurement.
  • Privacy Officer (PO): Makes sure vendor engagements follow privacy laws (FERPA, HIPAA, GLBA, GDPR), reviews how vendors handle data, and ensures the right data use agreements and Business Associate Agreements are in place.
  • Office of General Counsel (OGC): Reviews and approves vendor contract language on security, privacy, data handling, breach notification, indemnification, and liability.
  • Departmental Procurement Initiators: Start the vendor security and privacy review early, before contract negotiation, and never execute a contract with a data-accessing vendor without documented CISO review.
  • Vendors / Third Parties: Cooperate with SFA's assessments, answer security questionnaires accurately, keep required controls and certifications throughout the contract, and report incidents and material changes promptly.
Full role definitions The complete list of responsibilities for every role is in the attached policy PDF (Sec. 3, Authority).

What This Policy Covers

The policy sets objectives in two goal areas: checking a vendor before you sign, and managing the risk while the vendor is engaged. Expand any section below to see what it covers in plain language and which standard puts it into practice.

4.1  Vendor Security Review Objectives  Checking a vendor before you sign ⌄

Before SFA does business with a vendor that will touch SFA data or systems, that vendor has to pass a security and privacy check, and the contract has to include the right protections.

  • Mandatory pre-contract review: Any vendor that will store, process, transmit, or access SFA data, or reach SFA systems, must complete a security and privacy risk assessment run or approved by the CISO before the contract is signed or access is granted.
  • No contract, purchase order, or data sharing arrangement may be finalized without documented CISO review (and Privacy Officer review where applicable).
  • The depth of the review scales with the risk: the more sensitive the data and the more critical the service, the deeper the check.
  • Cloud services and TX-RAMP: Cloud vendors handling SFA data must be checked for Texas Risk and Authorization Management Program (TX-RAMP) certification before signing or renewing, and must keep that certification current for the life of the contract.
  • Contract security requirements: Contracts must spell out permitted uses of SFA data, minimum security controls, incident notification timelines, data return or destruction at the end, audit rights, legal compliance, and (for cloud) where the data is stored and under whose jurisdiction.
  • Special contract terms (HIPAA Business Associate Agreements, CJIS security addendums, AI data-use provisions) must be added when they apply, following the relevant SFA 06-107 standards.
!
Important
The CISO security review is a hard gate. No contract or agreement involving SFA data or system access may be executed without documented CISO review completion. The CISO can delay or block a purchase until the review is satisfied.
Put into practice by SFA 06-107.1.2 Cybersecurity Risk Management Standard · SFA 06-107.1.3 Personnel & Third-Party Security Standard · SFA 06-107.1.7 Information Security HIPAA Compliance Standard · SFA 06-107.2.7 CJIS Security Policy Compliance Standard · SFA 06-107.1.8 Artificial Intelligence Governance Standard
4.2  Ongoing Vendor Risk Management Objectives  Managing risk while the vendor is engaged ⌄

Signing the contract isn't the end of it. SFA keeps an eye on vendor security for as long as the relationship lasts, handles vendor incidents, and makes sure data comes back safely when the relationship ends.

  • Continuous monitoring: Vendor security and privacy controls are checked on a risk-based schedule throughout the contract, with at least an annual review for vendors that handle Confidential data, plus a fresh review whenever the vendor reports a major change, a security incident, or a change in subcontractors handling SFA data.
  • Vendor incident notification: Contracts must require vendors to report confirmed or suspected security incidents involving SFA data to the CISO without unreasonable delay. The CISO sets standard notification timelines in contract templates and folds vendor incidents into SFA's own incident response process.
  • Offboarding and data disposition: When a contract ends, SFA data must be returned or securely destroyed within the agreed timeframes, the CISO verifies it happened and keeps records, and the vendor's system access is revoked promptly.
Put into practice by SFA 06-107.1.2 Cybersecurity Risk Management Standard · SFA 06-107.1.3 Personnel & Third-Party Security Standard · SFA 06-107.2.6 Incident Management Standard · SFA 06-107.1.5 Information Data Protection & Privacy Standard

Compliance, Exceptions & Enforcement

Compliance with this policy is mandatory for everyone involved in procuring or managing third-party vendors. No vendor contract or agreement that involves SFA data or access to SFA systems may be executed without completing the CISO security review this policy requires. The Chief Information Security Officer (CISO) has the authority to delay or block contract execution until vendor security review is satisfactorily completed.

!
Important
Violations of this policy may lead to disciplinary action, up to and including involuntary separation from employment. A vendor contract executed without the required security review may be nullified (voided).

Compliance Mapping (Reference)

This section is for auditors, security staff, and anyone who needs the underlying control references. Everyday users can skip it.

Frameworks & control references ⌄

SFA 06-107.4 was written to align with the following authoritative sources cited in the policy:

  • Texas Administrative Code (TAC) 202, Subchapter C: the state rule for information security at Texas institutions of higher education (for example 202.72, 202.73, 202.75, 202.77).
  • Texas Government Code §2054.0593: the state's TX-RAMP requirement for cloud services.
  • Texas DIR Security Controls Catalog: the state's baseline control set (for example SA-9, IR-6, MP-6, SR-12).
  • NIST 800-53 Revision 5.1.1: the federal security and privacy control catalog (for example SA-4, SA-9, SA-9(01), IR-6, MP-6, SR-12).
  • NIST Cybersecurity Framework (CSF): supply-chain governance outcomes (for example GV.SC-04 through GV.SC-10, RS.CO-03).
  • UT System UTS 165: the UT System information security policy (Vendor Risk Management).
  • Applicable federal privacy regulations where relevant: HIPAA, FERPA, GLBA, and GDPR.

Each objective in the policy lists the specific control numbers it maps to. The complete objective-by-objective mapping is in the attached policy PDF and in the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

This policy is implemented through the following standards:

Related standards:

Other references:

  • Texas Risk and Authorization Management Program (TX-RAMP)
  • Texas Government Code §2054.0593 (TX-RAMP requirements)
  • Texas Government Code §2275 (Prohibition on contracts with certain foreign-owned companies)
  • SFA 06-107 Controls Crosswalk

Responsible office: Office of Information Security; Office of General Counsel; Procurement  ·  Contact: itsecurity@sfasu.edu

📎
Official document
The complete, official policy is attached to this article as a PDF, including its full objectives, role definitions, and control mappings. This article summarizes that policy in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this policy, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173921
Created
Thu 7/16/26 2:16 PM
Modified
Fri 7/17/26 12:50 PM

Related Articles

Related Articles (9)

Requirements for the responsible procurement, deployment, and use of artificial intelligence at SFA, including AI governance, inventory and risk classification, data-input controls, prohibited uses, human oversight of consequential decisions, and testing and monitoring; supports Policy 06-107.1.
Requirements for protecting Criminal Justice Information (CJI) in line with the FBI CJIS Security Policy, including access control, multi-factor authentication, personnel background screening, media protection, physical security, and audits; applies primarily to the University Police Department and supports Policy 06-107.2.
Requirements for identifying, assessing, and managing cybersecurity risk at SFA, including risk assessments, continuous monitoring, control assessments, and vendor risk management; supports Policy 06-107.1.
Requirements for preparing for and responding to security incidents at SFA, including incident planning, response, communication, and reporting; supports Policy 06-107.2.
Requirements for protecting SFA data and personal information throughout its life, including data handling and classification, encryption and transmission, consent and notices, and retention; supports Policy 06-107.1.
Requirements for governing SFA's security program, including the security strategy, documentation, leadership roles, planning and reporting, system inventory, and the insider-threat and research-security programs; supports Policy 06-107.1.
Requirements for protecting Protected Health Information (PHI) at SFA's Academic Clinics designated as HIPAA Healthcare Components, covering administrative, physical, and technical safeguards, business associate agreements, privacy, and breach notification; supports Policy 06-107.1. Student Health and Counseling records are FERPA-governed and out of scope.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Requirements for managing the security responsibilities of staff and vendors across the employment lifecycle, from screening and rules of behavior through transfers, offboarding, and discipline; supports Policy 06-107.1.