Software Risk Management Standard
Purpose
This standard establishes a consistent, risk‑based process for evaluating, approving, and managing software that may introduce significant operational, security, privacy, compliance, or reputational risks to Elon University. It supports the university’s goals of protecting institutional data, ensuring responsible technology adoption, and enabling academic and administrative innovation.
Scope
This Standard applies to all:
- University‑owned, leased, or managed devices
- Cloud‑based and on‑premises software solutions
- Academic, administrative, research, and auxiliary units
- Faculty, staff, contractors, student employees, and affiliates who procure or deploy software on behalf of Elon University
It covers:
- New software acquisition
- Renewal of existing software
- Third‑party integrations
- Free or freemium tools used with institutional data
- Software that is currently blocked by the university due to industry identified risks
Definitions
Software With Significant Risk
Software is considered high‑risk if it meets any of the following criteria:
- Handles sensitive or regulated data (e.g., FERPA, HIPAA, GLBA, research data, personal information).
- Integrates with enterprise systems or Single Sign-On (SSO).
- Transfers university data to external parties.
- Has access to large volumes of institutional or personal data.
- Impacts critical university operations (academic, financial, safety, or research systems).
- Is AI or machine learning technologies that process institutional data.
Exception
A documented, approved deviation from this standard will be granted when compensating controls or business justification sufficiently reduce risk.
Software Risk Management Standards
- All software posing potential risk must undergo an assessment before purchase, renewal, or deployment. Assessments are managed by Information Security, with coordination from IT Operations, Procurement, and Business Owners.
- Depending on the use case, the following may be required:
- Formal Security Risk Assessment (SRA); Information Security reviews application security, data flows, authentication/authorization, encryption, incident response, vendor security posture, vulnerabilities, and system architecture.
- Privacy/Data Protection Review: Compliance Managers validates compliance with FERPA, GDPR, PCI, state privacy laws, contractual terms, data retention, and consent requirements.
- Accessibility Review: Compliance ensures compliance with WCAG 2.1 AA and institutional accessibility policies.
- IT Operations Review: Information Technology will determine operational maintainability, including:
- Hosting/environment suitability
- Authentication Requirements
- Data Location Requirements
- Logging & Monitoring Requirements
- Integration Standard
- APIs must use secure protocols and validated schemas
- Change Management Coordination
- Disaster Recovery Expectations / Backup/restore expectations
- System performance or bandwidth requirements
- Patch management and update expectations
- Supportability by existing IT teams
- Risk decisions should align with Elon’s security and compliance frameworks to ensure consistency and rigor.
- The university reserves the right to rescind approval if new risks emerge (e.g., vendor breach, audit findings, or change in functionality).
- Approved software may require annual or biennial reassessments, security review upon major feature changes, incident reporting obligations for vendors, patch/vulnerability management review, or review of third‑party attestations (SOC 2, ISO, penetration tests) based on the data being used, transmitted, or processed within the application.
- When a business need justifies use of higher‑risk software, the business owner must document their Exception Request. Information in the request should include a business justification, risk acceptance rationale, data involved and the compensating controls necessary to mitigate the risk. The controls may include restricted data use, limited user access, network segmentation, enhanced monitoring/logging, or vendor security audit requirements.
- All application requests, risk reviews, exception requests and use decisions will be logged in Elon’s electronic ticketing system.
Noncompliance with this standard may result in denial of procurement, disabling integrations or SSO, removal or blocking of software from institutional networks and/or escalation to leadership.