Security Standards for Technology Purchasing

Overview

This article describes the technical security standards used when evaluating technology solutions at the college. These standards align with the CIS Critical Security Controls and support the ITS Tiered Support Framework by defining baseline security capabilities expected from software applications, SaaS platforms, and hardware solutions.

These standards are used during technology review, procurement, and implementation to help ensure technology solutions can be securely deployed, supported, and maintained within the college environment.

Relationship to the Tiered Support Framework

The ITS Tiered Support Framework defines the level of operational support provided for technology solutions.

Technology that meets the defined technical and security standards generally qualifies for Tier 2 support. Solutions that do not meet one or more of these standards may be classified as Tier 3 and require additional risk review.

Tier classifications are determined based on the solution’s ability to meet operational, security, and support requirements.

Alignment with CIS Critical Security Controls

The college aligns its technical security standards with the CIS Critical Security Controls framework, which provides a prioritized set of cybersecurity best practices.

Key control areas supported by these standards include:

CIS Control 1 – Inventory and Control of Enterprise Assets
Technology must be compatible with institutional device and asset management platforms.

CIS Control 2 – Inventory and Control of Software Assets
Applications must support centralized deployment and lifecycle management.

CIS Control 4 – Secure Configuration of Enterprise Assets and Software
Solutions must support secure configuration management and administrative controls.

CIS Control 5 – Account Management
Systems must support managed user accounts and administrative oversight.

CIS Control 6 – Access Control Management
Systems must support role-based access control to ensure users only have access to appropriate resources.

CIS Control 7 – Continuous Vulnerability Management
Solutions must support patching and remediation of discovered vulnerabilities.

CIS Control 8 – Audit Log Management
Where applicable, systems should support logging or integration with monitoring capabilities.

CIS Control 12 – Network Infrastructure Management
Hardware and network-connected devices must support secure networking protocols and enterprise networking standards.

Identity and Access Management Requirements

Systems must support appropriate access control mechanisms to manage user permissions and administrative access.

Where supported by the vendor, systems should integrate with the college identity platform using Microsoft Entra ID or SAML authentication.

However, the absence of Single Sign-On does not automatically disqualify a solution. Systems must still provide adequate access control capabilities.

At a minimum, systems must support role-based access control (RBAC) to allow administrators to manage user permissions and restrict access based on job function.

Administrative access should be protected through strong authentication methods such as multi-factor authentication where supported.

System Management and Vulnerability Management

Technology solutions must support ongoing system maintenance and security updates.

This includes:

  • Vendor-provided security updates and patches

  • The ability to remediate vulnerabilities identified through institutional vulnerability management processes

  • Compatibility with enterprise application or device management platforms where applicable

If vulnerabilities cannot be remediated due to vendor limitations or technical constraints, the department must coordinate with ITS Cybersecurity to determine appropriate mitigation strategies.

Depending on the severity of the vulnerability and associated risk to the college environment, additional safeguards may be required.

Application Criticality

Security and operational requirements may vary depending on the importance of the application to institutional operations.

Application criticality is categorized as:

Statewide Critical - This application has a direct impact to statewide essential functions, processes, activities, or population.

Department CriticalThe application directly impacts essential functions, processes, or activities of the college

Program CriticalThe application directly impacts the essential functions, processes, or activities associated with a specific department or program.

Noncritical - The application does not directly impact essential institutional or program functions.

Applications classified as Statewide, Department, or Program Critical may require stronger operational controls, higher availability expectations, and more rigorous security review.

Data Classification

Security requirements for technology solutions are influenced by the type of data the system stores, processes, or transmits. Technology solutions that store or process Restricted or Highly Restricted classification data may require stronger security controls, additional vendor security review, and stricter access management.

Institutional data is classified into the following categories:

Low

Data that presents minimal risk to the institution if disclosed, altered, or unavailable. Examples may include publicly available information or data that is appropriate for general access by the public.

Internal

This is information typically used within the institution and not for public sharing. Most documents are classified as 'Internal' within the college, and most internal users would have access. This type of data, if exposed to unauthorized parties, would have a very limited impact on the college's reputation, compliance requirements or ability to achieve strategic goals. Internally classified data does not contain direct identifiers. Examples may include standards, guidelines, or internal newsletters.

Restricted

Data that could result in operational disruption, reputational impact, or regulatory implications if disclosed or altered. This may include sensitive internal business information or data used in routine institutional operations.

Highly Restricted

Sensitive data that could result in significant harm to the institution, its employees, or students if disclosed, altered, or unavailable. This typically includes regulated data or information that requires stronger security protections.

Note: Systems that store or process Restricted or Highly Restricted classification data are expected to support stronger access controls, encryption where appropriate, and enhanced security monitoring capabilities.

Evaluating Technology Against Security Standards

Before requesting to purchase or implement new technology, departments are encouraged to confirm that the solution can meet the college’s technical and security standards. A detailed list of these requirements can be found in the Technical Support Standards knowledge base article.

Gathering this information from the vendor early in the evaluation process helps ITS determine whether the technology aligns with institutional requirements and can significantly reduce delays during the security and support review process.

If this information is not available during the initial review, ITS may need to request additional documentation from the vendor, which can extend the review timeline and delay purchasing or implementation.

When evaluating technology solutions, departments may wish to confirm the following with vendors:

Access Control and Authentication
Does the solution support role-based access control to manage user permissions?
Does the solution support SAML or Microsoft Entra ID Single Sign-On?
If SSO is not supported, what authentication and multi-factor authentication options are available?

Endpoint Software
Does the application require users to have local administrator privileges to run?
Can the application be deployed and managed through enterprise endpoint management platforms such as Intune or Jamf?

SaaS Solutions
Where is institutional data stored and processed?
What security controls protect customer data?
How are security updates and vulnerability patches managed by the vendor?

Network-Connected Devices or Hardware
Does the device support secure communication protocols such as HTTPS or SSH?
Is the device compatible with enterprise Wi-Fi and networking standards?

Providing this information when submitting a technology request helps ITS complete the review more efficiently and reduces the likelihood of delays during procurement or implementation.

Further Reading