Third-Party Integration Procedure
The purpose of this procedure is to ensure third-party integration contracts and service level agreements follow best practices.
This IT document, and all policies referenced herein, shall apply to all members of the University community including faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
- You must adhere to the Third-Party Integration Policy.
- When engaging with third-party integrations, the following must be arranged:
- Third-parties must have a formal, documented, and automated process for granting and revoking access to all systems that process or store Fordham Sensitive Data.
- Third-party’s User access rights shall be strictly limited to a need-to-know basis that permits access only to the systems and resources that are required for Users to perform their duties.
- Third-party Users with authorized access to Fordham Sensitive Data must be assigned a unique User ID, which must not be shared with any other individuals.
- Authenticators used in multi-factor authentication (MFA) must provide secure storage protections.
- Access rights must be revoked immediately and in an automated fashion upon the termination of any third-party User with access to the University’s IT Resources or if a change in job role eliminates the requirement for continued access.
- Third-parties must annually review User all-access rights authorizations.
- All third-party User access to systems storing Fordham Sensitive Data must be audited, maintained, and made available to the University, either upon request or as an automated log transfer.
- All systems that process or store University data must maintain an automated audit trail that documents system security events and any event that results in the access, modification, or deletion of University data.
- The audit trail must, at a minimum, record the following information for each event:
- The identity of any user/subject,
- Date and time,
- Source (e.g., email, SFTP record), and
- Outcome (success or failure) associated with the event.
- The audit logs must be read-only and protected from unauthorized access.
- Audit records documenting events (e.g., access, modification, deletion) must be made available to the University either upon request or as an automated log transfer.
- The third-party must employ a regular audit log review process (either manually or automated) for the detection of unauthorized access to University data.
- Initial data loads typically performed via SFTP must require PGP or GPG encryption of the data before transfer using 4096 bit or greater keys.
- Data integrations must be performed via APIs and messaging queues not via flat file transfers.
GNU Privacy Guard (GPG, also GnuPG) is a free encryption software that's compliant with the OpenPGP (RFC4880) standard.
IT Resources include computing, networking, communications, application, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and any related materials and services.
PGP encryption (Pretty Good Privacy encryption) is a data encryption computer program that gives cryptographic privacy and authentication for online communication. It is often used to encrypt and decrypt texts, emails, and files to increase the security of email.
Related Policies and Procedures
- Data Classification Guidelines
- Data Classification Policy
- Data at Rest Policy
- Data in Transit Policy
- Third-Party Integration Policy
|Responsible Person:||Director, IT Risk and Data Integrity|
|Approval Date:||November 25, 2019|