Use this article to help ensure compliance with HIPAA, PCI DSS, FERPA, CJIS, and NIST 800-171 (CUI).
Use the Published Assessments library before submitting a new technology risk assessment request when you are evaluating a technology, cloud service, software product, or vendor solution that may have already been reviewed by OU IT. The library can help you confirm whether an existing assessment is available, understand the approved use case, and determine whether your intended use aligns with the data categories and conditions documented in the published report.
The National Defense Authorization Act Section 889 (NDAA 889) prohibits executive agencies from entering into, or extending or renewing, a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, on or after August 13, 2020, unless an exception applies or a waiver is granted.
As an Owner of a Microsoft SharePoint site or Teams space, you play a critical role in protecting institutional data and ensuring compliance with security and governance policies. This guideline outlines your responsibilities to secure data, manage access, and periodically review permissions.