How to Use Published Assessments

OVERVIEW

Cybersecurity Central Published Assessments is a document library where OU IT publishes completed technology risk assessment reports that may be reused by the OU community when evaluating commonly requested technologies.

CLASSIFY YOUR DATA

Classifying your data will help guide your use of the Published Assessments.

 Category

 Examples

A

 Healthcare Data

 Medical Records, Insurance Info, ePHI identifiers

B

 Payment Card Data

 Cardholder Name, Number, Date

C

 Student Data

 FERPA Records, Class Lists, Assignments, Enrollment

D1

 Confidential Research Data

 Export Controlled Research, NIH, Controlled   Unclassified Information (CUI)

D2

 Research Data

 Unpublished Research, De-identified Research,   Intellectual Property

E

 University Administrative and Financial Data

 Financial Transactions, Personnel Records, Emergency   Procedures

F

 Public Data

 Published Research, Press Releases, Course   Information, Job Postings

WHEN TO USE THIS LIBRARY

Use the Published Assessments library before submitting a new technology risk assessment request when you are evaluating a technology, cloud service, software product, or vendor solution that may have already been reviewed by OU IT. The library can help you confirm whether an existing assessment is available, understand the approved use case, and determine whether your intended use aligns with the data categories and conditions documented in the published report.

SEARCH BEFORE SUBMITTING A NEW REQUEST

  1. Open the Published Assessments library at https://www.ou.edu/ouit/assessments.
  2. Search for the technology, product name, vendor name, or service name associated with your request.
  3. Review any matching assessment reports to determine whether the report applies to the technology and intended use you are considering.
  4. Compare your planned use of the technology to the approved data categries, approved use case, and any documented limitations or conditions in the report.
  5. If the published report does not match your intended use, or if your use involves data categories not approved in the report, submit a new assessment request for review at https://www.ou.edu/ouit/newassessment.

HOW TO INTERPRET A PUBLISHED REPORT

A published assessment report should be reviewed as documentation of a specific assessment outcome for a defined technology, use case, and data classification. Pay particular attention to the approved data categories listed in the report. These categories describe the types of OU data that were evaluated and approved for the documented use. If your intended use includes different, additional, or more sensitive data than what is listed, do not assume the published assessment applies. In those cases, a new or updated assessment may be required before the technology is used for that purpose.  See our How to read an IT Security Assessment Report knowledgebase article.

Print Article

Related Articles (1)

Starting July 1, 2024, the OU IT Security Profile Summary, shared when a security assessment has been completed, is changing it’s look and feel.

Related Services / Offerings (1)