The Vendor Security Assessment Program is intended to ensure that Vendors that will handle or have access to UC Data or IT Resources classified as P3/P4 meet campus security policy requirements. This is achieved in two ways:
- By evaluating the vendor's security controls in comparison to campus policy.
- Ensuring that the UCOP Data Security & Privacy Appendix is included in the vendor contract to provide baseline protection for the University in the event of a data breach.