Application and Cloud Services Assessment Requestor Questionnaire v6.0 Header Image

Application and Cloud Services Assessment Requestor Questionnaire


The Risk and Compliance team assesses server applications or services for appropriate use for the specific data type and this questionnaire assists in providing an understanding of your IT purchase to determine if a full assessment is necessary. Please fill out the questionnaire below and we will begin our assessment. Please note, we complete requests in the order we receive them and timelines are dependent on the responsiveness of the requestor, vendor, and the complexity of the agreement.

Product Information

Please indicate if there is a deadline to complete this purchase:
What are you purchasing? (Select all that apply):*
What is the term of this contract/purchase/agreement?*
Will University data be collected, processed, or stored through the use of this application? *
What is the classification of the data used for this application/service? Please refer to this Data Classification link ( https://www.cu.edu/security/data-classification ) for guidance and select one option below: *
What is the potential impact if a loss of data confidentiality, integrity, or availability occurs? High, Moderate, or Low - as defined on this link https://www.cu.edu/security/about-adverse-impact*
Where do users access data from?*
Where is the data stored?*
Is an internet connection required to send data out to an external vendor resource?*
How will you be purchasing this product/application? *(Select all that apply):? *
What type of purchase is this? *
If this is a renewal, do you have a current Business Associate Agreement (BAA) with the vendor? If “yes,” please provide a copy via email.*

If you have not already, please reach out to the Office of Regulatory Compliance (ORC) using the link (https://redcap.ucdenver.edu/surveys/index.php?s=LNXN9C3JM9) to determine if a BAA is needed since this application will be used with HIPAA/PHI data 

More information can be found here https://research.cuanschutz.edu/regulatory-compliance/home/hipaa/business-associate-agreements

Please note, this process is separate from the Application Assessment process. 

If you selected, “On-premise” or “Off-premise” solution to the question "Where is the data stored?" additional information is needed. Please respond to questions in the following section.

Will this product collect, process, or store any of the following personally identifiable information (Select all that apply)? *
How do users access this application/service?*
Will this product collect, process or store any of the following data types (Select all that apply)? *
If PHI is stored, will the data be de-identified? *

If you have not already, please reach out to the Office of Regulatory Compliance (ORC) using the link (https://redcap.ucdenver.edu/surveys/index.php?s=LNXN9C3JM9) to determine if a BAA is needed since this application will be used with HIPAA/PHI data 

More information can be found here https://research.cuanschutz.edu/regulatory-compliance/home/hipaa/business-associate-agreements

Please note, this process is separate from the Application Assessment process. 

How many records will be stored/processed in the product or application?*
Records may be applicable to the amount of data stored on each individual or it can apply to the amount of data files stored.
Will this request require integration with other CU Systems?*

If yes, the integration is a separate process. Please fill out this form to begin the data integration process - https://forms.ucdenver.edu/secure/dataintegrationrequest

Who will have access to the data: *
In accordance with University policy, will University data be stored within the US? *
Save and Resume Later
Progress