When Northwestern University engages a third-party service provider, the Information Security Office (ISO) is tasked with evaluating the service provider’s information security controls by conducting a Service Provider Security Assessment (SPSA).
The Information Security Policy Exception form for requesting an exception to a related Policy or Standard.
The Risk Exceptions ticketing workflow is designed to provide a consistent, auditable mechanism for requesting, reviewing, tracking, and closing risk exceptions associated with University systems, platforms, or services.
Northwestern Information Technology manages this service to centralize contract reviews and ensure required security, privacy, risk, and compliance assessments are completed.