SECURITYDATAREQUIREMENTSCHECKLIST
(ProcurementProtectedInformation)
Pleasechoose Yes(Y)orNo(N)belowtoindicatetypesofCSU,Chicopersonalinformationtobecollected,shared,
accessed/transmitted,orstoredby subcontractororsubcontractor’sagentaspartofthecontractstatementofwork:
Line
esor
No?
Confidential‐CSU Level 1 (S ection 8065.S02)
rocurement
se
n
1.
Doesthesubcontractororagentemploy more than 100 employees, access more
than 1000
individual pieces of information (e.g., names and SSN, credit cards,
medicalrecords,orany
combination)orconductfullSAS70/SSAE16(TypeII)
audits?
N= Use Low Sec. Data
Requirements
Y = Use High Sec. Data
Requirements
PCIDSS;PADSS;NACH
Requirements; HIPAA Requirements
APPLICABLESECTIONS
LINES2thru6
2.
Namewithcreditca
rdpaymentto Universit
merchant ID
5.2
3.
urc
aseo
so
twaretoprocessname w
t
cre
tcar
payment to
n
vers
t
merchantID
5.3
4.
amew
t
paymentto
n
vers
t
an
account
5.4
5.
e
ca
recor
sre
ate
toan
n
v
ua
nc
u
ng
sa
t
n
ormat
on
5.5
6.
Psyc
o
ogica
counse
ingrecor
sre
ate
to an in
ivi
ua
5.5
APPLICABLESECTIONS LINES7thru 58
1,2,3,4, 5.1, 5.6, 6, 7, 8, 9
7.
▪The application stores passwordsorcredentialsthatgrant access to level 1 and level 2 data
8.
▪The application stores PINs(PersonalIdentificationNumbers)
9. ▪
rt
atecom
ne
w
t
ast
our
g
ts o
an
name
10.
▪
re
tcar
num
ersw
t
car
o
er name
11. ▪
ax
w
t
name
12.
▪Driver’slicensenumber,stateidentification card, and other forms o
national orinternational identification
(suchaspassports,visas,
etc.)incombinationwithname
13. ▪
oc
a
ecur
t
num
eran
name
14.
▪
ea
t
nsurance
n
ormat
on
15. ▪
e
ca
recor
sre
ate
toan
n
v
ua
nc
u
ng
sa
ty
16.
▪
syc
o
og
ca
ounse
ngrecor
sre
ate
to an
n
v
ua
17.
▪Bankaccountordebitcardinformation in combination with an
required securit
code,access code,
orpasswordthatwould
permitaccesstoanindividual'sfinancialaccount
18. ▪
ometr
c
n
ormat
on
19.
▪
ectron
cor
g
t
ze
s
gnatures
20. ▪
r
vate
e
g
ta
cert
cate
21.
▪
awen
orcement personne
recor
s
22. ▪
r
m
na
ac
groun
c
ec
resu
ts