Information Security Risk Management—Frequently Asked Questions (FAQ)
Getting started
-
As early as possible—ideally during planning or vendor selection—so we can identify risks before contracts are signed or code goes live. Early engagement helps avoid delays later.
-
Any engagement involving third-party vendors, cloud services, new software tools, or sensitive data (e.g., student records, health data, financial systems) should be assessed. When in doubt, contact us—we’d rather double-check than miss something important.
Assessment process
-
Our standard Service-Level Agreement (SLA) is 7–20 business days, depending on data sensitivity, risk complexity, and vendor responsiveness. Submitting your request early gives us time to keep you on schedule.
-
We’ll need:
- A brief description of the project or vendor
- Data classification (Restricted, Confidential, Internal, or Public)
- Hosting details (e.g., cloud vs. on-premises)
- Any vendor-provided security documentation (SOC 2 report, HECVAT, SIG questionnaire, etc.)
-
Security certifications like SOC 2, ISO 27001, or completed questionnaires help us assess the vendor’s controls and identify potential weaknesses. This saves time and allows for more accurate risk analysis.
-
No. We provide risk-based insights and recommendations. Final go/no-go decisions—and acceptance of any remaining risk—remain with your department or business unit.
-
Yes, provided your department formally acknowledges and accepts the remaining risk. We document these risks and may recommend additional controls, ongoing monitoring, or scheduled reassessments.
After the assessment
-
You’ll receive a formal report outlining identified risks, suggested mitigations, and a residual risk score. If action is needed, we’ll track it through follow-up reviews or recertification as appropriate.
-
- If you submitted via ServiceNow, you can track progress and communicate with our team through the Rutgers IT Service portal.
- If you used the Work Intake Form, updates will be shared through email as your request moves through our queue.
Additional topics
-
No. All core risk assessment services are provided at no cost to Rutgers departments.
-
We don’t issue pass/fail grades. We highlight risks and provide recommendations. If risk cannot be mitigated to an acceptable level, we’ll help you evaluate alternative options or protections.
-
We follow Rutgers’ Information Classification Policy, which includes:
- Public – General access data
- Internal – Operational data not intended for public distribution
- Confidential – Sensitive business data (e.g., HR, finance)
- Restricted – Regulated data like SSNs, health records, or financial aid data
-
A vulnerability is a weakness or flaw in a system, application, network, or physical environment that an adversary can exploit to gain unauthorized access, disrupt operations, or compromise data. These weaknesses can be found in software code, hardware configurations, physical security controls, or even human processes.
-
The CISA KEV list refers to the Known Exploited Vulnerabilities (KEV) Catalog maintained by the Cybersecurity and Infrastructure Security Agency (CISA). It includes vulnerabilities that are actively being exploited by malicious actors in the real world.
-
The Common Vulnerability Scoring System (CVSS) is used to assess the severity of vulnerabilities. Scores range from 0.0 to 10.0, with higher scores indicating more severe vulnerabilities.
-
Rutgers utilizes vulnerability management tools that apply the Common Vulnerability Scoring System (CVSS) to prioritize remediation actions. Vulnerabilities are categorized as Critical, Severe, or Moderate based on their CVSS scores.
-
The National Institute of Standards and Technology (NIST) maintains the National Vulnerability Database (NVD), which uses the Common Vulnerabilities and Exposures (CVE) system. Each vulnerability is assigned a unique CVE ID to help organizations track and manage them.
Explore the CVE system:NIST National Vulnerability Database (NVD)
CVE Program Official Site
