Overview
This revised software procurement process will simplify and improve our current manual review methods. This effort works to streamline operations, enhance cost-efficiency, ensure regulatory compliance, and elevate management of our software solutions across the board.
How do I use this process?
This replaces the current manual process of requesting a waiver and emailing multiple groups for review.
- ALL software intended for use on UA owned devices, or that handles UA data must use this process. This includes open source, freeware, SaaS, paid subscriptions, bulk licensing, etc.
- When a university employee would like to obtain NEW software, not currently available to the University community, a request will be made via the software request form.
- For currently available software, the UA Software Register will identify software currently approved for use. This Register will be updated weekly. Requests will STILL NEED TO BE MADE to use the software. This captures the sensitive data information and identifies the contract administrator.
- Once the request is approved, the requestor (and contacts) will receive an email that they can move forward with procurement or download.
Roles and Responsibilities
The roles and responsibilities identified below are all persons that are required at various points due to the nature of the software and/or funding involved.
- Requester: This is the end user of the software. End users are asked to gather as much information from the vendor as possible to include; accessibility documentation, data storage location, geographical location among others as identified during the question sequence. If the person entering the information into the form is NOT the end user - they need to identify the individual and put their name as the requester.
- IT Service Desks: responsible for ensuring the accuracy of the request details entered. Also reviews for MAU specific software restrictions. **On Long Form Only
- Contract Administrator: responsible for the life of the software in the system. This includes being responsible for maintaining the subscription, notifying IT/Procurement of any changes in its use, and closing out the contract when no longer needed. The revised Contract Administrator Guidelines link can be found in Additional Information section below.
- Reviewer Groups: reviews the software for their specific functional areas.
- Disabilities Services: ensures the software is compliant with any accessibility obligations.
- Registrars: ensures student data is compliant with FERPA.
- Export Control: ensures the software is compliant with any Federal export control regulations.
- Federal Tax: ensures that software owned by foreign vendors is compliant with Federal regulations.
- Contract T&C/EULA: ensures that the terms and conditions are in agreement with UA requirements.
- Privacy/Data Security: provides the data security, data retention, and data privacy reviews.
- MAU CIO/CMT Exception Approval: reviews requests for exceptions to this process.
Additional Information