This guide is used to help you decide whether a project is Low risk or High risk.
It can also help you fill out the Supplier Security Review Questionnaire (SSRQ) PDF form.
Answer the questions below, then download the results and send them to SocIT for review.
Public or internal-use information. SocIT can review and provide low risk approval. An OIT Security Review is not required.
High risk
P3, P4
Sensitive or legally protected data. An OIT Security Review is required before use.
AcroForm field inspector
Reading ssrq-blank.pdf with pdf-lib and listing every form field, its type, and (for radios / checkboxes / dropdowns) its valid export values and widget coordinates.
Examples: “Qualtrics”, “Otter.ai”, “NIH Study 1234 interview transcripts”.
Data types, data sources, sponsor or contract, approximate number of records, who will have access, and how the supplier will be used. This text is copied into the SSRQ.
Step 2: Classification questions
An explanation is required before you can continue.
Your answers so far
No questions answered yet.
Step 3: A few more details for the security review
Your answers indicate this may be higher risk, so we need to know which specific categories of data are involved.
Answer Yes, Unsure, or No for each. If you are not certain, choose Unsure and SocIT will help you confirm.
Result
Optional: click here for the exact protection level (P1–P4), definitions, and examples
Protection level reference with examples
Level
Definition
Examples
P1
Public. Already released or approved for public release.
Course catalog, published research findings, public web content, press releases.
Sensitive. Moderate damage, moderate fines, or moderate privacy impact.
Student records under FERPA, most identifiable human-subjects research data, personnel files, non-public financial or donor data.
P4
Highly sensitive / legally protected, or Critical IT Infrastructure.
PHI under HIPAA, SSNs, bank or payment card numbers, export-controlled or CUI research data, passport or driver license numbers, authentication and network core systems.
When in doubt between two levels, choose the higher one. A security review will determine the correct level.