Protection Level & Risk Classification Guide

This guide is used to help you decide whether a project is Low risk or High risk.
It can also help you fill out the Supplier Security Review Questionnaire (SSRQ) PDF form.
Answer the questions below, then download the results and send them to SocIT for review.

About UCI Protection Levels ↗  ·  About SSRQs ↗

What the two risk bands mean
Risk bands and their protection levels
BandProtection levelsWhat happens
Low riskP1, P2Public or internal-use information. SocIT can review and provide low risk approval. An OIT Security Review is not required.
High riskP3, P4Sensitive or legally protected data. An OIT Security Review is required before use.

Step 1: Tell us what you are reviewing

Examples: “Qualtrics”, “Otter.ai”, “NIH Study 1234 interview transcripts”.

Data types, data sources, sponsor or contract, approximate number of records, who will have access, and how the supplier will be used. This text is copied into the SSRQ.

Does this involve personally identifiable information (PII) about people?
Does this involve an outside supplier, vendor, or a software / service purchase?

An SSRQ is only generated when this is Yes.