Information Assurance
Reporting to the CISO, Information Assurance (IA) protects the University’s data, supports research, and proactively surfaces IT risk whenever possible.
We partner with academic, administrative, and research units to assess cybersecurity practices, guide risk-informed decision-making, and promote regulatory compliance. Through a combination of assessments, consultations, and governance activities, IA helps the University securely enable technology while managing cyber risk. Our work can be divided into the following three categories:
-
Risk Assessment and Consultation
-
Governance, Training, and Policy
Security Framework Assessment
The Information Assurance team conducts an annual assessment of University units’ cybersecurity posture using the Cybersecurity Framework (CSF). At the conclusion of the security framework assessment (SFA) cycle, the Information Assurance team provides recommendations on how to address common cybersecurity gaps across campus and how each unit can improve its cybersecurity posture.
Security Framework Assessment (SFA) FAQ
Vendor Risk Reviews
Information Assurance conducts vendor risk reviews in consultation with the Financial Services’ Procurement and Payment Processes team. The team reviews agreements, statements of work, technical specifications, privacy policies, and integration plans. Information Assurance suggests modifications to contractual language, append appropriate information security terms, and identify IT practices that are required for successful implementation of the vendor’s product or service.
To request a vendor risk review in the context of a purchase, begin at the Procurement ServiceNow Intake.
For a general vendor risk inquiry outside the context of a purchase, email itrisk@uchicago.edu.
Risk Consultations
The Information Assurance team reviews products and services that a unit is considering prior to issuing an RFP or entering the procurement process. The team also assesses implementations of purchased solutions and evaluates the security of IoT devices. Additionally, the team reviews systems that may present elevated risks, recommending compensating controls where feasible or working with leadership to formally acknowledge and accept residual risks when necessary.
For Divisional Leadership: Divisional leadership may request an audit of its department’s existing security practices by requesting the General IT Security Offering, a collaborative review process involving a unit’s Technology Security team with the CISO’s office and IT Security.
General IT Security Offering
Generative AI Tool Evaluation Form
Plugin and App Request Form
IT Security Advisory and Compliance Request
Risk Acceptance Letters (RALs)
A Risk Acceptance Letter (RAL) is issued when a product under consideration for purchase presents risks that cannot be fully mitigated through contract negotiations. Information Assurance uses RALs to formally document that unit leadership has reviewed and accepted these risks in order to proceed with the purchase. RALs are not intended to alarm but to promote awareness and transparency around third-party risk. Each year, Information Assurance reviews active RALs to ensure they accurately reflect the University's third-party risk landscape and retires any associated with products no longer in use.
Risk Acceptance Letters FAQ
AI Tool Approval
A Risk Acceptance Letter (RAL) is issued when a product under consideration for purchase presents risks that cannot be fully mitigated through contract negotiations. Information Assurance uses RALs to formally document that unit leadership has reviewed and accepted these risks in order to proceed with the purchase. RALs are not intended to alarm but to promote awareness and transparency around third-party risk. Each year, Information Assurance reviews active RALs to ensure they accurately reflect the University's third-party risk landscape and retires any associated with products no longer in use.
Approved and Restricted AI Tools
Relevant Policies for the Use of AI Tools
Secure Research Data Strategy (SRDS)
The Secure Research Data Strategy (SRDS) was developed in an effort to create a shared understanding of our research security obligations. This understanding includes developing methodologies for data categorization based on the data involved in a project, the terms in any agreements, and identifying where there may be heightened risk. SRDS is a joint collaboration between representatives of Information Assurance, the University Research Administration, the IRB, and the Office of Research to develop solutions which keep the University safe and advance the University's core mission of research.
Research Tools’ Data Protection Levels
As part of the SRDS, Information Assurance maintains a list of common research tools and the SRDS protection levels for which their uses are approved.
Aligning Research Tools with Data Sensitivity and SRDS Requirements
University Research Administration Risk Reviews
Information Assurance conducts pre- and post-award risk reviews in coordination with University Research Administration, Research Project Principal Investigators, embedded IT Security and additional support resources. In each case, Information Assurance reviews the security requirements provided by the data lender and provides guidance on how to comply with these requirements so that the project is conducted in a regulatory-compliant manner.
To request a risk review through URA, submit an agreement review through the University Research Administration and ask about an IT Security Ancillary Review.
IRB Risk Reviews
Research involving human subjects often introduces security, privacy, vendor, architectural, and AI-related risks. Information Assurance reviews IRB protocols to evaluate whether the proposed technology, data handling practices, vendor relationships, and AI use align with the University’s Secure Research Data Strategy (SRDS), institutional policies, and applicable regulatory requirements, and provides recommendations to the IRB on tools and approaches that meet these standards.
For information about IRB risk reviews, contact the Social & Behavioral Sciences IRB Office.
Regulatory and Framework Compliance Support
Information Assurance (IA) provides guidance and consultation for regulatory and cybersecurity framework compliance efforts, including NIST SP 800-171, NIST SP 800-53, NIST Cybersecurity Framework (CSF) 2.0, and HIPAA. For research-specific requirements and support, please visit the Research Support page.
For NIST CSF 2.0 assessments, IA serves as the University's authoritative evaluator and may make maturity determinations directly. For regulatory frameworks and attestation-based requirements such as NIST SP 800-171, NIST SP 800-53, and HIPAA the preferred approach is an independent third-party assessment consistent with the expectations of data providers, sponsors, and regulatory bodies. IA maintains relationships with several approved assessment firms under established Master Services Agreements and can connect units with appropriate vendors to support their compliance and attestation activities.
To request regulatory and framework compliance support, email itrisk@uchicago.edu.
Security Awareness Training
Information Assurance helps shape the content for University-wide Security and Compliance training by leveraging Workday Learning. They can consult on the appropriateness of training specific to University unit’s compliance obligations.
To enroll your organization or unit in Security Awareness Training, submit a request through the University Services Portal. Requests must come from someone authorized to assign training and manage communications on behalf of the unit.
Technical Review Committee
The Technical Review Committee (TRC) is a governance unit of IT Services that reviews designs for significant technology implementations at the University of Chicago. The TRC evaluates these designs to implement new or change existing technology products or services through lenses of the University’s overall infrastructure strategy, technology standards, security standards, and industry best practices. Prior to procuring the solution, requesting parties submit a completed TRC questionnaire, committee members review it, then provide feedback to the requestor.
To request a TRC review, email itrisk@uchicago.edu.
Information Security Policies and Standards
The Information Assurance team leads the development and maintenance of the University’s information security policies. These policies establish the expectations and requirements for protecting University data, systems, and technology resources. Working in collaboration with stakeholders across campus, the team ensures that policies align with regulatory obligations, industry standards, and institutional priorities. The goal is to provide clear, actionable guidance that supports security, academic research, and operational excellence.
IT Exceptions
An IT Exception Request is used when a University department, system, device, or process cannot comply with a University IT policy or standard and requires approval for an alternative approach. Exception types include EUD Policy Exceptions, Vendor-Initiated Exceptions, Asset Management Standard Exceptions, API Credentials Rotation Standard Exceptions, and other technology or security policy exceptions.
IT Exceptions are reviewed against the applicable University policy or standard and, if accepted, are documented and tracked in ServiceNow.
IT Exceptions differ from Third-Party Risk Reviews and associated Risk Acceptance Letters (RALs) which assess the risks of external vendors, products, and services.