Gutiérrez questions security compliance standards in IRMA process
Gutiérrez asks what compliance standards are referenced in the IRMA security review and who sets them. DOE officials explain the three-step IRMA process: data processing review, DIIT technology review, and OTI cloud review, with standards set by DOE.
Thank you.
When talking about, it says here, paragraph four states that vendors complete a security questionnaire covering encryption, access control, and compliance standards.
New York City Public Schools security team reviews and approves it.
Can you clarify what compliance standards are referenced in this paragraph?
And where are these standards issued?
Who are these standards issued by?
Are you referring to the data security review process?
Yes, I'm referring to the security check part of it.
Okay, I'll defer to DIT for that question.
Sure, so the review process that goes on within the IRMA process is three steps.
The data processing review, which is legal and working with the vendor, getting the proper documentation, and then DIT,
does a review of the technology related to the system, and we get into those areas that you just described.
We have security professionals that know how to do that.
We have some tools that we also use to support that process.
And the third step is a review from OTI Cloud, which also looks at the technology and its security and where things are hosted and make sure that it's secure from their perspective.
But who sets the standards?
Is it, you know, OTI?
Is it DOE?
It's DOE.
Okay.
Okay, and then I had another question.