Security Planning Assessment (SPA)
The three phases to completing a SPA
-
MSS Review
Understand and address your system’s security requirements before submitting a SPA request. -
Intake and Triage
Request a SPA and complete an introductory consultation with the Information Security Office. -
Assessment
Perform additional activities required to complete the SPA process.
Phase 1: MSS Review
During the MSS Review phase, you will:
- Obtain IT support in determining applicable requirements if you are unsure about or don't know the technical information for the IT system.
- Determine the IT System's risk classification as either Low Risk, Moderate Risk, or High Risk.
- Review Yale University AI Guidelines for Staff and submit an AI project request if the IT System involves AI (e.g., machine learning, deep learning, large language models),
- Review the MSS and understand how the IT System aligns with them.
Phase 2: Intake and Triage
During the Intake and Triage phase, you will:
- Complete the SPA Request Form.
- Work with the Information Security Office (ISO) to complete an initial advisory consultation.
Phase 3: Assessment
During the Assessment phase, you will:
- Provide an attestation regarding the IT System's adherence to the MSS.
- Work with ISO to:
- Complete the exception request process, if necessary.
- Remedy vulnerabilities identified as part of the vulnerability scanning process (for systems installed onsite or in a Yale-owned/contracted space).
During this phase, for systems installed in a vendor’s cloud environment:
- Vendors will complete a Third Party Risk Management (TRPM) assessment.
- Contracts will be reviewed to ensure University cybersecurity requirements are met.
The final phase of the SPA process depends on the IT System’s risk classification and type. If the IT System is Low Risk, the ISO may determine this phase is not needed.
For additional information on each of the phases in the SPA process, please visit our Security Planning Assessment (SPA) Process Guidance webpage.
Need more help?
Supporting resources for completing the SPA:
- Security Planning Assessment (SPA) Process Guidance
- Yale's Minimum Security Standards
- Risk Classification Guideline
- Exception Request Process
For additional questions about the SPA, please email information.security@yale.edu.