Skip to page content

Technology Assessment Form (TAF) Required Documentation

Below is the acceptable documentation for technology purchases at Yosemite Community College District. This is required at each renewal for all systems and software the district utilizes before a purchase is authorized.

Note:

  • Only the highest level document is necessary
  • Documentation must be dated within the last 12 months
  • Documents must be submitted to Information Security before or during the purchase process for approval

 

Decision Matrix

Data Classification Acceptable Documentation
  HECVAT Lite HECVAT Full FedRAMP Authorized ISO 27001 SOC 2 Type II
Level 1   X X X X
Level 2: 100+ Records   X X X X
Level 2: 1-99 Records X X X X X
Level 3 N/A N/A N/A N/A N/A

 

Data Classifications

Data Classification Level Information Example
Level 1

Employment records, student Records, and other information that could cause substantial harm to the District, its staff, or its students.

Level 2 Personally Identifiable Information (PII) beyond first and last name or other information that could cause significant harm to the District, its staff, or its students.
Level 3 Publicly available directory information or information that could cause little to no harm to the District, its staff, or its students.

 

Additional Information

Warning: These links navigate to an external site outside of Yosemite Community College District's control. Proceed with caution.

HECVAT Full/Lite - https://www.educause.edu/higher-education-community-vendor-assessment-toolkit

FedRAMP - https://www.fedramp.gov/

ISO 27001 - https://www.iso.org/standard/27001

SOC 2 Type II - https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2