ITC Rapid Review - Additional Information

What is the ITC Rapid Review (IRR)?

The ITC Rapid Review is a collaboration with our clients providing expert technical and service perspectives to problem solving by rapidly responding to their technology needs and helping them make the best technology decisions for their department and Dartmouth.

How does the IRR process help me?

The IRR process helps ensure that you implement your technology solution safely, collaborating with necessary parties involved to help lead you to a successful resolution. If that solution leads to a purchase through Dartmouth Procurement, it provides a number of needed documents and review checks by appropriate teams. 

What are those documents and checks? And who are performing these tasks?  

  • HECVAT - The Higher Education Community Vendor Assessment Toolkit (HECVAT) is a part of the Vendor Risk Management (VRM) process conducted by the ITC Information Security Team. We will ask the vendor for their HECVAT or ask them to complete the newest form to ensure it meets Dartmouth's standards.  Some examples include how sensitive is the data, what security protocols are in place, how is access managed, etc. This process typically takes a week but could take longer depending on the vendor's responsiveness. fdafadsfsdaf
  • Soc 2 Type 2 - Third-party assessment designed to test the effectiveness of a vendor's security controls over a specific period of time (usually approximately one year). This will be requested if data is considered DISC Level 2 or higher. Dartmouth Information Security Policy | Policies 
  •  VPAT -The Voluntary Product Accessibility Template (VPAT) is an instrument used to document a product's conformance with accessibility standards and guidelines in order to generate an Accessibility Conformance Report. This report is critical in mitigating risk to Dartmouth by ensuring that technology solutions are accessible to all students and employees, and to communicate the need for alternatives to be made available in cases when a solution falls short of compliance obligations. 
  • ARM - The Archives and Records Management Assessment is performed by the Dartmouth Records Management team to ascertain if the data collected is part of the College's official records and what the storage and disposition requirements of the data may be.
  •  Master Sales Agreement or Terms and Conditions - Procurement will take a preliminary look at existing, request, or see about the possibility of adjusting terms that may factor in during the procurement process. 

Anything else I should be aware of during this process? 

Yes, here are a couple points of interest:

I went through the IRR process, what does my support look like for the solution? 

In most cases, the support for your specific solution will be handled through the vendor. Most vendors will provide support, at least at a basic level, but some offer a premier support tier. During the IRR process, we will explore what the vendor offers and any additional costs. 

I know of another department, team, or individual interested in a similar solution, should they submit IRR also?

Absolutely! We will be happy to work with anyone about anything IT related. If you prefer, bringing them along during your IRR is also an option. The choice is yours. 

Do you only handle purchasing solutions?

No, we do not. We assisted in many successful IRRs that resulted in locally developed solution or that used existing technology products to provide a solution. We look to explore all options with you.  If it does require purchasing, we will work you, the vendor, and procurement when necessary on a soft hand-off for next steps. 

Timeline

This can vary significantly. We have seen IRRs close in a matter of a few days when the solution is known, the vendor is very responsive and has the forms above ready, and the security review goes smoothly. We have others that take months finding out what the best solution is, building a proof of concept, then formalizing the solution that provides them value!

 

We look forward to helping you get the IT solution that you want!