Use processors that provide sufficient guarantees
A controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures.
Independent security assurance
Evidence foundA current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.
- SOC 2Vendor states SOC 2 on its trust centreas of 21 Sep 2026
- ISO/IEC 27001Vendor states ISO 27001 on its trust centreas of 21 Sep 2026
- ISO certificate"ISO 27001 Certification Exp May 2027" on the trust centreas of 21 Sep 2026
- SOC 3 report"Ellucian SOC 3 Type 2 Report" on the trust centreas of 21 Sep 2026
- and 4 more
Security testing and documentation
Evidence foundA penetration test report, a completed standard questionnaire (SIG, CAIQ, HECVAT) or security documentation shows how the supplier tests and runs its controls.
- Security policy or overview"Ellucian Cloud Information Security White Paper" on the trust centreas of 21 Sep 2026
- Security questionnaire (SIG, CAIQ, HECVAT)"Ellucian Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 Security Trust Assurance and Risk (STAR)_2025" on the trust centreas of 21 Sep 2026
- Security questionnaire (SIG, CAIQ, HECVAT)"Ellucian Higher Education Community Vendor Assessment Tool (HECVAT)" on the trust centreas of 21 Sep 2026
- Security questionnaire (SIG, CAIQ, HECVAT)"Student Financial Succes Solutions (fka CampusLogic) Higher Education Community Vendor Assessment Tool (HECVAT)" on the trust centreas of 21 Sep 2026
- and 6 more