This section captures essential information about the requester, software vendor, and business justification. Complete all mandatory fields to ensure timely processing.
Requester Full Name
Requester Corporate Email Address
Requester Department
Engineering & Development
Sales & Marketing
Finance & Accounting
Human Resources
Legal & Compliance
Operations
Customer Support
Information Technology
Other
Requester Role/Title
Software Application Name
Vendor Organization Name
Vendor Primary Website URL
Software Version or Release Track
Primary Software Category
Productivity & Collaboration
Customer Relationship Management (CRM)
Enterprise Resource Planning (ERP)
Business Intelligence & Analytics
Development & DevOps
Security & Compliance
Marketing Automation
Communication & Messaging
Human Capital Management
Project Management
File Storage & Sharing
Other
Detailed Business Purpose & Use Case Justification
Estimated Number of Initial Users
Estimated Number of Total Users at Full Deployment
Has budget been formally approved for this SaaS purchase?
Approved Budget Amount (Annual)
Note: Budget approval must be obtained before final IT integration approval. Proceed with technical assessment only.
Pricing Model
Per-User Subscription
Tiered Subscription
Consumption-Based
Flat Fee Enterprise License
Freemium
One-Time License with Maintenance
Other
Estimated Annual Cost (if budget not yet approved)
Desired Go-Live/Deployment Date
Is this software intended to replace an existing approved solution?
Name of Existing Software Being Replaced
Required Integration Touchpoints (select all that apply)
Active Directory/LDAP
Email System
Calendar System
Corporate HRIS
Financial System
CRM Platform
Custom API
Single Sign-On (SSO) Provider
Security Information and Event Management (SIEM)
Backup Solution
No Integration Required
Other
Vendor Primary Contact Name
Vendor Primary Contact Email
Vendor Support Model
24/7 Global Support
Business Hours Only
Premium/Paid Support Required
Community Support Only
Dedicated Account Manager
Other
Does the vendor provide a publicly accessible status page for service health?
Are there any known concerns about vendor financial stability or market viability?
Describe the specific financial stability concerns
Software Deployment Model
Public Cloud Multi-Tenant
Public Cloud Single-Tenant
Private Cloud
Hybrid Cloud
On-Premises Hosted
Not Sure
Does the software offer mobile applications (iOS/Android)?
Does the software require offline functionality or local data storage?
This section evaluates data sensitivity, residency, and protection mechanisms. Accurate classification is critical for risk assessment and compliance.
Types of Data to be Stored or Processed (select all that apply)
Customer Personal Information (PII)
Employee Personal Information (PII)
Financial Records
Health Information
Intellectual Property & Trade Secrets
Contractual & Legal Documents
Authentication Credentials
Corporate Strategy & Confidential Memos
Publicly Available Information
System Logs & Metadata
Other
Highest Data Classification Level
Public
Internal Use Only
Confidential
Restricted
Will Confidential or Restricted data be stored/processed?
Justify the business necessity for storing Confidential/Restricted data in this SaaS platform
Are there specific data residency or sovereignty requirements?
Specify required geographic regions or jurisdictions for data storage
Primary Cloud Service Provider (if known)
Is data encrypted at rest using industry-standard algorithms (AES-256 or equivalent)?
Explain the alternative data protection mechanism
Is data encrypted in transit using TLS 1.2 or higher?
Describe the transport security protocols used
Encryption Key Management Model
Vendor Managed Keys
Customer Managed Keys (CMK)
Bring Your Own Key (BYOK)
Hardware Security Module (HSM) Integration
Not Sure
Backup Frequency & Retention
Real-time Replication
Hourly Snapshots
Daily Backups
Weekly Backups
No Backups (Stateless)
Not Disclosed
Data Retention Period (e.g., 7 years, indefinite)
Does the vendor have a documented data deletion policy for customer data?
Describe the deletion process and certification mechanism
Will the SaaS application process personal data subject to privacy regulations?
Which data subject rights must be supported?
Right to Access
Right to Rectification
Right to Erasure (Right to be Forgotten)
Right to Data Portability
Right to Object
Right to Restrict Processing
Not Sure
Vendor's Data Breach Notification SLA (e.g., within 24 hours)
Does the vendor utilize sub-processors or fourth-party vendors?
List known sub-processors and their functions
Describe the disaster recovery objectives (RTO/RPO) if disclosed by vendor
Is comprehensive audit logging and monitoring available within the application?
I acknowledge that a Shared Responsibility Model applies and confirm understanding of our organization's obligations
This section assesses the application's integration with corporate identity and access management standards. Proper authentication controls are mandatory for enterprise deployment.
Does the application support Single Sign-On (SSO)?
Which SSO protocols/standards are supported?
SAML 2.0
OpenID Connect (OIDC)
OAuth 2.0
WS-Federation
Custom Proprietary Protocol
Warning: Applications without SSO support will require a security exception and additional authentication controls. This may delay approval.
Is SAML metadata exchange automated or manual?
Provide SAML metadata URL or upload location
Does the application enforce Multi-Factor Authentication (MFA)?
Which MFA methods are supported?
TOTP (Time-based OTP)
SMS/Voice
Push Notification (Mobile App)
FIDO2/WebAuthn Security Keys
Email OTP
Hardware Tokens
Certificate-Based
Critical: MFA is required for all SaaS applications accessing corporate data. A formal risk exception must be filed.
User Provisioning & Lifecycle Management Method
SCIM 2.0 Automated Provisioning
SCIM 1.1 Automated Provisioning
Just-in-Time (JIT) Provisioning
Manual Admin-Managed
API-Based Custom Integration
Not Supported
If SCIM is supported, provide SCIM endpoint URL
Does the application support granular Role-Based Access Control (RBAC)?
Describe available roles and permission levels
Can the application enforce our corporate password policy?
Describe the application's native password requirements
Is session timeout duration configurable by administrators?
What is the default and maximum session timeout?
Does the application support IP allowlisting/restrictions?
Does the application expose APIs for programmatic access?
API Authentication Method
OAuth 2.0 Client Credentials
API Keys
Mutual TLS (mTLS)
SAML Bearer Assertion
JWT Tokens
Basic Auth (Not Recommended)
Are Service Accounts supported for system-to-system integration?
Does the application support Conditional Access policies?
Is Privileged Access Management (PAM) integration supported?
This section evaluates the vendor's security posture, compliance certifications, and risk management practices. Independent verification is required for high-risk deployments.
Has the vendor completed a SOC 2 Type II audit?
Date of Last SOC 2 Type II Audit
Critical Gap: SOC 2 Type II is required for all SaaS vendors handling corporate data. Proceeding without this will require elevated risk approval.
Is the SOC 2 Type II report available for review under NDA?
SOC 2 Report Date
Which SOC 2 Trust Services Criteria are covered in the report?
Security (Common Criteria)
Availability
Processing Integrity
Confidentiality
Privacy
Not Sure
Is the vendor ISO 27001 certified?
Other Security & Compliance Certifications (select all that apply)
ISO 27017 (Cloud Security)
ISO 27018 (Privacy)
ISO 27701 (Privacy Management)
FedRAMP Authorized
CSA STAR
NIST Cybersecurity Framework
PCI DSS
HIPAA/HITECH
GDPR Compliant
None
Does the vendor undergo regular independent penetration testing?
Penetration Test Frequency
Annually
Semi-Annually
Quarterly
On-Demand
Ad-Hoc
Date of Most Recent Penetration Test
Is the penetration test report available for review?
Summarize critical and high findings and their remediation status
Does the vendor maintain a documented Vulnerability Management Program?
What is the SLA for patching Critical vulnerabilities?
Has the vendor experienced any security incidents or data breaches in the past 24 months?
Describe each incident, impact, and corrective actions taken
Data Center & Physical Security Controls (select all that apply)
ISO 27001 Certified Data Centers
SOC 1 Type II Data Centers
Biometric Access Controls
24/7 Security Staff
CCTV Monitoring
Redundant Power & Cooling
Not Disclosed
Network Security Controls Implemented (select all that apply)
Web Application Firewall (WAF)
Distributed Denial of Service (DDoS) Protection
Network Segmentation
Intrusion Detection/Prevention (IDS/IPS)
Zero Trust Architecture
Not Disclosed
Application Security Testing Practices (select all that apply)
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Interactive Application Security Testing (IAST)
Regular Code Reviews
Bug Bounty Program
Not Disclosed
Has the vendor completed our organization's Security Questionnaire?
Security Questionnaire Completion Date
Does the vendor maintain Cybersecurity Insurance?
Cyber Insurance Coverage Amount
Vendor Security Team Contact Email
Does the vendor have a published security incident response plan?
Does the vendor agree to our organization's Right to Audit clause?
This final section requires executive attestation and formal approval. All preceding sections must be completed before submission for sign-off.
Overall Risk Assessment Level
Low Risk
Medium Risk
High Risk
Critical Risk
Does this request require a formal risk exception or acceptance?
Risk Exception Justification and Mitigation Plan
Have all mandatory security requirements been satisfied or waived through proper exception process?
Has the business justification been validated and deemed critical?
Is budget approval confirmed and allocated?
Is the proposed implementation timeline realistic and approved?
Is a post-implementation security review required?
Scheduled Post-Implementation Review Date
Has a decommissioning and data retrieval plan been documented?
CISO Approval - I have reviewed the security assessment and approve proceeding
CISO Full Name
CISO Approval Date
IT Director Approval - I have reviewed technical requirements and resource allocation and approve proceeding
IT Director Full Name
IT Director Approval Date
Are additional executive approvals required (e.g., CFO, Legal, Data Protection Officer)?
Additional Approvers
Approver Name | Approver Role | Approval Status | Approval Date | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Final Decision
Approve for Immediate Deployment
Approve with Conditions
Reject - Security Concerns
Reject - Business Justification Insufficient
Defer - Pending Additional Information
Should this software be added to the approved corporate SaaS catalog?
Conditions of Approval or Rejection Reasoning
To configure an element, select it on the form.