Comprehensive SaaS Integration Request & Security Evaluation

1. Section 1: Requesting Department & Software Vendor Metadata

This section captures essential information about the requester, software vendor, and business justification. Complete all mandatory fields to ensure timely processing.

 

Requester Full Name

Requester Corporate Email Address

Requester Department

Requester Role/Title

Software Application Name

Vendor Organization Name

Vendor Primary Website URL

Software Version or Release Track

Primary Software Category

Detailed Business Purpose & Use Case Justification

Estimated Number of Initial Users

Estimated Number of Total Users at Full Deployment

Has budget been formally approved for this SaaS purchase?

 

Approved Budget Amount (Annual)

 

Note: Budget approval must be obtained before final IT integration approval. Proceed with technical assessment only.

Pricing Model

Estimated Annual Cost (if budget not yet approved)

Desired Go-Live/Deployment Date

Is this software intended to replace an existing approved solution?

 

Name of Existing Software Being Replaced

Required Integration Touchpoints (select all that apply)

Vendor Primary Contact Name

Vendor Primary Contact Email

Vendor Support Model

Does the vendor provide a publicly accessible status page for service health?

Are there any known concerns about vendor financial stability or market viability?

 

Describe the specific financial stability concerns

Software Deployment Model

Does the software offer mobile applications (iOS/Android)?

Does the software require offline functionality or local data storage?

2. Section 2: Data Classification & Cloud Storage Architecture

This section evaluates data sensitivity, residency, and protection mechanisms. Accurate classification is critical for risk assessment and compliance.

 

Types of Data to be Stored or Processed (select all that apply)

Highest Data Classification Level

Will Confidential or Restricted data be stored/processed?

 

Justify the business necessity for storing Confidential/Restricted data in this SaaS platform

Are there specific data residency or sovereignty requirements?

 

Specify required geographic regions or jurisdictions for data storage

Primary Cloud Service Provider (if known)

Is data encrypted at rest using industry-standard algorithms (AES-256 or equivalent)?

 

Explain the alternative data protection mechanism

Is data encrypted in transit using TLS 1.2 or higher?

 

Describe the transport security protocols used

Encryption Key Management Model

Backup Frequency & Retention

Data Retention Period (e.g., 7 years, indefinite)

Does the vendor have a documented data deletion policy for customer data?

 

Describe the deletion process and certification mechanism

Will the SaaS application process personal data subject to privacy regulations?

 

Which data subject rights must be supported?

Vendor's Data Breach Notification SLA (e.g., within 24 hours)

Does the vendor utilize sub-processors or fourth-party vendors?

 

List known sub-processors and their functions

Describe the disaster recovery objectives (RTO/RPO) if disclosed by vendor

Is comprehensive audit logging and monitoring available within the application?

I acknowledge that a Shared Responsibility Model applies and confirm understanding of our organization's obligations

3. Section 3: SSO, MFA & Identity Access Management Compatibility

This section assesses the application's integration with corporate identity and access management standards. Proper authentication controls are mandatory for enterprise deployment.

 

Does the application support Single Sign-On (SSO)?

 

Which SSO protocols/standards are supported?

 

Warning: Applications without SSO support will require a security exception and additional authentication controls. This may delay approval.

Is SAML metadata exchange automated or manual?

 

Provide SAML metadata URL or upload location

Does the application enforce Multi-Factor Authentication (MFA)?

 

Which MFA methods are supported?

 

Critical: MFA is required for all SaaS applications accessing corporate data. A formal risk exception must be filed.

User Provisioning & Lifecycle Management Method

If SCIM is supported, provide SCIM endpoint URL

Does the application support granular Role-Based Access Control (RBAC)?

 

Describe available roles and permission levels

Can the application enforce our corporate password policy?

 

Describe the application's native password requirements

Is session timeout duration configurable by administrators?

 

What is the default and maximum session timeout?

Does the application support IP allowlisting/restrictions?

Does the application expose APIs for programmatic access?

 

API Authentication Method

Are Service Accounts supported for system-to-system integration?

Does the application support Conditional Access policies?

Is Privileged Access Management (PAM) integration supported?

4. Section 4: Third-Party Vendor SOC 2 & Cybersecurity Assessment

This section evaluates the vendor's security posture, compliance certifications, and risk management practices. Independent verification is required for high-risk deployments.

 

Has the vendor completed a SOC 2 Type II audit?

 

Date of Last SOC 2 Type II Audit

 

Critical Gap: SOC 2 Type II is required for all SaaS vendors handling corporate data. Proceeding without this will require elevated risk approval.

Is the SOC 2 Type II report available for review under NDA?

 

SOC 2 Report Date

Which SOC 2 Trust Services Criteria are covered in the report?

Is the vendor ISO 27001 certified?

Other Security & Compliance Certifications (select all that apply)

Does the vendor undergo regular independent penetration testing?

 

Penetration Test Frequency

Date of Most Recent Penetration Test

Is the penetration test report available for review?

 

Summarize critical and high findings and their remediation status

Does the vendor maintain a documented Vulnerability Management Program?

 

What is the SLA for patching Critical vulnerabilities?

Has the vendor experienced any security incidents or data breaches in the past 24 months?

 

Describe each incident, impact, and corrective actions taken

Data Center & Physical Security Controls (select all that apply)

Network Security Controls Implemented (select all that apply)

Application Security Testing Practices (select all that apply)

Has the vendor completed our organization's Security Questionnaire?

 

Security Questionnaire Completion Date

Does the vendor maintain Cybersecurity Insurance?

 

Cyber Insurance Coverage Amount

Vendor Security Team Contact Email

Does the vendor have a published security incident response plan?

Does the vendor agree to our organization's Right to Audit clause?

5. Section 5: Chief Information Security Officer (CISO) & IT Director Sign-Off

This final section requires executive attestation and formal approval. All preceding sections must be completed before submission for sign-off.

 

Overall Risk Assessment Level

Does this request require a formal risk exception or acceptance?

 

Risk Exception Justification and Mitigation Plan

Have all mandatory security requirements been satisfied or waived through proper exception process?

Has the business justification been validated and deemed critical?

Is budget approval confirmed and allocated?

Is the proposed implementation timeline realistic and approved?

Is a post-implementation security review required?

 

Scheduled Post-Implementation Review Date

Has a decommissioning and data retrieval plan been documented?

CISO Approval - I have reviewed the security assessment and approve proceeding

CISO Full Name

CISO Approval Date

IT Director Approval - I have reviewed technical requirements and resource allocation and approve proceeding

IT Director Full Name

IT Director Approval Date

Are additional executive approvals required (e.g., CFO, Legal, Data Protection Officer)?

 

Additional Approvers

Approver Name

Approver Role

Approval Status

Approval Date

A
B
C
D
1
 
 
 
 
2
 
 
 
 
3
 
 
 
 
4
 
 
 
 
5
 
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Final Decision

Should this software be added to the approved corporate SaaS catalog?

Conditions of Approval or Rejection Reasoning

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.