Comprehensive SaaS Integration Request & Security Evaluation

1. Section 1: Requesting Department & Software Vendor Metadata

This section captures essential information about the requester, software vendor, and business justification. Complete all mandatory fields to ensure timely processing.


Requester Full Name

Requester Corporate Email Address

Requester Department

Requester Role/Title

Software Application Name

Vendor Organization Name

Vendor Primary Website URL

Software Version or Release Track

Primary Software Category

Detailed Business Purpose & Use Case Justification

Estimated Number of Initial Users

Estimated Number of Total Users at Full Deployment

Has budget been formally approved for this SaaS purchase?


Pricing Model

Estimated Annual Cost (if budget not yet approved)

Desired Go-Live/Deployment Date

Is this software intended to replace an existing approved solution?


Required Integration Touchpoints (select all that apply)

Vendor Primary Contact Name

Vendor Primary Contact Email

Vendor Support Model

Does the vendor provide a publicly accessible status page for service health?

Are there any known concerns about vendor financial stability or market viability?


Software Deployment Model

Does the software offer mobile applications (iOS/Android)?

Does the software require offline functionality or local data storage?

2. Section 2: Data Classification & Cloud Storage Architecture

This section evaluates data sensitivity, residency, and protection mechanisms. Accurate classification is critical for risk assessment and compliance.


Types of Data to be Stored or Processed (select all that apply)

Highest Data Classification Level

Will Confidential or Restricted data be stored/processed?


Are there specific data residency or sovereignty requirements?


Primary Cloud Service Provider (if known)

Is data encrypted at rest using industry-standard algorithms (AES-256 or equivalent)?


Is data encrypted in transit using TLS 1.2 or higher?


Encryption Key Management Model

Backup Frequency & Retention

Data Retention Period (e.g., 7 years, indefinite)

Does the vendor have a documented data deletion policy for customer data?


Will the SaaS application process personal data subject to privacy regulations?


Vendor's Data Breach Notification SLA (e.g., within 24 hours)

Does the vendor utilize sub-processors or fourth-party vendors?


Describe the disaster recovery objectives (RTO/RPO) if disclosed by vendor

Is comprehensive audit logging and monitoring available within the application?

I acknowledge that a Shared Responsibility Model applies and confirm understanding of our organization's obligations

3. Section 3: SSO, MFA & Identity Access Management Compatibility

This section assesses the application's integration with corporate identity and access management standards. Proper authentication controls are mandatory for enterprise deployment.


Does the application support Single Sign-On (SSO)?


Is SAML metadata exchange automated or manual?


Does the application enforce Multi-Factor Authentication (MFA)?


User Provisioning & Lifecycle Management Method

If SCIM is supported, provide SCIM endpoint URL

Does the application support granular Role-Based Access Control (RBAC)?


Can the application enforce our corporate password policy?


Is session timeout duration configurable by administrators?


Does the application support IP allowlisting/restrictions?

Does the application expose APIs for programmatic access?


Are Service Accounts supported for system-to-system integration?

Does the application support Conditional Access policies?

Is Privileged Access Management (PAM) integration supported?

4. Section 4: Third-Party Vendor SOC 2 & Cybersecurity Assessment

This section evaluates the vendor's security posture, compliance certifications, and risk management practices. Independent verification is required for high-risk deployments.


Has the vendor completed a SOC 2 Type II audit?


Is the SOC 2 Type II report available for review under NDA?


Which SOC 2 Trust Services Criteria are covered in the report?

Is the vendor ISO 27001 certified?

Other Security & Compliance Certifications (select all that apply)

Does the vendor undergo regular independent penetration testing?


Date of Most Recent Penetration Test

Is the penetration test report available for review?


Does the vendor maintain a documented Vulnerability Management Program?


Has the vendor experienced any security incidents or data breaches in the past 24 months?


Data Center & Physical Security Controls (select all that apply)

Network Security Controls Implemented (select all that apply)

Application Security Testing Practices (select all that apply)

Has the vendor completed our organization's Security Questionnaire?


Does the vendor maintain Cybersecurity Insurance?


Vendor Security Team Contact Email

Does the vendor have a published security incident response plan?

Does the vendor agree to our organization's Right to Audit clause?

5. Section 5: Chief Information Security Officer (CISO) & IT Director Sign-Off

This final section requires executive attestation and formal approval. All preceding sections must be completed before submission for sign-off.


Overall Risk Assessment Level

Does this request require a formal risk exception or acceptance?


Have all mandatory security requirements been satisfied or waived through proper exception process?

Has the business justification been validated and deemed critical?

Is budget approval confirmed and allocated?

Is the proposed implementation timeline realistic and approved?

Is a post-implementation security review required?


Has a decommissioning and data retrieval plan been documented?

CISO Approval - I have reviewed the security assessment and approve proceeding

CISO Full Name

CISO Approval Date

IT Director Approval - I have reviewed technical requirements and resource allocation and approve proceeding

IT Director Full Name

IT Director Approval Date

Are additional executive approvals required (e.g., CFO, Legal, Data Protection Officer)?


Final Decision

Should this software be added to the approved corporate SaaS catalog?

Conditions of Approval or Rejection Reasoning

This one's a dud? Build your own legend with Zapof's auto-calculating tables!
This form is protected by Google reCAPTCHA. Privacy - Terms.
 
Built using Zapof