Technology Approval Process (Cloud Services): Privacy and Security Assessment Guide Procedure

Governance

Adopted under the Privacy Policy

1.1 As the digital landscape moves further from on premise hosting, Cloud Services provide financial and production benefits to the Durham District School Board (“DDSB”) by reducing costs and increasing production and ease of use. The DDSB recognizes that the financial and production benefits of Cloud Services must be balanced with ensuring security and privacy of information in the custody, or under the control of the DDSB, and be consistent with legislative requirements, including the Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56 and its regulations, as amended (“MFIPPA”), Personal Health Information Protection Act, 2004, S.O. 2004, c. 3 and its regulations, as amended (“PHIPA”), and the Education Act, R.S.O. 1990, c. E.2 and its regulations, as amended (the “Education Act”).

1.2 The objective of the Technology Approval Procedure (Cloud Services): Privacy and Security Assessment Guide (this “Procedure”) is to assist DDSB employees in assessing and implementing Cloud Services by outlining specific issues that should be raised and considered before Vendor selection is finalized to adequately protect the security and privacy of information in the custody or under the control of the DDSB. 

1.3 This Procedure can be used to assist DDSB employees as well as Vendors in responding to Requests for Proposals and evaluating collocation, managed hosting, Cloud and Infrastructureas-a-Service (IaaS), Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS), Desktop-as-a-Service (DaaS), and Backendas-a-Service (BaaS) Providers. 

1.4 This Procedure is to be interpreted and applied in accordance with the DDSB’s commitment to promoting and upholding Indigenous rights and human rights in all its learning and working environments. This includes anti-colonial, anti-discriminatory and anti-racist approaches and actions to provide services and employment that are safe, welcoming, respectful, inclusive, equitable, accessible and free from discrimination and harassment consistent with the DDSB’s Indigenous Education Policy, Human Rights, Anti-Discrimination and Anti-Racism Policy, Safe and Respectful Workplace and Harassment Prevention Policy and related procedures

2.1 This Procedure applies to:

2.1.1 All DDSB employees with a responsibility for Cloud Services procurement, assessment, approval, implementation, and management.

2.1.2 All Vendors, Cloud Services Providers and their supply chains that provide Cloud Services to the DDSB.

2.1.3 Outsourced provisions of Cloud Services (e.g., software as a service, platform as a service, cloud hosting).

2.1.4 Outsourced provisions of information technology functions and consulting where personnel are managed by the Cloud Service Provider.

3.1 When assessing Cloud Services for Vendor selection, there are nine areas to consider, detailed in Appendix A: General, Data Encryption, Access Privileges, Regulatory Compliance, Data Provenance, Data Segregation, Data Recovery, Monitoring and Reporting, and Business Continuity. These nine areas align to areas of security risk associated with Cloud Services. 

3.2 When applying this Procedure, ensure each criterion is relevant and necessary to the Cloud Service’s use. Additional evaluation assessment guide, questions, and information not set out in this Procedure may be included in a Cloud Services assessment to reflect unique requirements. Similarly, portions of this Procedure may not apply to a particular Cloud Service.

3.3 Not all Vendors or CSPs will be required to pass every piece of assessment guide in order to be selected. Factors, such as the sensitivity of the data stored, will dictate how strict or lenient these assessment guide should be implemented. For example, storage of PI and PHI will require a stricter application of the assessment guide. 

3.4 DDSB employees must ensure they work only with trusted Vendors and CSPs that can address Cloud Service security challenges. In moving from using just one Cloud Service to using several Cloud Service from different providers, the DDSB also must manage all these issues across multiple operators, each with different infrastructures, operational policies, and security skills. This complexity of trust requirements drives the need for a ubiquitous, highly reliable method to secure our data as it moves to, from and around the Cloud Service.

4.1 Information Technology Services (“ITS”) and Legal Services

ITS and Legal Services are jointly responsible for the administration of this Procedure. 

4.2 Innovative Education

4.3 The Innovative Education (“IE”) team is responsible for reviewing all Cloud Services requested for approval by education staff that fall under the “Educational” category (used for in-person or online classrooms) to determine the following:

4.3.1 If the technology requested has pedological value;

4.3.2 Privacy considerations that require further review by IT Services;

4.3.3 Whether the technology would be redundant because the DDSB already uses a similar or alternate approved “standard” technology; and

4.3.4 Guidelines concerning how technology will be deployed in classrooms. 

Questions relating to requests for Educational Cloud Services approval can be sent to innovative.education@ddsb.ca