Minor | Major | Total | |
Question Text | 68 | 2 | 70 |
Question Response Logic/Favorability | 0 | 5 | 5 |
Total | 68 | 7 | 75 |
The latest version of the Higher Education Community Vendor Assessment Toolkit, HECVAT v3.05, signifies a significant step forward from its previous iteration, v3.04. Our in-depth analysis aims to demystify the intricacies of this update, offering a clear and practical guide for information security professionals in higher education responsible for conducting and evaluating HECVAT assessments and vendor risk, as well as for third-party vendors and cloud service providers who complete the HECVAT on behalf of their organizations.
In this analysis, we will unpack the significant updates from HECVAT v3.04 Full to v3.05 Full. Those using versions before 3.4 should note additional changes from versions 3.0, 3.1, 3.2, and 3.3. Our focus here is on question text, logic, response choice, and weighting, excluding any potential updates in the response guidance section. Notably HECVAT released updated v3.05 versions of HECVAT Full, Lite and On Prem question sets. Our analysis will focus on the HECVAT Full.
Version 3.05 does not introduce any changes to question numbering and weighting but instead focuses on question text and preferred response logic. Overall there were 70 questions with text changes, mostly minor textual tweaks. Additionally, 5 questions had changes in their favorable responses, significantly altering the underlying logic and impact of these questions.
Minor | Major | Total | |
Question Text | 68 | 2 | 70 |
Question Response Logic/Favorability | 0 | 5 | 5 |
Total | 68 | 7 | 75 |
68 questions underwent minor changes. These modifications, while small, are significant in ensuring the clarity and precision of the questionnaire. It’s important to understand that these minor changes do not alter the core substance or the response logic of the questions. Rather, they refine the presentation, making the questionnaire more user-friendly and less prone to misinterpretation.
One illustrative example of such a minor change is seen in QUAL-02:
This single question showcases four distinct yet subtle changes:
In the latest version of HECVAT, v3.05, several significant modifications have been made, warranting a closer examination. These “Major Changes” are not mere textual adjustments but substantive revisions that fundamentally alter how certain questions are framed and scored.
Two questions in the HECVAT v3.05 underwent a text change. These “text changes” involve significant modifications to the essence of the questions, altering their focus and framing to better assess vendor risk.
Three key questions in the HECVAT v3.05 had changes in the core response logic or favorability. These changes significantly impact how responses are interpreted and scored.
Two questions in HECVAT v3.05 with changes in response logic potentially introduce errors, raising concerns about the accuracy of scoring.
Updating your HECVAT from version 3.04 to 3.05 is a straightforward process. You can begin by directly copying and pasting your answers from the previous version. The key area to focus on is the response to question DOCU-05; ensure it aligns with the CMMC v2.0 level 2 standards, which correlate with the 110 controls of NIST 800-171. Most other changes in this update are minor or relate to logic outside the scoring page, so they shouldn’t materially affect your responses on the vendor response tab.
To summarize, the transition from HECVAT v3.04 to v3.05 involves 75 changes affecting question texts and favorable responses. Among these, 70 are minor textual edits with two notable exceptions: the update of DOCU-05 for CMMC compliance and the replacement of a duplicate question in AAAI-19 (in the analyst tab). The five changes in response logic correct the scoring for three questions but introduce potential errors in two others.
If you are looking for a more detailed guidance on specific question by question changes, be on the lookout for a detailed change log from the HECVAT working committee that is reportedly coming soon.
Still using spreadsheets to manage your HECVATs? Join dozens of established higher education institutions who trust Isora to help them build and scale their Third-Party Security Risk Management (TPSRM) programs. Get a demo to learn how Isora can help your team scale its efforts using the HECVAT.
Dive into our research-backed resources–from product one pagers and whitepapers, to webinars and more–and unlock the transformative potential of powerfully simple GRC.
Learn MoreAnalyzing changes in HECVAT v3.05 for higher education infosec teams evaluating vendors. Includes text tweaks, logic shifts, and errors.
Learn how to establish a successful vendor risk management (VRM) program at a higher education institution using the HECVAT.