No provisioning process
Introduce one. Ad hoc site creation is the source of most permission inconsistency in federated institutions.
Twenty checks on whether student information is organised, protected and findable across a federated institution.
Universities are federated by nature. Departments create sites, research groups keep their own structures, and central IT has authority over some of it and influence over the rest.
The result is student information distributed across an estate nobody has mapped, with access decisions made locally and inconsistently.
Registrar or Head of Student Services
SharePoint and Microsoft 365 administrators
Information governance lead
Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.
Whether the estate has a shape anybody designed.
The obligations that make this different from a corporate estate.
Where exposure accumulates in an open institution.
Whether the structure actually serves people.
These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.
Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.
Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.
The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.
Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.
The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.
Introduce one. Ad hoc site creation is the source of most permission inconsistency in federated institutions.
Run discovery. Proportionate protection is impossible without knowing where the data is.
Restrict it this week. It is a disclosure risk that requires no attacker and no error.
Ask ten staff to find five things and time them. The findings are usually immediate and cheap to fix.
We will run the audit against one faculty or department and give you the findings including the discovery results, whether or not you take the remediation further with us.
Twenty checks before a large device refresh in an institution, covering procurement, provisioning and the academic calendar.
Twenty checks before a recruitment cycle opens, covering data, communication and the melt window most institutions leave unmanaged.
Twenty checks before building an institutional data platform, covering governance, access and whether anybody will act on the output.
Describe the situation in your own words.