{"id":5206,"date":"2020-12-01T15:23:00","date_gmt":"2020-12-01T23:23:00","guid":{"rendered":"https:\/\/policyusc.wpengine.com\/?p=5206"},"modified":"2026-05-08T11:23:29","modified_gmt":"2026-05-08T18:23:29","slug":"third-party-security-risk-management","status":"publish","type":"post","link":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/","title":{"rendered":"Third-Party Security Risk Management"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. Policy<\/h2>\n\n\n\n<p>Issued: May 3, 2019<strong>\u00a0<br><\/strong>Last Revised: August 1, 2025<strong>\u00a0<br><\/strong>Last Reviewed: May 5, 2026<strong>\u00a0<\/strong><\/p>\n\n\n\n<p><strong>\u200b\u200bApplies to:\u200b <\/strong><em>Faculty (including part-time, adjunct and visiting faculty), postdoctoral scholars, staff and student workers (including graduate\/undergraduate student workers and graduate assistants) employed by University of Southern California (\u201cUSC\u201c or the \u201cUniversity\u201c) and including those working for the University\u2019s health system (\u201cUSC Employees\u201d); third parties including vendors, affiliates, consultants, and contractors when using USC-Owned Technology Resources; iVIP (guests with electronic access) as well as any other users of USC-Owned Technology Resources, including retirees, independent contractors, or others (e.g., temporary agency employees) who may be given access on a temporary basis to University systems. This policy continues to apply to individuals who are on sabbatical or other leaves, or who are visiting other institutions.<\/em>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. Policy Purpose<\/h2>\n\n\n\n<p>This Third-Party Security Risk Management Policy establishes university security requirements for the use of third-party services, products or related processes that:<\/p>\n\n\n\n<p>\u2022 Handle USC information; either by accessing, storing, processing, transmitting, or receiving data, for hardware and software products, support and maintenance, service or solution providers, and Information Technology (IT) services.<\/p>\n\n\n\n<p>\u2022 Maintain a separate, but trusted network connected, to the USC network and provide services for, on behalf of, or in conjunction with USC.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Scope and Application<\/h2>\n\n\n\n<p>\u200b\u200bThis policy identifies the minimum requirements for third-party security risk management activities for all USC departments, schools, and units (DSU) inclusive of Keck Medical affiliates, retirees, emeriti, consultants, etc. who have access to USC technology resources, including USC email, as well as any other users of the USC network infrastructure, including independent contractors or others (e.g., temporary agency employees) who may be given access on a temporary basis to University systems. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Definitions<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Term<\/th><th>Definition<\/th><\/tr><\/thead><tbody><tr><td>Business Associates&nbsp;Agreement (BAA)&nbsp;<\/td><td>A legal document between a healthcare provider and a contractor, when that vendor might receive access to Protected Health Information (PHI)&nbsp;<\/td><\/tr><tr><td>Confidential&nbsp;<\/td><td>Data that includes regulated or sensitive information requiring compliance efforts if accessed by unauthorized parties or which could cause legal, financial, reputational, or operational harm if disclosed.&nbsp;<\/td><\/tr><tr><td>Data Security Addendum (DSA)&nbsp;<\/td><td>A legal document used during the procurement process that is designed to safeguard and limit the unauthorized disclosure and use of personal information and proprietary technical data between a vendor and USC&nbsp;<\/td><\/tr><tr><td>High Value Information&nbsp;(HVI)&nbsp;<\/td><td>USC information systems that create, process, transmit or store High Value Information (HVI)&nbsp;<\/td><\/tr><tr><td>Internal Use Only&nbsp;<\/td><td>Data that includes all information used to conduct USC business, unless categorized as \u201cConfidential\u201d or \u201cPublic\u201d&nbsp;<\/td><\/tr><tr><td>Protected Health&nbsp;Information (PHI)&nbsp;<\/td><td>Also referred to as personal health information, generally refers to demographic information, medical histories, test and laboratory results, mental health conditions, insurance information, and other data that a healthcare professional collects to identify an individual and determine appropriate care&nbsp;<\/td><\/tr><tr><td>Third-Party&nbsp;<\/td><td>Any outside individual or entity who is not a university student, faculty or staff employee who contractually interacts with or on behalf of USC. This includes but is not limited to vendors, consultants, contractors, and research and business partners&nbsp;<\/td><\/tr><tr><td>Third-Party Relationship&nbsp;Owner (TPRO)&nbsp;<\/td><td>The individual responsible for establishing and managing the interactions between a third-party and USC&nbsp;<\/td><\/tr><tr><td>USC-Owned Technology Resources&nbsp;<\/td><td>Technology resources owned, licensed, or developed by USC, including but not limited to: network-based communication services (USC networks, email accounts, instant messaging platforms, and cloud-based repositories); USC-issued computers and electronic devices (desktops, laptops, mobile phones, tablets, servers, satellite phones, and pagers) purchased or leased using university funds; and any USC-developed or licensed software.&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">5. Policy Details<\/h2>\n\n\n\n<p><strong>Objective<\/strong>&nbsp;<\/p>\n\n\n\n<p>The objective of this policy is to safeguard and preserve an environment that encourages academic and research collaboration through the management of third parties to ensure responsible safeguard and use of USC information.&nbsp;<\/p>\n\n\n\n<p><strong>Policy Requirements<\/strong>&nbsp;<\/p>\n\n\n\n<p>5.1 USC Office of Cybersecurity must maintain defined cybersecurity criteria for third-party services, products or related processes handling Confidential data, as defined by the Data Protection Policy.&nbsp;<\/p>\n\n\n\n<p>5.2 Prior to the initial third-party service, product or related processes, handling or storing USC Confidential data, the Third-Party Relationship Owner (TPRO) will request that USC Office of Cybersecurity assess security practices of the third party.&nbsp;<\/p>\n\n\n\n<p>5.3 The Third-Party Relationship Owner (TPRO) will adhere to cybersecurity requirements relating to USC&#8217;s Confidential information assets, as defined by the Data Protection Policy, being accessed, stored, analyzed, processed, or transmitted by third party services, products or offerings. The TPRO will also obtain a Data Security Addendum (DSA) with the third party that handles, stores or transmits Confidential data and consult with the Office of Ethics and Compliance regarding whether a Business Associates Agreement (BAA) is needed for information assets related to Protected Health Information (PHI). The DSA and BAA must use USC\u2019s pre-approved templates unless approved by the Office of Ethics and Compliance or the Office of the General Counsel.&nbsp;<\/p>\n\n\n\n<p>5.4 The Third-Party Relationship Owner (TPRO) is required to confirm with the Office of General Counsel that a binding Non-Disclosure Agreement (NDA) or appropriate contractual language (e.g., data confidentiality requirements) is in place prior to a third-party handling data which is not \u201cPublic\u201d, as defined by the Data Protection Policy.&nbsp;<\/p>\n\n\n\n<p>5.5 USC Office of Cybersecurity will monitor and periodically assess third-party cybersecurity practices for third-party services, products or related processes handling, storing or accessing Confidential data or High Value Information (HVI), or vendors deemed critical by the University.&nbsp;<\/p>\n\n\n\n<p>5.6 Third Party Relationship Owners will work with USC Office of Cybersecurity to monitor and reassess third party cybersecurity practices in a timely manner.&nbsp;<\/p>\n\n\n\n<p>5.7 New and existing third parties will be assessed and monitored for cybersecurity risks by USC Office of Cybersecurity.&nbsp;<\/p>\n\n\n\n<p>5.7.1 Third parties flagged with high or critical security risk ratings will be escalated to local department, school, or unit leadership (i.e., SVP and\/or Dean) and the USC Chief Information Security Officer for review.&nbsp;<\/p>\n\n\n\n<p>5.8 Procurement will collect and maintain up-to-date third-party information, including the following:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Third-party contact information&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Third-party relationship owner and represented School\/Unit&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Third-party associated website(s)&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">6. Procedures<\/h2>\n\n\n\n<p>N\/A<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7. Forms<\/h2>\n\n\n\n<p>N\/A<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. Responsibilities<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>POSITION or OFFICE<\/th><th>RESPONSIBILITIES <\/th><\/tr><\/thead><tbody><tr><td>USC Office of Cybersecurity&nbsp;<\/td><td>1.  Develop and review exceptions to the policy&nbsp;<br>2.  Monitor activity relative to the policy requirements as well as provide periodic communications and training designed to support the policy and related procedures, as needed&nbsp;<\/td><\/tr><tr><td>USC Personnel&nbsp;<\/td><td>1.  Understand and comply with this policy&nbsp;<br>2.  In any situations where it is not clear if the actions being contemplated are permitted, seek guidance from their supervisor or USC Office of Cybersecurity&nbsp;<\/td><\/tr><tr><td>SVPs, Deans, Department Chairs and Supervisors\/Managers of departments, schools, and units&nbsp;<\/td><td>1.  Set expectations with USC Personnel to comply with this policy&nbsp;&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">9. Related Information<\/h2>\n\n\n\n<p><strong>Compliance Measurement<\/strong>&nbsp;<\/p>\n\n\n\n<p>The USC Office of Cybersecurity will monitor compliance with this policy, USC\u2019s cybersecurity policies and standards, and applicable federal and state laws and regulations\u00a0using\u00a0various methods, including but not limited to periodic policy attestations. Compliance with cybersecurity policies will be monitored regularly in conjunction with\u00a0USC\u2019s\u00a0monitoring of its cybersecurity program. Internal Audit will conduct periodic internal audits to ensure compliance.\u00a0<\/p>\n\n\n\n<p><strong>Exceptions<\/strong>&nbsp;<\/p>\n\n\n\n<p>Any requested exceptions to the policy will be submitted to <a href=\"mailto:secgovrn@usc.edu\" target=\"_blank\" rel=\"noreferrer noopener\">secgovrn@usc.edu<\/a> and evaluated in accordance with the decision criteria defined by the USC Office of Cybersecurity issues and exceptions management processes.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Non-Compliance<\/strong>&nbsp;<\/p>\n\n\n\n<p>Violation of this policy may lead to this being classified as serious misconduct, which is grounds for discipline in accordance with the Faculty Handbook, staff employment policies, and the Student Handbook, as appropriate. Any disciplinary action under this policy will\u202fconsider\u202fthe severity of the offense\u202fand\u202fthe individual\u2019s intent\u202fand could include termination\u202fof access to\u202fthe USC network, USC systems and\/or applications, as well as employment actions up to and including termination, and student disciplinary actions up to and including expulsion.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">10. Contacts<\/h2>\n\n\n\n<p>\u200b\u200bPlease direct any questions regarding this policy to:\u200b&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>OFFICE<\/th><th>PHONE<\/th><th>EMAIL<\/th><\/tr><\/thead><tbody><tr><td>USC Office of Cybersecurity&nbsp;<\/td><td>&nbsp;<\/td><td>trojansecure@usc.edu&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Please view policy to access additional details.<\/p><\/div>\n<div class=\"categories\"><a class=\"category-single\" href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/information-technology\/\">Information Technology<\/a><a class=\"category-single\" href=\"https:\/\/policy.usc.edu\/category\/publicly-available\/\">Publicly Available<\/a><a class=\"category-single\" href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/research\/\">Research<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[21,1,47],"tags":[6,48,8],"class_list":["post-5206","post","type-post","status-publish","format-standard","hentry","category-information-technology","category-publicly-available","category-research","tag-faculty","tag-research","tag-staff"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Third-Party Security Risk Management - Policies and Policy Governance<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/policy.usc.edu\/third-party-security-risk-management\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Third-Party Security Risk Management - Policies and Policy Governance\" \/>\n<meta property=\"og:description\" content=\"Please view policy to access additional details.Information TechnologyPublicly AvailableResearch\" \/>\n<meta property=\"og:url\" content=\"https:\/\/policy.usc.edu\/third-party-security-risk-management\/\" \/>\n<meta property=\"og:site_name\" content=\"Policies and Policy Governance\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-01T23:23:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-08T18:23:29+00:00\" \/>\n<meta name=\"author\" content=\"nsantill\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"nsantill\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/\"},\"author\":{\"name\":\"nsantill\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/#\\\/schema\\\/person\\\/33e3b6ebbe84c07d02348c3a9ffd54cc\"},\"headline\":\"Third-Party Security Risk Management\",\"datePublished\":\"2020-12-01T23:23:00+00:00\",\"dateModified\":\"2026-05-08T18:23:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/\"},\"wordCount\":1329,\"keywords\":[\"Faculty\",\"research\",\"Staff\"],\"articleSection\":[\"Information Technology\",\"Publicly Available\",\"Research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/\",\"url\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/\",\"name\":\"Third-Party Security Risk Management - Policies and Policy Governance\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/#website\"},\"datePublished\":\"2020-12-01T23:23:00+00:00\",\"dateModified\":\"2026-05-08T18:23:29+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/#\\\/schema\\\/person\\\/33e3b6ebbe84c07d02348c3a9ffd54cc\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/third-party-security-risk-management\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/policy.usc.edu\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Third-Party Security Risk Management\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/#website\",\"url\":\"https:\\\/\\\/policy.usc.edu\\\/\",\"name\":\"Policies and Policy Governance\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/policy.usc.edu\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/policy.usc.edu\\\/#\\\/schema\\\/person\\\/33e3b6ebbe84c07d02348c3a9ffd54cc\",\"name\":\"nsantill\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g\",\"caption\":\"nsantill\"},\"sameAs\":[\"http:\\\/\\\/it.provost.usc.edu\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Third-Party Security Risk Management - Policies and Policy Governance","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/","og_locale":"en_US","og_type":"article","og_title":"Third-Party Security Risk Management - Policies and Policy Governance","og_description":"Please view policy to access additional details.Information TechnologyPublicly AvailableResearch","og_url":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/","og_site_name":"Policies and Policy Governance","article_published_time":"2020-12-01T23:23:00+00:00","article_modified_time":"2026-05-08T18:23:29+00:00","author":"nsantill","twitter_card":"summary_large_image","twitter_misc":{"Written by":"nsantill","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/#article","isPartOf":{"@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/"},"author":{"name":"nsantill","@id":"https:\/\/policy.usc.edu\/#\/schema\/person\/33e3b6ebbe84c07d02348c3a9ffd54cc"},"headline":"Third-Party Security Risk Management","datePublished":"2020-12-01T23:23:00+00:00","dateModified":"2026-05-08T18:23:29+00:00","mainEntityOfPage":{"@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/"},"wordCount":1329,"keywords":["Faculty","research","Staff"],"articleSection":["Information Technology","Publicly Available","Research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/","url":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/","name":"Third-Party Security Risk Management - Policies and Policy Governance","isPartOf":{"@id":"https:\/\/policy.usc.edu\/#website"},"datePublished":"2020-12-01T23:23:00+00:00","dateModified":"2026-05-08T18:23:29+00:00","author":{"@id":"https:\/\/policy.usc.edu\/#\/schema\/person\/33e3b6ebbe84c07d02348c3a9ffd54cc"},"breadcrumb":{"@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/policy.usc.edu\/third-party-security-risk-management\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/policy.usc.edu\/third-party-security-risk-management\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/policy.usc.edu\/"},{"@type":"ListItem","position":2,"name":"Third-Party Security Risk Management"}]},{"@type":"WebSite","@id":"https:\/\/policy.usc.edu\/#website","url":"https:\/\/policy.usc.edu\/","name":"Policies and Policy Governance","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/policy.usc.edu\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/policy.usc.edu\/#\/schema\/person\/33e3b6ebbe84c07d02348c3a9ffd54cc","name":"nsantill","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/56b96297d4092b71ccb14079f751ba45bcb3b332fee07a41c7b4253cda7c6884?s=96&d=mm&r=g","caption":"nsantill"},"sameAs":["http:\/\/it.provost.usc.edu\/"]}]}},"author_meta":{"display_name":"nsantill","author_link":"https:\/\/policy.usc.edu\/author\/nsantill\/"},"featured_img":null,"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"nsantill","author_link":"https:\/\/policy.usc.edu\/author\/nsantill\/"},"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false,"single-post-image":false,"gb-block-post-grid-landscape":false,"gb-block-post-grid-square":false,"rpwe-thumbnail":false},"uagb_author_info":{"display_name":"nsantill","author_link":"https:\/\/policy.usc.edu\/author\/nsantill\/"},"uagb_comment_info":0,"uagb_excerpt":"Please view policy to access additional details.Information TechnologyPublicly AvailableResearch","coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/information-technology\/\" class=\"advgb-post-tax-term\">Information Technology<\/a>","<a href=\"https:\/\/policy.usc.edu\/category\/publicly-available\/\" class=\"advgb-post-tax-term\">Publicly Available<\/a>","<a href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/research\/\" class=\"advgb-post-tax-term\">Research<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">Information Technology<\/span>","<span class=\"advgb-post-tax-term\">Publicly Available<\/span>","<span class=\"advgb-post-tax-term\">Research<\/span>"]},"tags":{"linked":["<a href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/research\/\" class=\"advgb-post-tax-term\">Faculty<\/a>","<a href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/research\/\" class=\"advgb-post-tax-term\">research<\/a>","<a href=\"https:\/\/policy.usc.edu\/category\/all-policy-topics\/research\/\" class=\"advgb-post-tax-term\">Staff<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">Faculty<\/span>","<span class=\"advgb-post-tax-term\">research<\/span>","<span class=\"advgb-post-tax-term\">Staff<\/span>"]}},"comment_count":0,"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 1 month ago"},"absolute_dates":{"created":"Posted on December 1, 2020","modified":"Updated on May 8, 2026"},"absolute_dates_time":{"created":"Posted on December 1, 2020 3:23 pm","modified":"Updated on May 8, 2026 11:23 am"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/posts\/5206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/comments?post=5206"}],"version-history":[{"count":1,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/posts\/5206\/revisions"}],"predecessor-version":[{"id":9285,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/posts\/5206\/revisions\/9285"}],"wp:attachment":[{"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/media?parent=5206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/categories?post=5206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/policy.usc.edu\/wp-json\/wp\/v2\/tags?post=5206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}