9-27-26: Reminder: CUNY Information Security Review Process
TO: John Jay Faculty and Staff
FROM: Joseph Laub, Chief Information Officer
DATE: September 27, 2026
RE: Reminder: CUNY Information Security Review Process
I am writing once again to remind the campus community that systems, software, applications, and technology services that store, process, transmit, or integrate with College or University data require completion and approval of the CUNY Information Security Risk Questionnaire, known as the ISRQ.
The ISRQ process is reviewed by University Governance, Risk, and Compliance, or University GRC, and as of May of this year has been integrated into CUNYBuy. The ISRQ approval must be completed before new systems, or software can be procured, or existing systems can be renewed.
Departments planning to purchase, implement, or renew systems or software should begin this renewal process early in the fiscal year and allow to avoid delays with projects, contracts, and renewals.
Thank you for your cooperation in helping protect John Jay and CUNY data.
If you have any questions or concerns, please contact the DoIT helpdesk at 212.237.8200 or helpdesk@jjay.cuny.edu.