Question CHNG-02
Does your Change Management process also verify that all required third-party libraries and dependencies are still supported with each major change?
Weight | 20 |
High Risk | No |
Required | Yes |
Compliant Answer | Yes |
Standard Guidance
EDUCAUSE provides no guidance here
Answering "NO"
Please describe any plans to implement third-party library dependancy tracking.
Answering "YES"
Please describe your program to track these dependancies.
Reason for Question
This question is fundamentally about supply chain. The vendor should be able to document its procedures around tracking third-party maintained libraries.
Follow-Up Inquiries
If the vendor's response does not cover the details outlined in the reasoning, follow-up and get specific responses for each, as needed.
HECVAT Pro Advice
[Add expert insights and best practices]
Implementation Tips
[Add practical steps for SME SaaS vendors]
FAQ
[Add common questions related to this HECVAT item]
Resources
[Add links to relevant articles or tools]