IT Acquisitions

Background

IT acquisitions have a potential impact on more than one school or division, and technology decisions made without central oversight can have unexpected negative consequences. Therefore, the Policy on IT Acquisitions establishes conditions under which a potential technology acquisition would be subject to review by the IT Acquisitions Team prior to moving forward.

Pre-Approved Technology

Software Licensing

Welcome to the campus-wide software site. It is the goal of Information Technologies (IT) to manage and track large-scale site licenses so that colleges, departments, faculty, staff, and students can save money on key computer software. We also provide the ability to purchase software licenses for any software that doesn’t conflict with those available.

Planning Requirements

Prior to initiating contact with a third-party information technology product/service provider, the potential IT acquisition must be reviewed to ensure that the product/service meets the following criteria:

  • Is not a duplication of preexisting, in-house NMSU IT products/services that meet the acquirer’s need;
  • Is compatible with existing IT architecture and University central network and computing systems;
  • Does not violate regulatory requirements of FERPA, FISMA, HIPAA, GLBA, PCI, or the state of New Mexico;
  • Meets NMSU’s IT compliance/privacy/security requirements, and cloud service provider provides evidence of SOC2 report and meets the NMSU cloud service provider contractual requirements.

The requestor of the product/service acquisition must submit a completed IT acquisition request form that contains pertinent information about the products and services to be acquired and justification of need to the following:

  • IT acquisition committee at itacquisition@nmsu.edu
  • Form must be signed/approved by appropriate university VP/Dean/Department/Director.

Below is a flowchart showing the Acquisitions approval process.  Note that review may take a few days up to a week or longer, and that the acquisition of “externally” hosted cloud services will require a more in-depth review to ensure data security and inclusion of proper terms & conditions in the contractual agreement.

Committee Membership

Membership is structured to achieve a wide representation of input from staff knowledgeable in acquiring information technology.  

  • CISO and Chair of the Committee
  • Co-Chair: This position will be voted in by the committee members
  • Chief Privacy Officer and IT Compliance Officer 
  • Director of Procurement Operations
  • IT Project Manager 
  • Director of Infrastructure and Communications 
  • IT Financial Operations 
  • IT Information Security and Cybersecurity
  • Doña Ana Community College 
  • NMSU Alamogordo  
  • NMSU Grants 
  • NMSU Global
  • College of ACES 
  • College of Arts and Sciences 
  • Library Systems 
  • Or designee for the above 
  • Member(s) designated by the Chairperson as needed  

Membership duration is ongoing.