Fiscal Note
No fiscal impact.
Title
Authorizing the City’s Information Technology Director to sign non-disclosure agreements with software and technology vendors in order to obtain SSAE 16 reports.
Body
WHEREAS, the City uses software products from a number of vendors for a variety of functions; and
WHEREAS, this software includes both hosted and software-as-a-service products; and
WHEREAS, vendor-supplied software products have an impact on the operations of the city; and
WHEREAS, it is necessary to review Statement on Standards for Attestation Engagements (SSAE 16) reports, also known as Service Organization Control (SOC) reports, in order to determine if the vendors have adequate controls, policies and procedures in place; and
WHEREAS, most vendors require a signed confidentiality or non-disclosure agreement before they will provide these reports; and
WHEREAS, City staff, including department heads, do not have authority to sign contractual documents on behalf of the City, the IT department anticipates requesting SSAE 16 reports on a regular basis and if a confidentiality or non-disclosure agreement is required from the vendor prior to disclosure, it is not practical to seek individual authority for the mayor and city clerk to sign each one
NOW, THEREFORE, BE IT RESOLVED that the City of Madison’s Information Technology Director is authorized to sign confidentiality or non-disclosure agreements on behalf of the City with software and technology vendors in order to obtain SSAE 16 reports, in a form approved by the City Attorney.