Software Intake Process

This page provides a single place for Capilano University staff and faculty to request new software.

Before submitting a request, please complete the steps below. New software may require budget, academic, privacy, cybersecurity and procurement reviews before it can be purchased or deployed.

 

Before You Submit

1. Check for existing software

Review the Software Catalog to see if Capilano University already has software that meets your needs.

Also check whether the application is available through Software Center, Company Portal or Self Service.

2. Obtain approval

Discuss the request with your Dean or Director and obtain their approval before proceeding.

3. Contact the Privacy Office

After receiving approval from your Dean or Director, contact the Privacy Office at privacy@capilanou.ca to initiate an Initial Privacy Assessment (IPA).

4. Submit the request in AskIT

Complete the New Software Request Form in AskIT. Provide as much information as possible about the software, its purpose, intended users and deployment requirements.

If the software will be used for teaching or learning, complete the Educational Technology and Learning Environments Committee questionnaire included in the form.

Important: You may request a quote from the vendor, but do not purchase the software, sign an agreement or make any commitment to the vendor before Procurement has reviewed the terms and conditions.

What Happens After You Submit the Request

DTS review and support

A member of the Digital Technology Services (DTS) team will acknowledge your request and guide you through the review process.

DTS will review:

  • The business and technical requirements.
  • Whether existing software can meet the identified need.
  • Licensing and deployment requirements.
  • Software ownership and funding.
  • Privacy and cybersecurity requirements.
  • Support and implementation considerations.

Departmental Budget and Ownership

Capilano University uses a shared software funding model:

  • University-wide software: DTS may fund academic or administrative software used across the University.
  • Department-specific software: Specialized software used by a particular department, faculty or program is normally funded by that business unit.

A DTS Manager will review the funding and ownership requirements with the requester.

Approval of a software request does not automatically confirm that DTS will fund the purchase.

Academic Software—CTE and ETLE Review

For software used for teaching or learning, the Educational Technology and Learning Environments Committee questionnaire must be completed as part of the New Software Request Form.

The questionnaire replaces the previous separate Microsoft Form.

For more information, visit:

Privacy Review—IPA and PIA

The Privacy Office will first complete an Initial Privacy Assessment.

An IPA generally takes a few business days. Based on its findings, the Privacy Office may require a more detailed Privacy Impact Assessment (PIA).

The time required to complete a PIA depends on:

  • The priority of the request.
  • The complexity of the software.
  • The type of information being collected or stored.
  • The availability of information from the requester and vendor.
  • The Privacy Office’s current workload.

The Privacy Office will work with the program manager responsible for the initiative to determine an appropriate timeline.

Link: Privacy and Access to Information—Capilano University Employee Portal

Cybersecurity Review—STRA

DTS Cybersecurity will conduct a preliminary security check when the software request is received. This review helps confirm the credibility of the software and identify immediate risks or vulnerabilities.

After the required approvals and privacy review are complete, Cybersecurity will determine whether the software requires:

  • A Lite Security Threat Risk Assessment (STRA), which typically takes approximately three weeks; or
  • A Comprehensive STRA, which may take up to two months.

Assessment timelines may vary depending on the complexity of the software, required integrations, vendor responsiveness and availability of internal resources.

Procurement and Purchase Requisition

A quote may be obtained from the vendor at any point in the process. However, no commitment may be made until Procurement has reviewed the vendor’s terms and conditions.

This review is required even for low-cost software because contracts can include privacy, security, liability, renewal and cancellation risks.

Before the software can be purchased, a Purchase Requisition must be approved and signed by the appropriate signing authority, based on the approval of the Dean or Director.

Procurement may provide one of the following decisions:

  1. Approved: Procurement proceeds with ordering the software.
  2. Approved with comments: Procurement identifies contract deviations that may be accepted if the associated risks are understood. Procurement and DTS will work with the requester to establish a risk mitigation plan.
  3. Rejected: The vendor’s terms are not acceptable. Procurement will propose Capilano University’s terms and conditions and General Services Agreement to the vendor. If the vendor accepts the revised terms, a new Purchase Requisition will be submitted for review.

Software Deployment

After the software has been approved and purchased, DTS will prepare it for deployment based on the information provided in the request form.

This may include:

  • Preparing and testing the installation package.
  • Configuring the software for a lab or individual device.
  • Assigning licences to approved users or devices.
  • Scheduling deployment to the requested computers.
  • Providing installation or access instructions.

Deployment typically takes between one week and one month, depending on the complexity of the software and the number of devices involved.

Requests for an upcoming academic term should be submitted as early as possible. Requests received outside the recommended timeline will be scheduled based on available capacity and may not be ready by the requested date.

Estimated Timelines

The following estimates begin when the relevant team has received all required information:

  • Initial Privacy Assessment: A few business days.
  • Privacy Impact Assessment: Varies by priority and complexity.
  • Lite Security Threat Risk Assessment: Approximately three weeks.
  • Comprehensive Security Threat Risk Assessment: Up to two months.
  • Software deployment after purchase: Approximately one week to one month.

These timelines are estimates. The complete process may take longer if additional approvals, vendor documentation, contract negotiations or technical integrations are required.

Was this helpful?
0 reviews