Cyber Risk Management Program

Program Overview

The Cyber Risk Management Program (CRMP) is a holistic initiative designed to help UC Berkeley Units manage digital risk and ensure compliance with the UC systemwide IS-3 Electronic Information Security Policy. By shifting from a purely technical checklist to a risk-based governance model, the program protects the university’s reputation, research integrity, and administrative operations.

Get Help

Key Program Principles:

Security is a shared responsibility; everyone has a role.

Focus on risk management; risk assessment is key.

Units are responsible for managing their own information security risk.

Protection Level & Availability Level inform risk level and controls.

UISL Resources:

Assessment Cycle:

  1. Review the Assessment Schedule.
  2. Annually, review your registered assets in Socreg.
    1. Socreg Unit Security Metrics Guide.
  3. Review the Unit Self-Assessment & Isora GRC page.
  4. Read the Berkeley Isora Guidance.
  5. Log in to the Isora unit self-assessment platform.
  6. Check out the CRMP Dashboards data visualization and reporting tool.