Overview
An update to the Departmental Information Security Contact Policy was approved by the campus Compliance & Enterprise Risk Committee (CERC) in November 2022. The Policy defines Department-level responsibilities for ensuring prompt and appropriate action in the event of an information security incident. The main purpose of the Policy remains unchanged: to ensure that ISO is able to contact the proper people in each Department and have them take appropriate action in the event of a security incident. The specific responsibilities for both Departments and Information Security Contacts have been updated and clarified, along with the definitions and resources associated with this Policy.
Summary
The below table breaks out the sections of the Policy on the left and provides a summary of the updates made in that section on the right. Additional resources are linked as needed. We wanted to display these key updates in a clear and concise way so that users may quickly see the changes that were made.
If you have questions about any of the changes, please email us at security-policy@berkeley.edu.
Section |
Summary of Changes |
I. Purpose |
Section now called “Purpose / Policy Statement” to align with Campus policy format. Reframed as a policy statement. No new content. |
II. Scope |
New section to align with Campus policy format. No new content, but highlights that this policy applies to all Campus Departments and Information Security Contacts. |
III. Background |
Removed some narrative. Incorporated background info from other sections of the Policy. Added link to ISO’s Procedures for Blocking Network Access. |
IV. Key Definitions and Glossary |
|
V. Requirements |
|
VI. Consequences of Violations |
New section to align with Campus policy format. Reiterates that violations of this Policy may result in devices being blocked from network access. Also highlights that violations may lead to costs to the Department and Unit resulting from unaddressed security issues. |
VII. Related Documents and Policies |
New section to align with Campus policy format. Consolidated references from other sections into this section. Also changed NetReg references to Socreg to reflect the 3/1/2022 conversion of NetReg to Socreg. |
VIII. Getting Help |
New section to address early feedback. Includes information for Departments that receive IT support from another Unit or department; and how to obtain general assistance. |