Information Security Investment Program

Overview

UC President Drake has notified all UC locations and outlined requirements for updated information security investment plans. These plans are integral to protecting UC’s information and systems and have specific goals and expectations, as listed below.

UC Berkeley is poised to meet these requirements via these six projects:

1. Cyber Security Awareness Training

"Ensure cyber security awareness training for 100 percent of location employees." 

2. Cyber Escalation Response

"Ensure timely cyber escalation of incidents in alignment with UC Incident response and cybersecurity escalation standards." (CalNet Login required)

3. Identification and Management

"Ensure identification, tracking, and vulnerability management of all computing devices connected to university networks." (Page coming soon.)

4. Endpoint Detection and Response (EDR)

"Deploy and manage UC-approved Endpoint Detection and Response (EDR) software on 100 percent of assets defined by UC EDR deployment standards."

5. Multi-Factor Authentication (MFA)

"Deploy, enable, and configure multi-factor authentication (MFA) on 100 percent of campus and health email systems in conformance with established UC MFA configuration standards."

6. Data Loss Prevention (DLP) for Health Email Systems

"Deploy and configure a robust DLP solution for all health email systems to mitigate unauthorized data exfiltration." (Page coming soon.)