Security Basics: 101

Protecting Yourself

Protect your personal information by following guidelines for managing passwords, learning how to avoid phishing scams, and by remembering secure computing practices at all times.

Protecting your password

Protecting your passphrases and passwords is fundamental to protecting your online information and accounts. This is especially true of your CalNet credentials, which provide access to a wide array of online services for students, faculty, and staff.

Beware of Phishing Scams

Phishing scams trick users into revealing account information via email, phone, or text. Always verify emails that seem official asking for urgent action, as they may link to fake login pages or install malware. For protection tips, visit the Fight the Phish toolkit.

Set Strong Passphrases

Use unique, complex passphrases to defend against dictionary or brute-force attacks. Avoid common words or personal information, and consider using a password manager.

Avoid Public Kiosks and Untrusted Devices

Be cautious using public kiosks or borrowing devices, as they may harbor malware. Always log out properly to prevent unauthorized access.

Understand Attacker Techniques

Attackers can compromise credentials through shoulder surfing or by viewing information you post about yourself online! They also exploit reused passwords, so use unique passwords for every site.

Protecting your personal information and safety

Protecting Your Data

Managing UC Berkeley data correctly protects the university and reduces privacy risks. Follow these simple steps throughout the four stages of the data lifecycle.

Planning and Creation

  • Classify your data: Determine your data's sensitivity level using Berkeley's Classification Guideline.
  • Set up security: Apply the Minimum Security Standards required for your data level.
  • Review vendor contracts: Ensure outside vendors sign UC's "Appendix - Data Security" before giving them access to sensitive details.
  • Identify compliance rules: Check if your data falls under laws like FERPA, HIPAA, PCI DSS, or GDPR, and ensure you have a breach response plan ready.

Using and Sharing

  • Limit access: Share sensitive data only with people who strictly need it for their job.
  • Redact unnecessary info: Strip out personal details before sending files.
  • Inform recipient: Make sure anyone receiving the data knows its sensitivity level and handling rules.
  • Use approved channels: Send and store files through vetted tools like bMail, bDrive, or Box. Verify all Data Use and Access Agreements are in place.

Storing and Backing Up

  • Use approved storage: Store files using UC Berkeley-contracted services (like Research Data Storage or bConnected).
  • Back up your files: Back up data routinely to prevent loss.
  • Plan for outages: Follow UC Continuity and Disaster Recovery policies to keep your systems accessible.

Destroying and Offboarding (Access Control)

  • Follow retention schedules: Keep files only as long as the UC Berkeley Records Retention Schedule requires.
  • Securely delete electronic files: Permanently erase digital files in accordance with IT destruction standards.
  • Shred paper records: Dispose of physical files in approved secure destruction bins.
  • Clean up after projects: Remove permissions and delete unnecessary data when a project ends.

Protecting Devices

Keep all your devices protected with the latest operating system (OS) and application security patches, up-to-date anti-malware programs, and secure mobile device use.

Turn On Automatic Updates

Updating your software closes security holes automatically so you don't have to think about it.

  • University-Owned Computers: Contact IT to enroll in the Berkeley Desktop service to automate all updates.
  • Windows PCs: Go to Settings > Windows Update and turn on automatic updates.
  • Macs: Open Settings > General > Software Update and switch Automatic Updates to ON.
  • iPhones & iPads: Go to Settings > General > Software Update > Automatic Updates and toggle them on.
  • Android Devices: Open Settings > System > System update to check for updates, and set the Google Play Store to auto-update apps.

Verify Your Security & Anti-Malware Software

Berkeley Security Software is required on all university-owned computers.

Anti-malware stops malicious software from damaging your files or taking over your system.

  • Windows: Open the built-in Windows Security app to confirm real-time protection is active.
  • Mac & Third-Party Apps: If you use separate antivirus software, check its settings to ensure real-time scanning and automatic signature updates are enabled.

Secure Your Mobile Devices

Smartphones carry sensitive data and need extra safeguards.

  • Set a Strong Lock: Always use a Passcode, PIN, Face ID, or Fingerprint lock.
  • Turn On "Find My": Enable Find My (iOS) or Find My Device (Android) so you can locate, lock, or remotely erase a lost device.
  • Wipe Old Devices: Erase all content and settings before selling, recycling, or giving away an old phone.
  • Avoid Security Risks:
    • Do not jailbreak or root your phone (this removes built-in defenses).
    • Only download apps from official stores (App Store / Google Play).
    • Review app permission requests carefully before accepting them.
    • Avoid sensitive transactions (like banking) on public Wi-Fi.
    • Note: Do not store university data in personal iCloud or personal cloud accounts—use approved campus storage instead.