IS-3

Items related to BFB-IS-3: Electronic Information Security Policy

Patch Management Toolkit

Patch Management in the Age of AI

The window to patch is shrinking. Artificial Intelligence (AI) has dramatically accelerated how quickly vulnerabilities are discovered and exploited by bad actors. To protect UC Berkeley’s network, IT Service Providers must transition from slow, manual patching to agile, automated, and repeatable processes

Why the Patching Window Has Collapsed

Historically, IT teams had weeks to test and deploy patches. Today, AI-driven tools have compressed this timeline down to days or even hours...

Cyber Risk Management Program Annual Themes

Secure Access Management

Secure access management is essential for protecting sensitive data and systems. It ensures that only authorized users have the right level of access, reducing the risk of data breaches, insider threats, and operational disruptions.

Check out our Secure Access Management Guide to get started!

Cyber Risk Management Program

Welcome to UC Berkeley’s Cyber Risk Management Program (CRMP) home page. Berkeley’s Cyber Risk Management Program is a holistic program to help Units manage cyber risk as well as compliance with IS-3, UC's systemwide electronic information security policy.

Here you will find information and resources to help your Unit with its ongoing cyber risk management and annual CRMP review.

Jump to: Key Program Principles |...

IS-3 Resources

Overview

UC Business and Finance Bulletin IS-3 is the University of California’s systemwide information security policy. IS-3 defines how information security risk is handled within the university.

The following resources provide information and supporting documents relating to IS-3 and UC Berkeley's implementation of IS-3.

Policy & Campus Implementation: BFB-IS-3: Electronic Information Security (IS-3) - The...

IS-3 Informational Page

Overview

UC Business and Finance Bulletin IS-3 is the University of California’s systemwide information security policy. The policy and related standards are available on the UC Systemwide Information Security website.

IS-3 establishes how information security risk is handled within the university. Foundational elements include:

Security is a shared responsibility - everyone has a role. IS-3 focuses on risk...

Cyber Risk Management Program Unit Assessment Dashboards

The UC Berkeley Information Security Office (ISO) has created Tableau dashboards that contain the campus' Unit Assessment data. The dashboards are a data visualization and reporting tool to help Units and campus leadership track and analyze compliance as part of our Cyber Risk Management Program (CRMP).

There are three Tableau dashboards to aid in measuring compliance progress across campus:

Unit Dashboard: This dashboard can be used to track compliance progress and Unit...

IS-3 Implementation - Archive

Overview

The update of UC's Electronic Information Security Policy, IS-3, in 2018 brought changes to the way information security risk is managed at UC, and here at Berkeley. This project was designed to integrate IS-3's requirements and principles into Berkeley's existing information security program in a way that aligned with core campus priorities and values. Its goal was to help ensure that risk is understood and addressed at the appropriate organizational levels, and includeed updating the fundamentals of the campus’ security program to current UC and...

Information Security Policy Guide for Units

This is a living document last updated January 22, 2026 I. Introduction

The UC system wide policy UC Electronic Information Security Policy BFB-IS-3 (IS-3) establishes that Units are responsible for the appropriate protection of Institutional Information and IT Resources within the Unit. IS-3 identifies specific information security-related requirements and...

Secure Access Management Toolkit

Secure access management is essential for protecting sensitive data and systems. It ensures that only authorized users have the right level of access, reducing the risk of data breaches, insider threats, and operational disruptions. Learn how to improve managing access to your system with these tips and resources.

Onboarding and Offboarding Checklists

Effective user access management is crucial for maintaining security and operational efficiency within an organization. Including user access management within an onboarding/offboarding process can help streamline access for new hires...

Workstation Encryption Guide

Welcome to the IS-3 Annual Theme webpage for FY24! On this page you will find practical tools, resources and videos for encrypting the workstations in your unit.

Option #1: Berkeley Managed Desktop Service
(Recommended)

Enroll your workstations in the Berkeley Managed Desktop service, which offers a number of benefits such as:

Encryption by default for newly enrolled desktop and laptop computers Standard operating system and software Automated...