Vendor Security Assessment Program

A service overview and catalog of Vendor Security Assessment Program provided by the UC Berkeley IT Service Hub.

Description

The Vendor Security Assessment (VSA) service provides a rigorous, third-party evaluation of a vendor’s ability to safeguard University data and systems. Managed by the Information Security Office (ISO), this service ensures that any external partner handling sensitive information meets the University’s high standards for technical, administrative, and physical security. 

Benefits & Features

Scope & Deliverables

For more information, see Details about the Vendor Security Assessment Service.

Getting Started

To ensure a smooth assessment, please complete the following steps before submitting your request.

1. Gather Documentation from the Vendor

Ask your vendor contact for the following items:

Inform the vendor that Venminder will contact them to conduct the assessment on behalf of UC Berkeley.

2. Prepare Usage Details

Ensure you have these details ready for the intake form:

3. Coordinate with your Buyer

Before submitting the VSA request, work with your Buyer to confirm:

4. Submit the Form

Once the above steps are complete:

Service Details

Eligibility

This service is available to Faculty and Staff.

Contact

Technical Support: Request a Vendor Security Assessment (CalNet login required) or email questions to security-assessments@berkeley.edu.

Availability

Available 24/7. Support is provided Monday–Friday, 8:00 AM – 5:00 PM PT, excluding University holidays and curtailment periods.

Cost

There are no direct costs associated with the standard service. Rush orders for vendor assessments may have a cost charged by our external vendor, Venminder. Rush order fees range from $250 to $1000 depending on the type of assessment.

Data Classification

This service is rated for P3, A2, and R2 data.

Compliance: Users are responsible for ensuring data handled within this service complies with the Data and IT Resource Classification Standards.