A knowledge base article about CPHS Questionnaire Guide for Electronic Safeguards provided by the UC Berkeley IT Service Hub - Knowledge Portal
The objective of the CPHS assessment is to ensure that covered devices (e.g., workstations, laptops, servers) comply with the data security requirements issued by the California Health and Human Services Agency (CHHSA) Committee for the Protection of Human Subjects (CPHS).
This guide will walk you through the questions in the Electronic Safeguards section and provide tips and instructions to help you understand the compliance requirements and how to fulfill them.
Technical Details
ISO recommends the Secure Research Data & Compute (SRDC) platform or another approved server environment for handling PID. If you would like to use the SRDC link is external) platform you can contact Research IT to set up a consulting appointment.
Approved server environments:
- SRDC Virtual Machine service
- SRDC High Performance Computing service
- California Policy Lab (CPL) lab environment
- Integrative Cancer Research Group (ICARE) lab environment
The FIPS-140-2 standard is referred to by many of the requirements. It is the Federal Information Processing Standard specified security requirements for cryptographic modules.
Before beginning the questionnaire
Fill out the CPHS Researchers and Covered Devices Google document.
-
-
When you are finished filling out the document, give ciso-mssei-ssp@calgroups.berkeley.edu commenter access.
-
Keep the URL of the document handy as you will provide it to us in the questionnaire.
-
Please also keep this document updated for your own records/inventory.
Additional Resources
ISO recommends that your research project review the following resources:
- BitLocker for Windows and FileVault2 for MacOS fulfill this requirement.
Recommendation:
FIPS 140-2 compliant USB flash drives can be purchased to fulfill this requirement. Encryption and decryption is done on the drive, with no trace left on the host system.
- Approved server environments fulfill this requirement.
- Enabling Automatic Windows Updates or Mac Software Updates fulfills this requirement.
- Campus-owned laptops and/or workstations that are managed by Berkeley Desktop fulfill this requirement. However, it is important to regularly log out or manually reboot the machine periodically so that it receives security updates in a timely fashion. The device will not auto-reboot if a user is logged into a Berkeley Desktop machine.
Recommendation:
- Application software must also have security updates applied.
- Non-Berkeley researchers or researchers with personally-managed devices can follow the Patching and Updates Steps or can consult with their local IT administrator to confirm that system updates are installed automatically.
Ensure that all passphrases in the PID computing environment adhere to campus MSSND 5: Passphrase Guidelines. All users should be aware and trained on campus passphrase requirements and systems should enforce passphrase policies whenever feasible.
These requirements apply to passphrases for:
- Local user, single sign-on, default, and service accounts
- Applications
- Encrypted removable media or other electronic storage that handle PID
ISO recommends that you utilize a password manager such as LastPass to generate and manage unique passphrases that exceed the campus complexity requirements. UC Berkeley is offering Free LastPass Premium to all Students, Staff, and Faculty.
- Campus-owned laptops and/or workstations that are managed by Berkeley Desktop fulfill this requirement.
Recommendation:
- Non-Berkeley researchers or researchers with personally-managed devices can follow Device Lock-out Steps or can consult with their local IT administrator to enable screen lockout.
- See the MSSND Device Lock-Out requirement.
- Approved server environments fulfill this requirement.
- Campus-owned laptops and/or workstations that are managed by Berkeley Desktop fulfill this requirement.
- Windows devices with Windows Defender enabled fulfill this requirement.
- Mac devices running a supported version of MacOS fulfill this requirement.
Recommendation:
- Non-Berkeley researchers or researchers with personally-managed devices can follow Anti-malware Software Steps or can consult with their local IT administrator to confirm that anti-virus software is configured correctly.
- Approved server environments fulfill this requirement.
- All other server environments must be registered in Socreg, please see our Socreg Documentation.
- Approved server environments fulfill this requirement.
- All other server environments can enroll in the Log Correlation Program.
- Approved server environments fulfill this requirement.
- Describe the logging capabilities enabled on all devices that will be handling PID.
- Approved server environments fulfill this requirement.
- Systems storing PID should generally not be accessible from the Internet. If remote access is necessary, systems must comply with MSSND #8: Remote Access Services.
- Approved server environments fulfill this requirement.
- Use the campus Secure Deletion Guideline to determine the PID disposal method that works best for your research project.
- Approved server environments fulfill this requirement.
- Campus-owned laptops and/or workstations that are managed by Berkeley Desktop fulfill this requirement.
- Non-Berkeley researchers or researchers with personally-managed devices can follow the MSSND: How to Secure Devices guide or can consult with their local IT administrator to confirm that MSSND requirements are met.