A knowledge base article about Socreg Best Practices provided by the UC Berkeley IT Service Hub - Knowledge Portal
Overview
Accurate and complete registration of assets is imperative for information security operations and the safeguarding of Protected Data. Below is a high-level description of how asset registration and security incident management relate to each other.
Asset Registration
- (1) Register Assets: Security Contacts register assets in Socreg for which they are responsible. They also define Protected Data (PD) Applications, which may include assets from other Unit Security Contacts in addition to their own.
Incident Management
The Information Security Office (ISO) incident management system uses registration information to:
- (2) Initiate enhanced scanning of Protected Data Assets.
- (3) Set significance levels for incoming security events.
- (4) Route security incident notices back to the appropriate Security Contacts.
Periodically Review Registrations
It is important to periodically review your Security Contact information (Org node, email address), membership, and registered assets (subnets, IP addresses, offsite hostnames, and devices) for accuracy.
For each Security Contact, select View from the gear icon menu and review each tab for the following:
- Email Address: Is the Security Contact email correct? This is used for all official security notices.
- Membership: Is the member list complete? Does at least one member have Receive FYI Email set to "Yes"? Does at least one member have Admin privileges?
- Subnets: Are subnets containing Protected Data behind a firewall? To change subnet descriptions, contact the Campus DNS Administrator at dns@berkeley.edu.
- Hostnames: Are Offsite hostnames with a Protection Level above P1 still accurate? Are any hostnames stuck in "Requested" status (indicating an open ticket with ISO)?
- Device Ownership: University-owned devices must be registered to a Unit Security Contact, not an individual. If you find university devices registered to individuals, use the "Contact Us" link in Socreg to request a transfer.
Review Protected Data (PD) Applications and Services
Security Contacts receive an annual notice to review PD Application and Service registrations. During this review, confirm:
- Protection Level (PL): Ensure the PL and record quantities are correct.
- Components: Verify that subnets are claimed, hostnames are approved, and devices are registered to the Unit Security Contact.
- Responsibility: The PD Application should be registered to the Security Contact responsible for responding to incidents for that specific application.
- PD Partners: If your asset is used in another group's PD Application, you are a "Partner." Partners can manage their own components within that application and will be notified of changes.
- PD Service Owners: Review which PD Applications are currently consuming your services.
Protection Level Matching
A component within a PD Application must have a Protection Level (PL) equal to or higher than the application itself. Controls applied to a component must be equal to or greater than those required for the data within the application.
Example: An application with PL3 data can use an "Encrypted Backup Service" only if that service is also rated PL3 or higher. If the service is rated PL2, Socreg will generate an alert.
Registering Components
All components within a PD Application must be registered. Devices must be registered to a Unit Security Contact (KB0015397) rather than an individual.
Note: Until you add at least one network component (IP, Subnet, or Device) to a PD Application, the registration does not result in increased protection or monitoring from ISO.
Making Changes & Updates
Members with appropriate access can perform most updates directly in Socreg. For substantial changes, email socreg@berkeley.edu for assistance with:
- Reorganizing or retiring a Security Contact.
- Moving large batches of assets between contacts.
- Moving a Security Contact into a subgroup beneath a parent.