Socreg Security Contacts

A knowledge base article about Socreg Security Contacts provided by the UC Berkeley IT Service Hub - Knowledge Portal

Security Contacts in Socreg

Definition

A Security Contact is a group of authorized members who register IT Resources and receive security notices involving those resources.

The email address for a Security Contact should reach multiple people so that security incidents receive prompt attention. This can be accomplished by using a CalNet Special Purpose Account (SPA), a listserv, a bConnected List, or any other group email address that is monitored by and reliably reaches more than one person.

Socreg supports different types of Security Contacts: Department, Group, Individual, Service Provider, and Client. These types correctly route security notices to the responsible party based on how IT is managed within specific units.


Department Security Contact

The Department Security Contact responds to security notices for a University organization or department. They are associated with a specific Org node in the campus organizational tree. Only Department Security Contacts can have child Security Contacts (Group Security Contacts).

Note: Initial creation of a Department Security Contact requires review and approval by the Information Security Office (ISO).

Group Security Contact

Group Security Contacts are created by Department Security Contacts when a separation of responsibility is necessary (e.g., a specific research lab within a large department). They do not have an Org node set directly but must have a "parent" Department Security Contact so that security reporting can "roll up" to the correct Org node.

Common uses for Group Security Contacts:

  • Separating devices into sets that receive (or do not receive) support from a specific Service Provider.
  • Creating specific sets of members for the purpose of providing a service.
  • Dividing incident response responsibilities between different administrative groups.

When a Group Security Contact is created, the creator is added as the first member and can add others. Notices sent to the Group Security Contact can also be configured to notify the parent Department Security Contact.

Privilege Levels for Security Contact Members

Privilege Level Functionality
View-only Members can view registered assets but cannot make any changes.
Device Members can add or edit Device registrations.
IP Information Members can manage Devices AND all IP address information (Subnets, Subdomains, Offsite Hostnames, PD Applications, etc.).
Admin Full access: Can manage Devices, IP information, and Security Contact metadata (Name, Email, Membership).

Individual Security Contacts

Users can register personally-owned devices for use with the campus DHCP service. While individuals can request approval for a new Offsite hostname, the approval process will determine which Unit Security Contact (Department or Group) should be the permanent home for that hostname.

Service Provider and Client Relationship

The Service Provider Security Contact provides IT management for another Security Contact (the Client). For example, IT Client Services might act as a Service Provider for a departmental Security Contact.

  • Notifications: Security event notices (vulnerabilities, compromises) go to members of both the Service Provider and the Client.
  • Visibility: Security reports will show incidents in the respective parent departments of both parties.

Service Provider Privileges within a Client Contact

Clients choose their Service Provider from a list within Socreg. Service Providers can be granted specific functional rights within the Client's space:

Granted Privilege Allowed Functionality
Device Provider can manage Device registrations for the Client.
IP Information Provider can manage Devices and IP address information for the Client.

Restriction: Regardless of privilege level, Service Providers cannot modify the Security Contact information (membership, name, or email) of their clients.

Requests for Assets or Access

Socreg has a request system so that people can:

  • Request membership in a Security Contact

  • Request the creation of a Group Security Contact under a Department Security Contact

  • Request the creation of a new Department Security Contact from ISO

People may also request the transfer of assets from one Security Contact to another for:

  • PD Applications

  • Devices

  • IP Addresses

  • CC IP Addresses

New requests can be made on the Request page.  If you receive a notice about a request made to your Security Contact, review and approve or deny it in the “Requests to Review” table.  Requests you have made will be in the “Requests Submitted” table’.  You can view their status or cancel them if they are no longer needed.  

Please contact socreg@berkeley.edu for any questions or additional support.