Socreg User Guide: Basic Functions and Use Cases

A knowledge base article about Socreg User Guide: Basic Functions and Use Cases provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

Socreg is a self-service asset registration portal developed by the Information Security Office (ISO) to help campus departments and their Security Contacts maintain the registration of network assets and Protected Data to meet University policy requirements.

Socreg is designed to allow Security Contacts to update assets, including:

Note: Users accessing socreg.berkeley.edu from off-campus or while connected to the CalVisitor Wi-Fi network must use the campus VPN.

What is a Security Contact?

A Security Contact is a group in your department that receives and responds to security notices from the Information Security Office (ISO). Members have two main responsibilities:

  1. Manage the department's registered assets for routine security monitoring.
  2. Respond to or forward any security notices related to those assets.

Registered assets include computers and devices connected to the campus network. For additional information, you can click Help in the upper-right corner of any Socreg page.

How to Establish a Security Contact

  1. Log into Socreg (ensure you are on the campus network or VPN).
  2. Click Asset/Access Requests on the left sidebar.
  3. If a Security Contact already exists for your unit: Select "Request membership" from the New Requests drop-down. Your request must be approved by an existing member.
  4. If no Security Contact exists: Select "New Departmental Request" from the New Requests drop-down to initiate a request to ISO.

Once you are a member, you can view and edit details, manage membership, and access specific tabs for different asset types. Security notices are sent to the Security Contact's group email, while Socreg administrative business emails are sent to individual members.


Helpful Use Cases

Use Case #1: Departmental Sub-units

Scenario: Your department has several subunits that manage their own network resources.
Solution: Create "Group Security Contacts" under your primary Department Security Contact. This creates a parent-child relationship where sub-units manage their own assets while reporting rolls up to the parent org node.

Use Case #2: Broad Notification Requirements

Scenario: You manage all departmental devices, but specific research groups want to receive notices for their systems directly.
Solution: Use CC IP Addresses. Under the "CC IPs" tab, you can add other Security Contacts to be copied on any security notices sent to specific IP addresses.

Use Case #3: Fully Managed IT (ITCS)

Scenario: All of your department's IT resources are managed by IT Client Services (ITCS).
Solution: Add IT Client Services as the "Service Provider" for your Security Contact. ITCS staff will be able to manage your assets and will be automatically copied on all security notices.

Use Case #4: Mixed IT Support

Scenario: Your department maintains some systems internally, while others are supported by ITCS.
Solution: Create a Group Security Contact for the ITCS-supported assets and assign IT Client Services as the Service Provider for only that specific group.

Use Case #5: Application and Database Support

Scenario: You support applications or databases on servers managed by a different group, but you want to see the security alerts for those hosts.
Solution: Establish your own Security Contact and request CC IP Address status from the Security Contact that owns the host servers.

Use Case #6: Researchers with Protected Data

Scenario: You are a researcher with Protected Data on a server managed by the central data center.
Solution: Create a Group Security Contact under your Department Security Contact. Register your Protected Data (PD) Application (including Protection Level and record counts) and add the relevant IP addresses/components to that application.