Socreg: Best Practices

A knowledge base article about Socreg: Best Practices provided by the UC Berkeley IT Service Hub - Knowledge Portal

Registration & Incident Notification - Overview

Below is a high-level description and diagram of how asset registration and security incident management relate to each other. Accurate and complete registration of assets is imperative for information security operations and to safeguard Protected Data.

Asset registration

Incident Management

ISO’s incident management system uses Asset and Protected Data registration information to:

Registration & Incident Notification - Diagram

Socreg Incident Management Diagram

Periodically Review Registrations

It's important to periodically review your registrations, Security Contact information (Org node, email address), and Security Contact membership. Also, review registered assets (e.g., subnets, IP addresses, offsite hostnames, and devices) for accuracy and integrity.

For each Security Contact in your Security Contact list, select ‘View’ from the gear icon drop-down menu, and review each tab.

Things to look for: 

Review Protected Data Applications/Services:

Security Contacts will be sent an annual notice to review PD Application and PD Service registrations. Security Contacts should review: 

For PD Partners: If one Security Contact's asset is used in another Security Contacts' PD Application, that makes the first Security Contact a partner of the PD Application. Partners can add and remove their own components from the PD Application. Partners will be notified when their asset is included in someone else's PD Application. If a Security Contact feels that is incorrect, they can remove the component or contact socreg@berkeley.edu(link sends e-mail).

For PD Service Owners: In addition to reviewing all of the above, review which PD Applications are consuming your PD Services.

Protection Level Matching:

A component within a PD Application must have a PL number equal to or higher than the PD Application it is a component of. That means that the controls applied to a component must be better than, or equal to, the controls necessary to protect data within the PD Application. 

For example: “Medium-Secret Application” with P3 data can consume a PD Service “Encrypted Backup Service” as long as the service is rated for P3 or above. If the service is only rated for P2 then Socreg will alert the Security Contact.

Registering Components:

All components within a PD Application should be registered. In the case of Devices, they should be registered to a Unit Security Contact as opposed to an Individual.

Protected Data Applications with No Components:

Each PD Application registration includes certain attributes (name, description, Protection Level, record count, etc.,) AND one or more network components (IP address, Subnet, Device, etc.,). The first set of information is necessary to classify the PD Application appropriately. The second set is necessary to correctly identify the components within the PD Application, and more importantly, give the Information Security Office (ISO) information on which network assets to monitor. Until you add at least one network component to the PD Application, this registration does NOT result in increased protection from ISO.

Making Changes & Updates 

If changes to the Security Contact’s registered assets are needed, someone in the Security Contact with the appropriate level of access should be able to perform these updates. 

For more substantial changes like: 

Send an email to socreg@berkeley.edu describing the change needed, and our office will work with you.