Socreg Best Practices

A knowledge base article about Socreg Best Practices provided by the UC Berkeley IT Service Hub - Knowledge Portal

Overview

Accurate and complete registration of assets is imperative for information security operations and the safeguarding of Protected Data. Below is a high-level description of how asset registration and security incident management relate to each other.

Asset Registration

Incident Management

The Information Security Office (ISO) incident management system uses registration information to:


Periodically Review Registrations

It is important to periodically review your Security Contact information (Org node, email address), membership, and registered assets (subnets, IP addresses, offsite hostnames, and devices) for accuracy.

For each Security Contact, select View from the gear icon menu and review each tab for the following:

Review Protected Data (PD) Applications and Services

Security Contacts receive an annual notice to review PD Application and Service registrations. During this review, confirm:

Protection Level Matching

A component within a PD Application must have a Protection Level (PL) equal to or higher than the application itself. Controls applied to a component must be equal to or greater than those required for the data within the application.

Example: An application with PL3 data can use an "Encrypted Backup Service" only if that service is also rated PL3 or higher. If the service is rated PL2, Socreg will generate an alert.

Registering Components

All components within a PD Application must be registered. Devices must be registered to a Unit Security Contact (KB0015397) rather than an individual.

Note: Until you add at least one network component (IP, Subnet, or Device) to a PD Application, the registration does not result in increased protection or monitoring from ISO.

Making Changes & Updates

Members with appropriate access can perform most updates directly in Socreg. For substantial changes, email socreg@berkeley.edu for assistance with: